Trojan

Should I remove “Trojan-Downloader.Win32.Adload.soki”?

Malware Removal

The Trojan-Downloader.Win32.Adload.soki is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.soki virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.soki?


File Info:

name: 2131669A624AF697A43F.mlw
path: /opt/CAPEv2/storage/binaries/cfe9cc7fe6051ee04f052f5d800d6a5b061874995998d34eb7141039e4a7ccfd
crc32: 4375AD35
md5: 2131669a624af697a43f746719be0571
sha1: cf12a2023b9b30d033bf19d794945ceaa5e993e2
sha256: cfe9cc7fe6051ee04f052f5d800d6a5b061874995998d34eb7141039e4a7ccfd
sha512: 55ca197d3fc18d1b434ecbcda84efa52beb08c2ae39c1f5acd0d4b431fe05277fb6d62fcc398bd19fcee1d9033b5bf227ee10a56e0a4b19a97701360f3b5bdf5
ssdeep: 98304:8SiiOoALMal42eoU+ZDOSJNCer5gCpEtrYVwQgyfUSKCDnWDkP1k:goKzm23d3Nh5gCzVwfkKCDcktk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11336123FB268653ED46F4B3249739350997BBA60B81A8C2E17F4494CCF274701E3BA56
sha3_384: fd46be2d2a19151176bcb11739ad4d93418b989bb3be2559b2cfb66ef1a2b215fed05807dd3f6996b5cdd6001d127a02
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-11-15 09:48:30

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Autem Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Autem
ProductVersion: 7.6.20.13
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.soki also known as:

LionicTrojan.Win32.Adload.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.46812749
FireEyeTrojan.GenericKD.46812749
McAfeeArtemis!2131669A624A
CylanceUnsafe
SangforTrojan.Win32.Adload.soki
K7AntiVirusTrojan ( 005810941 )
AlibabaAdWare:Win32/AdLoad.49daccdf
K7GWTrojan ( 005810941 )
CyrenW32/Agent.CSU.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002C0RHK21
KasperskyTrojan-Downloader.Win32.Adload.soki
BitDefenderTrojan.GenericKD.46812749
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan-downloader.Adload.Hnkr
Ad-AwareTrojan.GenericKD.46812749
SophosTroj/Agent-BHKP
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0RHK21
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
EmsisoftTrojan.GenericKD.46812749 (B)
GDataWin32.Trojan.BSE.W4BXSV
AviraHEUR/AGEN.1142027
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 99)
VBA32TrojanDownloader.Adload
ALYacTrojan.GenericKD.46812749
MalwarebytesAdware.DownloadAssistant
IkarusTrojan.Win32.Crypt
FortinetRiskware/Adload
WebrootW32.Adware.Gen
AVGWin32:AdwareX-gen [Adw]

How to remove Trojan-Downloader.Win32.Adload.soki?

Trojan-Downloader.Win32.Adload.soki removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment