Trojan

About “Trojan-Downloader.Win32.Adload.tfyy” infection

Malware Removal

The Trojan-Downloader.Win32.Adload.tfyy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tfyy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.tfyy?


File Info:

name: 46A3C821B967DFF47EFE.mlw
path: /opt/CAPEv2/storage/binaries/aaa8588f1d78968821f006ea135dc9fcbfecdea118d77cc4e4b1a4a0fa9d5218
crc32: 798D3CA4
md5: 46a3c821b967dff47efe0b7bad83c06f
sha1: 4f65ca49a93aab4bfc575ba925b52789f826423e
sha256: aaa8588f1d78968821f006ea135dc9fcbfecdea118d77cc4e4b1a4a0fa9d5218
sha512: a028143c9d04e6b8691801fed8eec2fd5c221f0dc66d0fb90320a7aa71fd314a949d10aa8c60766e45af1d122e79386c0c4446ccd6ec89a1c9663ce87143baed
ssdeep: 98304:zh25/w2JZfx0Z28IrzG6+UeDS9ommOUJBbPWFxb+6yb//Z7H:F2TDyDIrz+Xc5txy6YXZ7H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3361211A2A3703BCC257675E495D2FC8FE66BA338D088732DF1EB9E2835655087BD24
sha3_384: 0df097bd688bdfffcb59fd0d6bbca07b67988c2ea15a165a6a47af760fbebb8a178757ea5d000098dc68c6d19e40a3f6
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-05-29 11:51:48

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Dolor Setup
FileVersion:
LegalCopyright:
ProductName: Dolor
ProductVersion: 1.9.14.17
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tfyy also known as:

LionicTrojan.Win32.Adload.a!c
MicroWorld-eScanGen:Variant.Midie.101463
ALYacGen:Variant.Midie.101463
CylanceUnsafe
SangforTrojan.Win32.Adload.tfyy
K7AntiVirusTrojan ( 005850dc1 )
AlibabaAdWare:Win32/AdLoad.316d0736
K7GWTrojan ( 005850dc1 )
CyrenW32/DownloadAssist.AV.gen!Eldorado
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tfyy
BitDefenderGen:Variant.Midie.101463
NANO-AntivirusTrojan.Win32.Adload.jnkxjl
AvastNSIS:Downloader-ADB [Trj]
TencentWin32.Trojan-downloader.Adload.Pdwd
Ad-AwareGen:Variant.Midie.101463
EmsisoftGen:Variant.Midie.101463 (B)
F-SecureHeuristic.HEUR/AGEN.1237231
DrWebTrojan.DownLoader43.52796
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
FireEyeGen:Variant.Midie.101463
SophosDownload Assistant (PUA)
AviraHEUR/AGEN.1237231
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Midie.D18C57
GDataWin32.Backdoor.Bodelph.BB4R09
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!46A3C821B967
MAXmalware (ai score=83)
VBA32Trojan.Sabsik.FL
MalwarebytesAdware.DownloadAssistant
IkarusTrojan.NSIS.Agent
MaxSecureTrojan.Malware.11012363.susgen
FortinetW32/Agent.CUJ!tr
AVGNSIS:Downloader-ADB [Trj]
PandaTrj/CI.A

How to remove Trojan-Downloader.Win32.Adload.tfyy?

Trojan-Downloader.Win32.Adload.tfyy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment