Trojan

Trojan-Downloader.Win32.Adload.pef removal

Malware Removal

The Trojan-Downloader.Win32.Adload.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.pef virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

Related domains:

jorjifornk.live
wpad.local-net

How to determine Trojan-Downloader.Win32.Adload.pef?


File Info:

name: F10CBC74540018D35710.mlw
path: /opt/CAPEv2/storage/binaries/ff9b45e6bb90ab4fe5cf9a3f6b44dd1a6ef3cf0a665fed41255f69e307079d71
crc32: 255951ED
md5: f10cbc74540018d3571076ae1ac47fdc
sha1: 1e4de218ce6756cc32efd501bd4f059739bfde4c
sha256: ff9b45e6bb90ab4fe5cf9a3f6b44dd1a6ef3cf0a665fed41255f69e307079d71
sha512: a7e0d73adc40e3fa94b51fbdf8b5b3a40dab19b16dba75f3c1611047d174445d865c255b55dd22e97681b5b7f34492a05f61d392ffd0e94156699cb660b7faee
ssdeep: 98304:JSlOzAC3NVQACg/TUmNbMww2/jEBqGUrs9pj:JIAACISBNQdoGL9pj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137369F61BA09B1FFD49A2778D527CDC25B6D0FB846204817996C7C7EBDF3C81218AD28
sha3_384: 5af446fad42d2b0c4d404e81af35090532a5ec9c45557b052505e30c83a69826c89f774eb926f40e2435d1ebad8d32fd
ep_bytes: e90cd6280128ab5d95837ba61d94d23a
timestamp: 2021-10-28 23:59:51

Version Info:

Comments: ab28886af3b6f732ef902aaf66703c121f6899eb
CompanyName: Ariolic Software (http://www.ariolic.com)
FileDescription: ActiveSMART Library
FileVersion: 2.10.2.167
InternalName: ActiveSMART DLL
LegalCopyright: Copyright © 2018 Ariolic Software, Ltd.
OriginalFilename: ActiveSMART.exe
ProductName: Active SMART
ProductVersion: 2.10.2.167
SpecialBuild: UNICODE
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.pef also known as:

DrWebTrojan.DownLoader44.3283
MicroWorld-eScanTrojan.GenericKDZ.79496
FireEyeGeneric.mg.f10cbc74540018d3
ALYacTrojan.GenericKDZ.79496
CylanceUnsafe
K7AntiVirusTrojan ( 00580bdb1 )
K7GWTrojan ( 00580bdb1 )
ArcabitTrojan.Generic.D13688
CyrenW32/Kryptik.FQF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLZO
KasperskyHEUR:Trojan-Downloader.Win32.Adload.pef
BitDefenderTrojan.GenericKDZ.79496
AvastWin32:AdwareX-gen [Adw]
Ad-AwareTrojan.GenericKDZ.79496
SophosTroj/Agent-BHKP
McAfee-GW-EditionBehavesLike.Win32.Generic.rh
EmsisoftTrojan.GenericKDZ.79496 (B)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
AviraHEUR/AGEN.1145844
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.FOM1ZH
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.AdwareX-gen.R448039
McAfeeGenericRXQO-XS!F10CBC745400
VBA32BScope.TrojanDownloader.Adload
MalwarebytesAdware.DownloadAssistant
APEXMalicious
IkarusTrojan.Win32.Crypt
FortinetRiskware/Kryptik
AVGWin32:AdwareX-gen [Adw]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan-Downloader.Win32.Adload.pef?

Trojan-Downloader.Win32.Adload.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment