Trojan

Should I remove “Trojan-Downloader.Win32.Adload.tgge”?

Malware Removal

The Trojan-Downloader.Win32.Adload.tgge is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tgge virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.tgge?


File Info:

name: 7112359677C801D78213.mlw
path: /opt/CAPEv2/storage/binaries/2c5d0a68ba74875f315e63e8c3ce35a41c796a08a7648514fe92b1899bbfa929
crc32: 44395F70
md5: 7112359677c801d78213d5cf868b025f
sha1: 2d868ac3a12c2c7e648ba48eb6377f1d573e4def
sha256: 2c5d0a68ba74875f315e63e8c3ce35a41c796a08a7648514fe92b1899bbfa929
sha512: 6779ed571705508625bc8b95e90f8027df5899a11c3a20a0107d9405bd0238956fc78d0a528b0d6564cdb9c17c67dcc329694356c15669249a783d7c92f466c4
ssdeep: 98304:zh2FRISXNOF92uMCIh8cmb3VHce19ftNQ+HRY4EDBHvIpGntAIHVB2KQrGt/Z7H:d2FRW2upIKlb3hpmS3KIpGtAI1BsuZ7H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D361102A2A3347BDD253679E481E2FC4FD62BA734D084772CF0EB8E2976295587BD50
sha3_384: 6f47d62c027aff02bfc30c2c0078fbdd160abd33a92d4083d597671865bf185cf9b56b5d84e743a07e872aa7c290cfc7
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-05-29 11:51:48

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Est Setup
FileVersion:
LegalCopyright:
ProductName: Est
ProductVersion: 10.4.14.13
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tgge also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.101463
FireEyeGen:Variant.Midie.101463
ALYacGen:Variant.Midie.101463
CylanceUnsafe
SangforTrojan.Win32.Adload.tgge
K7AntiVirusTrojan ( 00587f231 )
AlibabaAdWare:Win32/AdLoad.982fa669
K7GWTrojan ( 00587f231 )
CyrenW32/DownloadAssist.AV.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tgge
BitDefenderGen:Variant.Midie.101463
AvastNSIS:Downloader-ADB [Trj]
Ad-AwareGen:Variant.Midie.101463
EmsisoftGen:Variant.Midie.101463 (B)
TrendMicroTROJ_GEN.R002C0WJO21
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
SophosDownload Assistant (PUA)
IkarusTrojan.NSIS.Agent
GDataWin32.Backdoor.Bodelph.WUC2TY
WebrootW32.Adware.Gen
AviraTR/NSIS.Agent.dmrcy
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!7112359677C8
VBA32Trojan.Tnega
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002C0WJO21
TencentWin32.Trojan-downloader.Adload.Adkc
YandexTrojan.DL.Adload!RpchyEptKzM
FortinetW32/Agent.CUJ!tr
AVGNSIS:Downloader-ADB [Trj]
PandaTrj/CI.A

How to remove Trojan-Downloader.Win32.Adload.tgge?

Trojan-Downloader.Win32.Adload.tgge removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment