Trojan

Trojan-Downloader.Win32.Adload.tekg removal

Malware Removal

The Trojan-Downloader.Win32.Adload.tekg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tekg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.tekg?


File Info:

name: 5C7C4A0812AE25EB0CF4.mlw
path: /opt/CAPEv2/storage/binaries/0659c75eba2cd1ed4f4fc7f7793284165d2fc5c0bc1bb62939efa3750f359ee9
crc32: 3D74977E
md5: 5c7c4a0812ae25eb0cf47d4c01499e5d
sha1: 73b319b0e8c16ed2e6ecc3603fc0b7e95488e0c2
sha256: 0659c75eba2cd1ed4f4fc7f7793284165d2fc5c0bc1bb62939efa3750f359ee9
sha512: 324889bd635fd10f07a5eb33d0149a2593811de093e26fc6f1ecc7128dd1ea7cc64f85d908e07ce25f438aaa5841067be2ce7752911136c4c37419f268312a6f
ssdeep: 49152:PdIfjdYRXsMnZrYIgRXsecoyx5gUBZ9mX/N/G5rQB7q4xEWifbf5AeMWCwwZqy3:lojyd5YIOXstx6UHCGKq6EWuzGJDwUr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11506334273D30071F280167C545684A82FB7BEE42AE1543E7EFADA0D57B9A864C7B8F1
sha3_384: 307b5d6a2dc3a844f5b914ce9e8230329077717db8f629a03292d65ddc64d338e93a3bb3e243fc7dc9d9e3bc368264be
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-05-29 11:51:48

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Dolores Setup
FileVersion:
LegalCopyright:
ProductName: Dolores
ProductVersion: 10.3.1.13
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tekg also known as:

LionicTrojan.Win32.Adload.a!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader43.46796
MicroWorld-eScanTrojan.GenericKD.47204509
FireEyeTrojan.GenericKD.47204509
McAfeeArtemis!5C7C4A0812AE
CylanceUnsafe
SangforTrojan.Win32.Adload.tekg
K7AntiVirusTrojan ( 00587f231 )
AlibabaAdWare:Win32/AdLoad.9d6cd5ab
K7GWTrojan ( 00587f231 )
CyrenW32/Adload.FV.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R011C0WJL21
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9908274-0
KasperskyTrojan-Downloader.Win32.Adload.tekg
BitDefenderTrojan.GenericKD.47204509
AvastNSIS:Downloader-ADB [Trj]
TencentWin32.Trojan-downloader.Adload.Sxyq
Ad-AwareTrojan.GenericKD.47204509
EmsisoftTrojan.GenericKD.47204509 (B)
TrendMicroTROJ_GEN.R011C0WJL21
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
SophosDownload Assistant (PUA)
IkarusTrojan.NSIS.Agent
GDataWin32.Backdoor.Bodelph.06YQ0C
AviraHEUR/AGEN.1145728
ArcabitTrojan.Generic.D2D0489D
ViRobotTrojan.Win32.Z.Agent.3796053
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32TrojanDownloader.Adload
ALYacTrojan.GenericKD.47204509
MAXmalware (ai score=80)
MalwarebytesAdware.DownloadAssistant
FortinetW32/Agent.CKH!tr
AVGNSIS:Downloader-ADB [Trj]

How to remove Trojan-Downloader.Win32.Adload.tekg?

Trojan-Downloader.Win32.Adload.tekg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment