Trojan

How to remove “Trojan-Downloader.Win32.Adload.tehb”?

Malware Removal

The Trojan-Downloader.Win32.Adload.tehb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tehb virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.tehb?


File Info:

name: 697507AB064396CEB2E7.mlw
path: /opt/CAPEv2/storage/binaries/478a69b957aaf3e821af24d23a2250d30fd1861e3f4bf22a2f317f2326ec27d8
crc32: 49C05B25
md5: 697507ab064396ceb2e7344898526305
sha1: add18e872262862c9b01460168b2d1d4f3725477
sha256: 478a69b957aaf3e821af24d23a2250d30fd1861e3f4bf22a2f317f2326ec27d8
sha512: 1915eeab58e0fdb2e9de0ecf6a36d445130b5c0e4d655255ae4a0331f8368d94bb5e890e889f18cae58c8e60c2fa9a761bf20187913da24cee79e5519d75d6fd
ssdeep: 49152:PBU+BFVuYaM3jQkbCtsvQhZJIKEX/We+B8KkLCFf7/jMnOSURxmOwwZqy3:ZHug7E8K2mfEOSSxTwUr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B063303B7C3407DEA950938989544285D736EA934F660B82EF9C94F1F7C7C294BEBA1
sha3_384: 3ccd419db24657976d76f2fa5b960f89afbd332864a5a8760116528a0f5721c45e4f0afac45054d4c08bcd1599171866
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-05-29 11:51:48

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Recusandae Setup
FileVersion:
LegalCopyright:
ProductName: Recusandae
ProductVersion: 5.19.19.5
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tehb also known as:

LionicTrojan.Win32.Adload.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47207365
FireEyeTrojan.GenericKD.47207365
ALYacTrojan.GenericKD.47207365
CylanceUnsafe
SangforTrojan.Win32.Agent.SLC
K7AntiVirusTrojan ( 00587f231 )
AlibabaAdWare:Win32/AdLoad.f70cb3fb
K7GWTrojan ( 00587f231 )
CyrenW32/Adload.FV.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9908274-0
KasperskyTrojan-Downloader.Win32.Adload.tehb
BitDefenderTrojan.GenericKD.47207365
AvastNSIS:Downloader-ADB [Trj]
TencentWin32.Trojan-downloader.Adload.Wptl
Ad-AwareTrojan.GenericKD.47207365
EmsisoftTrojan.GenericKD.47207365 (B)
ComodoMalware@#1pok2n58uz0cf
DrWebTrojan.DownLoader43.46468
TrendMicroTROJ_GEN.R011C0WJK21
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
SophosDownload Assistant (PUA)
IkarusTrojan.NSIS.Agent
GDataWin32.Backdoor.Bodelph.JK79O8
AviraHEUR/AGEN.1237231
ArcabitTrojan.Generic.D2D053C5
ViRobotTrojan.Win32.Z.Agent.3765389
ZoneAlarmTrojan-Downloader.Win32.Adload.tehb
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!697507AB0643
MAXmalware (ai score=81)
VBA32TrojanDownloader.Adload
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R011C0WJK21
MaxSecureTrojan.Malware.127007690.susgen
FortinetW32/multiple_detections
AVGNSIS:Downloader-ADB [Trj]
PandaTrj/CI.A

How to remove Trojan-Downloader.Win32.Adload.tehb?

Trojan-Downloader.Win32.Adload.tehb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment