Trojan

Trojan-Downloader.Win32.Adload.sqfj information

Malware Removal

The Trojan-Downloader.Win32.Adload.sqfj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.sqfj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.sqfj?


File Info:

name: 82883C6C44271B063F57.mlw
path: /opt/CAPEv2/storage/binaries/6f7ad50a3e231764f266ad23e0afb2be38650f446c93184b31bdac0bfc156725
crc32: D63CD2B4
md5: 82883c6c44271b063f57c475b480d515
sha1: 7e3b33c579186121156b3dbbacbd58c91676a96a
sha256: 6f7ad50a3e231764f266ad23e0afb2be38650f446c93184b31bdac0bfc156725
sha512: 036a09339969957b5a2dd5ef0193b3e4f01b143951dae84076b22394aaefdd29397396b7e5427502990d8910b070570d8e4bbccb4c6bf1d981bcab22a6be2774
ssdeep: 98304:8Sij+5QVyUPcuGtYAvK1JMVUsoxex7AmlICDnWDkP1U:mL4UPatY9MVfoxelICDcktU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10A36123FB268653EC46A4B3249B39350997BBB61B81E8C2E17F4080DDF665701E3F616
sha3_384: 3933b5ef2b39df3fd2160c77710efdf956b993a9a8182ff492136ba3a5764a31fd29b5621cfbb1947b14aa5bb44a302a
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-11-15 09:48:30

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Velit Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Velit
ProductVersion: 1.9.14.6
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.sqfj also known as:

LionicTrojan.Win32.Convagent.a!c
MicroWorld-eScanTrojan.GenericKD.46857902
FireEyeTrojan.GenericKD.46857902
McAfeeArtemis!82883C6C4427
CylanceUnsafe
VIPRETrojan.GenericKD.46857902
SangforTrojan.Win32.Adload.sqfj
K7AntiVirusTrojan ( 0057fbec1 )
AlibabaAdWare:Win32/AdLoad.33b61a90
K7GWTrojan ( 0057fbec1 )
CyrenW32/Agent.CPA.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HMIO
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.sqfj
BitDefenderTrojan.GenericKD.46857902
AvastWin32:AdwareX-gen [Adw]
RisingDownloader.Convagent!8.123D1 (CLOUD)
Ad-AwareTrojan.GenericKD.46857902
SophosTroj/Agent-BHKP
F-SecureHeuristic.HEUR/AGEN.1206162
Trapminesuspicious.low.ml.score
EmsisoftApplication.Dropper (A)
GDataWin32.Trojan.BSE.W4BXSV
AviraHEUR/AGEN.1237241
ArcabitTrojan.Generic.D2CAFEAE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.46857902
MAXmalware (ai score=81)
VBA32TrojanDownloader.Adload
MalwarebytesAdware.DownloadAssistant
TencentWin32.Trojan-downloader.Adload.Dzjs
YandexTrojan.DL.Adload!ocW6MsjiB6E
IkarusTrojan.Win32.Crypt
FortinetRiskware/Adload
AVGWin32:AdwareX-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Downloader.Win32.Adload.sqfj?

Trojan-Downloader.Win32.Adload.sqfj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment