Trojan

How to remove “Trojan-Downloader.Win32.Adload.tgqv”?

Malware Removal

The Trojan-Downloader.Win32.Adload.tgqv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tgqv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.tgqv?


File Info:

name: A9515CC141411B58F5A3.mlw
path: /opt/CAPEv2/storage/binaries/952d369c876dd0676fd9a5dacdbd5c540ce21a2a71bfd57774ff0d345bbfdb78
crc32: 26EDB259
md5: a9515cc141411b58f5a3b18bc0bddc9a
sha1: db043bdf9ae786ea7b3fc16751ccaf8a8e3b146d
sha256: 952d369c876dd0676fd9a5dacdbd5c540ce21a2a71bfd57774ff0d345bbfdb78
sha512: 1e81a9f062d412646ac226abf9e9f3fdacfda6351ca1f490245e0455aa53f885deb42e7d34b3d5490ff30cd5afddfac2c29a1130684c2844622aa6fcdeaff8c7
ssdeep: 98304:zmQp/zEvWHDggEMB29eGh+nSuLmLxrDPU0/R2rUBZRDGVkasflIV7YOj7BL9/Z7H:UJDMB2/h+n1Lm5Thpbw+KF/BLdZ7H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115361222A293743BCC263579D485D2FD9FD62BA338E084732CF4EB5E6976591087BD20
sha3_384: be65062de8b58f79dd0a63986d4e0cc6ffc1de932f8650ee32d034e9125b8e2776d1b0cf1986c45990bda35f5b873ea8
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-05-29 11:51:48

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Excepturi Setup
FileVersion:
LegalCopyright:
ProductName: Excepturi
ProductVersion: 7.10.4.3
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tgqv also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.101463
FireEyeGen:Variant.Midie.101463
McAfeeArtemis!A9515CC14141
CylanceUnsafe
SangforTrojan.Win32.Adload.tgqv
K7AntiVirusTrojan ( 00587f231 )
AlibabaAdWare:Win32/AdLoad.32d01788
K7GWTrojan ( 00587f231 )
CyrenW32/Agent.CWT.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tgqv
BitDefenderGen:Variant.Midie.101463
AvastNSIS:Downloader-ADB [Trj]
TencentWin32.Trojan-downloader.Adload.Lmub
Ad-AwareGen:Variant.Midie.101463
EmsisoftGen:Variant.Midie.101463 (B)
TrendMicroTROJ_GEN.R002C0WJP21
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
SophosDownload Assistant (PUA)
IkarusTrojan.NSIS.Agent
AviraHEUR/AGEN.1145728
MicrosoftTrojan:Win32/Mamson.A!ac
GDataGen:Variant.Midie.101463
CynetMalicious (score: 100)
VBA32Trojan.Wacatac
ALYacGen:Variant.Midie.101463
MAXmalware (ai score=82)
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002C0WJP21
MaxSecureTrojan.Malware.127313641.susgen
FortinetW32/Agent.CUJ!tr
WebrootW32.Adware.Gen
AVGNSIS:Downloader-ADB [Trj]
PandaTrj/CI.A

How to remove Trojan-Downloader.Win32.Adload.tgqv?

Trojan-Downloader.Win32.Adload.tgqv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment