Trojan

What is “Trojan-Downloader.Win32.AdLoad.sjfw”?

Malware Removal

The Trojan-Downloader.Win32.AdLoad.sjfw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.AdLoad.sjfw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.AdLoad.sjfw?


File Info:

name: 7DBC3DCF72C91FD1D00F.mlw
path: /opt/CAPEv2/storage/binaries/42b8a68134125deffc51fdcaa903ff06f64c6d97001810b56668fc2d656a3397
crc32: 7341FE32
md5: 7dbc3dcf72c91fd1d00fc6ec661a8bbd
sha1: 48b7fe0e17e78bfa267065de65eb8438279002df
sha256: 42b8a68134125deffc51fdcaa903ff06f64c6d97001810b56668fc2d656a3397
sha512: 1ed2422ccd49cae974739450e7a87afe81eabf2143bffa25efc87642932468341a99c6f625fdeb048321774c219adeedf198c76e672c284f5dbf42f0c827b86b
ssdeep: 98304:PX4InxhcQk9yJJAEL4Axn8XFhDySIyMoCSyazx14:vOQUu/xnOFhDySNdya0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D261227B298613EC0AA27364673A41058FBB66DF417BE1677F0C48CCF660C51E3AB65
sha3_384: f0b77949935605cd2522fee6ea873e4f33927f5ea58fecfee67de2527e526e09542e09a65a2026791f844fb6c537d282
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2019-04-27 08:22:11

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Sunt Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Sunt
ProductVersion: 8.17.7.12
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.AdLoad.sjfw also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.1686
MicroWorld-eScanTrojan.GenericKD.37553859
FireEyeTrojan.GenericKD.37553859
ALYacTrojan.GenericKD.37553859
CylanceUnsafe
VIPRETrojan.GenericKD.37553859
SangforTrojan.Win32.Ekstak.akhsm
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Generic.1eb73bd1
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.AdLoad.sjfw
BitDefenderTrojan.GenericKD.37553859
AvastNSIS:Downloader-ADB [Trj]
TencentWin32.Trojan-Downloader.Adload.Wmhl
Ad-AwareTrojan.GenericKD.37553859
EmsisoftAdware.Downloader (A)
McAfee-GW-EditionBehavesLike.Win32.CSDImonetize.rc
SophosTroj/Agent-BGXK
GDataTrojan.GenericKD.37553859
GoogleDetected
AviraHEUR/AGEN.1237227
Antiy-AVLTrojan/Generic.ASSuf.4DD71
ArcabitTrojan.Generic.D23D06C3
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
Acronissuspicious
McAfeeArtemis!7DBC3DCF72C9
MAXmalware (ai score=84)
VBA32Trojan.Zadved
MalwarebytesAdware.DownloadAssistant
FortinetW32/Agent.SLC!tr
AVGNSIS:Downloader-ADB [Trj]

How to remove Trojan-Downloader.Win32.AdLoad.sjfw?

Trojan-Downloader.Win32.AdLoad.sjfw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment