Trojan

Should I remove “Trojan-Downloader.Win32.Adload.tkih”?

Malware Removal

The Trojan-Downloader.Win32.Adload.tkih is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tkih virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Downloader.Win32.Adload.tkih?


File Info:

crc32: 8EEE2C69
md5: c11d5a8298340d1301f752928505b678
name: C11D5A8298340D1301F752928505B678.mlw
sha1: df368e47fdb6bf314f962bd280b29f500b5c688c
sha256: b2763840220eeb812ac79f72e932044195931f1b0228a68df4e841afdbbb4fda
sha512: d5facc2ec68919a1ca218603dbd7a0ae41b9d9bb77360d0f2532fedab3560e7b2a44690e90b7a4a77df18709b01004b337b4004b6bba21a50997b17e4d101ce9
ssdeep: 98304:c1QTLLdjw/Vx27l+joN+iF92e5Efxi4B9OybRuZxF2DcjuroIu2WutPKrsb8q:4oLddR+sNueRmOUtDcmoIu2Wuf8q
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Tam Rich Ltd
Comments: This installation was built with Inno Setup.
ProductName: coHunter
ProductVersion:
FileDescription: coHunter Setup
OriginalFileName:
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tkih also known as:

K7AntiVirusTrojan ( 005722f11 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
AlibabaAdWare:Win32/AdLoad.9219c3a2
K7GWTrojan ( 005722f11 )
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Downloader.Win32.Adload.tkih
BitDefenderTrojan.GenericKD.47444875
MicroWorld-eScanTrojan.GenericKD.47444875
TencentWin32.Trojan-downloader.Adload.Sudp
Ad-AwareTrojan.GenericKD.47444875
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeTrojan.GenericKD.47444875
EmsisoftTrojan.GenericKD.47444875 (B)
AviraHEUR/AGEN.1144245
MicrosoftTrojan:Script/Phonzy.C!ml
GDataWin32.Backdoor.Bodelph.D02S3T
McAfeeArtemis!C11D5A829834
MAXmalware (ai score=89)
VBA32Trojan.Sabsik.FL
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CKE21
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan-Downloader.Win32.Adload.tkih?

Trojan-Downloader.Win32.Adload.tkih removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment