Trojan

Trojan-Downloader.Win32.Adload.tcyu malicious file

Malware Removal

The Trojan-Downloader.Win32.Adload.tcyu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tcyu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.tcyu?


File Info:

name: 607E55AF343557B32DEA.mlw
path: /opt/CAPEv2/storage/binaries/170b94ff361efda658b9e2a94cb3903b49b68daab0dc5d2e207442c6a05f0114
crc32: 339B5710
md5: 607e55af343557b32deab03d56c186e3
sha1: 8553144b547600ea976f11c60da87d0835611a04
sha256: 170b94ff361efda658b9e2a94cb3903b49b68daab0dc5d2e207442c6a05f0114
sha512: 73b563f16bfe8a7b1be47ad4d2121291a38934ff041a51c0b6b14c3679687725579e8daf1ad431f18374ec2050b27723e24365ad4630a8a1f181ee63cd276d62
ssdeep: 98304:pKkwflh6qv+QB7KTE0ax2vM+Qg/9ExhtrIZLr6wUr:MkwNf9ITjp0Q/utItr6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB16330B73D341F4D04805B12C53A09A3C27BC7929DA64ADAEF9D60F5D7D7827C39AA2
sha3_384: 4636e71f20da97c5617bb7d0fa8254ffda18e15826772be201701ced0760f9d926d9a9d386127f3aa237d27e634d14ae
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-05-29 11:51:48

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Facilis Setup
FileVersion:
LegalCopyright:
ProductName: Facilis
ProductVersion: 1.6.17.18
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tcyu also known as:

LionicTrojan.Win32.Adload.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47192208
FireEyeTrojan.GenericKD.47192208
McAfeeArtemis!607E55AF3435
CylanceUnsafe
SangforTrojan.Win32.Adload.tcyu
K7AntiVirusTrojan ( 005850dc1 )
AlibabaAdWare:Win32/AdLoad.84ca9dc1
K7GWTrojan ( 005850dc1 )
CyrenW32/Adload.FV.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R011C0GJH21
ClamAVWin.Trojan.Generic-9908274-0
KasperskyTrojan-Downloader.Win32.Adload.tcyu
BitDefenderTrojan.GenericKD.47192208
AvastNSIS:Downloader-ADB [Trj]
TencentWin32.Trojan-downloader.Adload.Wmje
Ad-AwareTrojan.GenericKD.47192208
EmsisoftTrojan.GenericKD.47192208 (B)
TrendMicroTROJ_GEN.R011C0GJH21
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
SophosDownload Assistant (PUA)
GDataWin32.Backdoor.Bodelph.HVJ6KP
MAXmalware (ai score=86)
ZoneAlarmTrojan-Downloader.Win32.Adload.tcyu
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacTrojan.GenericKD.47192208
VBA32TrojanDownloader.Adload
MalwarebytesAdware.DownloadAssistant
IkarusTrojan.NSIS.Agent
FortinetW32/multiple_detections
AVGNSIS:Downloader-ADB [Trj]
PandaTrj/CI.A
MaxSecureTrojan.Malware.173.susgen

How to remove Trojan-Downloader.Win32.Adload.tcyu?

Trojan-Downloader.Win32.Adload.tcyu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment