Trojan

Trojan-Downloader.Win32.Adload.tcso removal instruction

Malware Removal

The Trojan-Downloader.Win32.Adload.tcso is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tcso virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

Related domains:

wpad.local-net
jorjifornk.live

How to determine Trojan-Downloader.Win32.Adload.tcso?


File Info:

name: 516194AC59CC18D2E636.mlw
path: /opt/CAPEv2/storage/binaries/0d622fc63214070e2ec5d056c985a617ef274b061ef2e97da31d9c7428ecd970
crc32: 4DB77F25
md5: 516194ac59cc18d2e6360121c5c18326
sha1: 5414b4239213aaf3e3934f9c553de556f71082a6
sha256: 0d622fc63214070e2ec5d056c985a617ef274b061ef2e97da31d9c7428ecd970
sha512: 6e83a26a3a4983985ff2a8e49e8cb96e5c9de65883ea1c0ce71557f981f9eebf5eb31e4ba15bcbdd177193e5470309805a318da0ffea2d9f32417c7688a3e473
ssdeep: 98304:1sI0m4VFrMPJ2W/SDz/GKp9iD32tIKwNZiiBJneWp+:iIz47+J2W/Sv/GegmGrN0kJo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138163383F38305B1F2790577AC12C195AD2A7C2029E1A0765DF9DF0F8CBA3D168779A9
sha3_384: 04297fa6c47ef21f2fa81226fc0d1883b2d5f1b0fe20e363c0e8f4252cde9b4fb1235a825aa6d6551487bc27cdce2525
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-05-29 11:51:48

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Consectetur Setup
FileVersion:
LegalCopyright:
ProductName: Consectetur
ProductVersion: 5.10.5.11
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tcso also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Agent
McAfeeArtemis!516194AC59CC
CylanceUnsafe
SangforTrojan.Win32.Adload.tcso
BitDefenderGen:Variant.Midie.100605
K7GWTrojan ( 00587f231 )
K7AntiVirusTrojan ( 00587f231 )
CyrenW32/Agent.DAS.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tcso
AlibabaAdWare:Win32/AdLoad.ad71e305
MicroWorld-eScanGen:Variant.Midie.100605
AvastNSIS:Downloader-ADB [Trj]
Ad-AwareGen:Variant.Midie.100605
EmsisoftGen:Variant.Midie.100605 (B)
TrendMicroTROJ_GEN.R002C0WJG21
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
FireEyeGen:Variant.Midie.100605
SophosDownload Assistant (PUA)
IkarusTrojan.NSIS.Agent
GDataWin32.Backdoor.Bodelph.E6G38J
AviraTR/NSIS.Agent.xejhf
ArcabitTrojan.Midie.D188FD
MicrosoftTrojan:Win32/Tnega!ml
AhnLab-V3Malware/Gen.Generic.C4695816
ALYacGen:Variant.Midie.100605
MAXmalware (ai score=88)
VBA32Trojan.Sabsik.FL
MalwarebytesAdware.WinYahoo
TrendMicro-HouseCallTROJ_GEN.R002C0WJG21
TencentWin32.Trojan-downloader.Adload.Stkb
FortinetW32/Download_Assistant
AVGNSIS:Downloader-ADB [Trj]
PandaTrj/CI.A

How to remove Trojan-Downloader.Win32.Adload.tcso?

Trojan-Downloader.Win32.Adload.tcso removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment