Trojan

Trojan-Downloader.Win32.Adload.sroc removal guide

Malware Removal

The Trojan-Downloader.Win32.Adload.sroc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.sroc virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.sroc?


File Info:

name: 3FCB0F334D567077979E.mlw
path: /opt/CAPEv2/storage/binaries/66f27dd070631a6fb7afb1e0aa9cd22ba041abfdaef9dae24146a403b57316d4
crc32: A6249D2B
md5: 3fcb0f334d567077979edd05cc28204a
sha1: 6d133b47109e54296ff607b72cd6b41384e040e8
sha256: 66f27dd070631a6fb7afb1e0aa9cd22ba041abfdaef9dae24146a403b57316d4
sha512: 0617ec3fbe5ae9c7ae429dfff8a15825481b8a33b8e06ce1a296076a21b94dd77cbea15726a57c489569229c18a773b581c33af6671f537bab7171511a555181
ssdeep: 98304:qXpovtrxxZGwPMLIehEgBa7f8J6ujBVwsibPy5skFpTl:qXp8rtIV1wzq7Tl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA163307F3C304F5E6645739A968854C1D27B96501E4483A2FFCEB0F05BEAC264B9FA6
sha3_384: 80d3114b3e26d90a87e2bc2eff19868f1b56995abeb6aff92a40ee82f2cbe08acef092551421db0eb3a08016fe184597
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-05-29 11:51:48

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Aliquid Setup
FileVersion:
LegalCopyright:
ProductName: Aliquid
ProductVersion: 9.7.10.1
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.sroc also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
CylanceUnsafe
SangforTrojan.Win32.Agent.SLC
K7AntiVirusRiskware ( 0040eff71 )
AlibabaAdWare:Win32/AdLoad.4196ec65
K7GWRiskware ( 0040eff71 )
CyrenW32/Agent.CYZ.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.sroc
AvastNSIS:Downloader-ADB [Trj]
TencentWin32.Trojan-downloader.Adload.Lpcd
DrWebTrojan.DownLoader45.6037
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
SophosDownload Assistant (PUA)
GDataWin32.Backdoor.Bodelph.OQM6R5
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1237229
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
Acronissuspicious
McAfeeArtemis!3FCB0F334D56
VBA32Trojan.Sabsik.FL
MalwarebytesAdware.DownloadAssistant
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/Adload
AVGNSIS:Downloader-ADB [Trj]
CrowdStrikewin/grayware_confidence_70% (W)

How to remove Trojan-Downloader.Win32.Adload.sroc?

Trojan-Downloader.Win32.Adload.sroc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment