Trojan

About “Trojan-Downloader.Win32.Adload.tlla” infection

Malware Removal

The Trojan-Downloader.Win32.Adload.tlla is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tlla virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

Related domains:

wpad.local-net
olustgtapi.live

How to determine Trojan-Downloader.Win32.Adload.tlla?


File Info:

name: 33BB7A966A87240A0224.mlw
path: /opt/CAPEv2/storage/binaries/166690d5aac36114d5f29a685f5d000fa38ef228849c420e468a8315b5b6865d
crc32: 4E91C8DD
md5: 33bb7a966a87240a02248b3bd3ecf863
sha1: 7e6aef5456b383b4961d10ad43e66b9af444d7c2
sha256: 166690d5aac36114d5f29a685f5d000fa38ef228849c420e468a8315b5b6865d
sha512: 32d4868032640630bd7b8e7a462c68de695b6623aea51bd624043616fa28c1c317bb67a5463c33e440d9e3e8a82dd13759dd36da9f5de4e77c1b89dcb6610684
ssdeep: 98304:/1QTZc9JTOw/zdlL2phJggLYYRK6k+L2MFrkWg/J91seyrsChIoQsV:9FJXLL2phCGYyK6kiFrkWg/J91shsaIq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5261227B299653EC49A37350673A01058FBB66DF417BE2677F0C48DCF660C01E3AA69
sha3_384: cbaec3a0727d1350a0dfd4b76b87c5225399106ff71a3bd5cb72b327ef7e585fe75d143c8bf86b59b9941d8fa57fac8a
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2021-07-22 05:43:38

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Gtplicity, Inc.
FileDescription: IGViewer Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: IGViewer
ProductVersion:
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tlla also known as:

LionicTrojan.Multi.Generic.4!c
McAfeeArtemis!33BB7A966A87
K7AntiVirusTrojan ( 005722f11 )
AlibabaAdWare:Win32/AdLoad.5d670c71
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tlla
AvastWin32:Trojan-gen
TencentWin32.Trojan-downloader.Adload.Lked
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
GDataWin32.Backdoor.Bodelph.WPPX3H
AviraHEUR/AGEN.1144245
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CKL21
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen

How to remove Trojan-Downloader.Win32.Adload.tlla?

Trojan-Downloader.Win32.Adload.tlla removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment