Trojan

Should I remove “Trojan.Adduser.100316”?

Malware Removal

The Trojan.Adduser.100316 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Adduser.100316 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Trojan.Adduser.100316?


File Info:

crc32: CADC0D70
md5: 5a0f504c8aed6d126551cba41cd8a4d5
name: 5A0F504C8AED6D126551CBA41CD8A4D5.mlw
sha1: b8ebc7d2b07f4a6d5099d2b61e13172ad716a4a9
sha256: 2cad4e8db92b99ad6d39979c1be03f72b5f04b63bdd0b0d86e167b9811dfd5e5
sha512: 200d6aa68f1846753143c62bb69589154ff3535c9907a267704fb6cf911b3d08b4c5b97cfb94c5e4a553477ebd5f49b1536bc5b051e0647578b26731a65e226d
ssdeep: 6144:kUrv1hUB24BFuNOKcG5Y2vj4868P32mFIPbJSICH:kMvYB2SuSO3vM8602mFgbeH
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan.Adduser.100316 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.Adduser.100316
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.60117
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/MBRlock.AQ
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Foreign.naew
NANO-AntivirusTrojan.Win32.Ransom.ibcdbg
TencentMalware.Win32.Gencirc.10ce95d9
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.TrojanDropper.Agent.HNMS@4xnjpy
F-SecureHeuristic.HEUR/AGEN.1105895
BitDefenderThetaGen:NN.ZexaF.34104.vqHfaeHxcFbb
FireEyeGeneric.mg.5a0f504c8aed6d12
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Foreign.hwb
AviraHEUR/AGEN.1105895
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmTrojan-Ransom.Win32.Foreign.naew
GDataWin32.Trojan.PSE.183RH9S
Acronissuspicious
VBA32SScope.Trojan.PWS.22627
PandaTrj/GdSda.A
YandexTrojan.GenAsa!ybv8ECUyKWQ
IkarusTrojan.Sisproc
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/MBRlock.AQ!tr.ransom
AVGWin32:Trojan-gen

How to remove Trojan.Adduser.100316?

Trojan.Adduser.100316 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment