Trojan

Trojan-Downloader.Win32.Adload.tfks (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Adload.tfks is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tfks virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Trojan-Downloader.Win32.Adload.tfks?


File Info:

name: 1DF236A9D29023B2601C.mlw
path: /opt/CAPEv2/storage/binaries/eab4a808ddb7c331befd474d1ced9f0b0f1c19100b5073a4746a6592155494e7
crc32: 3971E04D
md5: 1df236a9d29023b2601ceed27a90942a
sha1: 972755889ed4fe8891f8942af44af156e9b8df92
sha256: eab4a808ddb7c331befd474d1ced9f0b0f1c19100b5073a4746a6592155494e7
sha512: ecc2c950164cd2e8d1b46c56ea0b27dbba551558a68554c553b03b9aadf249af25db5bb526c8174a4c82805d8c0d6beb5191b4416025a20f41f474b4badaf010
ssdeep: 98304:zyPoPJ+CZT8aRKVD9hEhZqa5qU8f6m1LB3CUmP6SIaLy/Z7H:mPoB+gKVB6h55gCm1LsHySpLsZ7H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18136111262A3743BDD253579E885E2FC5FD62B9738E580732DF0EB4E213528A087BD64
sha3_384: 2b093c96c66826cb1deef24b96b49dcd619580eabe69b85e46711ae70f207f7b1fbc6a989de12ebff1fccf90a14b99c4
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-05-29 11:51:48

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Aut Setup
FileVersion:
LegalCopyright:
ProductName: Aut
ProductVersion: 5.12.7.6
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tfks also known as:

LionicTrojan.Win32.Adload.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.101463
FireEyeGen:Variant.Midie.101463
McAfeeArtemis!1DF236A9D290
CylanceUnsafe
SangforTrojan.Win32.Adload.tfks
K7AntiVirusTrojan ( 0056e5201 )
AlibabaAdWare:Win32/AdLoad.2f2f6b89
K7GWTrojan ( 0056e5201 )
CyrenW32/DownloadAssist.AV.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tfks
BitDefenderGen:Variant.Midie.101463
AvastNSIS:Downloader-ADB [Trj]
TencentWin32.Trojan-downloader.Adload.Edok
Ad-AwareGen:Variant.Midie.101463
SophosDownload Assistant (PUA)
DrWebTrojan.DownLoader43.48931
TrendMicroTROJ_GEN.R03FC0WJO21
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
EmsisoftGen:Variant.Midie.101463 (B)
IkarusTrojan.NSIS.Agent
GDataGen:Variant.Midie.101463
AviraHEUR/AGEN.1237231
ArcabitTrojan.Midie.D18C57
ViRobotTrojan.Win32.Z.Sabsik.4953438
ZoneAlarmTrojan-Downloader.Win32.Adload.tfks
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
ALYacGen:Variant.Midie.101463
MAXmalware (ai score=85)
VBA32Trojan.Sabsik.FL
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R03FC0WJO21
MaxSecureTrojan.Malware.127305036.susgen
FortinetW32/Agent.CUJ!tr
AVGNSIS:Downloader-ADB [Trj]
PandaTrj/CI.A

How to remove Trojan-Downloader.Win32.Adload.tfks?

Trojan-Downloader.Win32.Adload.tfks removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment