Trojan

How to remove “Trojan-Downloader.Win32.AdLoad.siex”?

Malware Removal

The Trojan-Downloader.Win32.AdLoad.siex is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.AdLoad.siex virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

Related domains:

perclickbest.club
wpad.local-net

How to determine Trojan-Downloader.Win32.AdLoad.siex?


File Info:

name: 1FC2F44DCBD026204215.mlw
path: /opt/CAPEv2/storage/binaries/7a9bc597b6710b65179ec9c51a72d29b3ce9f77411972ea22b113f2cf886dd2e
crc32: 7DC07BDB
md5: 1fc2f44dcbd026204215053285d95582
sha1: 76c1878a20aaf42512dafb5c4c45e0e1d12c8b98
sha256: 7a9bc597b6710b65179ec9c51a72d29b3ce9f77411972ea22b113f2cf886dd2e
sha512: 7b5758c6f9ce968d63543279c6da8d29616e9e4e296e7aafb0b4401343fb9fa340b81176e6c3b52ef3117bb5dfabd2464b19a02896c5baaf59ef3f970e24d47b
ssdeep: 98304:PX4UexHJFwSc9GGmG/I+HQbIY1I2bPeNChRGF6lmvbP6+yazx14:vzYHzwvrmGgWU1zb2jvNya0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F356232B7298613EC4AE27314A73A11068FBB66DF417BE1676F0C48DCF651C10E3AB65
sha3_384: a17331a16b669573c584dccf564590e892910ff276d840a8bd9d3678786dc6494c5e89d68dcb7a2291218df8c1e174b7
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2019-04-27 08:22:11

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Odio Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Odio
ProductVersion: 6.15.16.3
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.AdLoad.siex also known as:

LionicTrojan.Win32.AdLoad.a!c
Elasticmalicious (high confidence)
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CyrenW32/Agent.CJW.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.AdLoad.siex
AlibabaAdWare:Win32/AdLoad.764d7176
NANO-AntivirusTrojan.Win32.Adw.ixhpeq
EmsisoftAdware.Downloader (A)
DrWebTrojan.Zadved.1686
TrendMicroTROJ_GEN.R002C0RGA21
McAfee-GW-EditionBehavesLike.Win32.CSDImonetize.tc
SophosTroj/Agent-BGXK
IkarusPUA.Optional.Install
AviraHEUR/AGEN.1142804
CynetMalicious (score: 99)
McAfeeArtemis!1FC2F44DCBD0
VBA32Trojan.Zadved
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002C0RGA21
TencentWin32.Trojan-downloader.Adload.Edeo
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.8964!tr
AVGNSIS:Downloader-ADB [Trj]
AvastNSIS:Downloader-ADB [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan-Downloader.Win32.AdLoad.siex?

Trojan-Downloader.Win32.AdLoad.siex removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment