Trojan

Trojan-Downloader.Win32.Adload.tlsk removal guide

Malware Removal

The Trojan-Downloader.Win32.Adload.tlsk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tlsk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary

Related domains:

olustgtapi.live

How to determine Trojan-Downloader.Win32.Adload.tlsk?


File Info:

name: C901AB6D0B7F75544EA1.mlw
path: /opt/CAPEv2/storage/binaries/defefd5daff6a6600f1aadbbdfce9149f17c2f16b5bbce088da81cc0f46d8958
crc32: 0B3D6B32
md5: c901ab6d0b7f75544ea141853a1a5191
sha1: 5f5b8157e317d2e0e56f3081211276cb54450f90
sha256: defefd5daff6a6600f1aadbbdfce9149f17c2f16b5bbce088da81cc0f46d8958
sha512: 791d21869fc8f1eee2d6cf17affeb3e57ec71e8fb78a1b9e82a9dd26093ae622e75132b5de1e150ceede4f6482f6cb81a020466041dcd2f1d7c5fb9e960e21ad
ssdeep: 98304:R1QTnCrfbTEP+jo3ftU2deRa6phzcM+c65AlDPDto9ymtj3m8ChsJYq:XICrfbQWGftoa6nz36mVPDtRnfq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B436F1963B19D525C18AF370A6226240A0F7AE68F593DC2DF5F4F50CC77AAC02D2F256
sha3_384: 5e541fa1e688a16b12fdad3e76378b387246325fb1f4e2dd84818f9833f9b0d98a4d5dc8175c2327ad2ec9b866979fe5
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2021-07-22 05:43:38

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Itplicity, Inc.
FileDescription: IIViewer Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: IIViewer
ProductVersion:
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tlsk also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38104018
FireEyeTrojan.GenericKD.38104018
McAfeeArtemis!C901AB6D0B7F
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaAdWare:Win32/AdLoad.048d3187
K7GWTrojan ( 005722f11 )
K7AntiVirusTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan-Downloader.Win32.Adload.tlsk
BitDefenderTrojan.GenericKD.38104018
AvastWin32:Trojan-gen
TencentWin32.Trojan-downloader.Adload.Swub
Ad-AwareTrojan.GenericKD.38104018
EmsisoftTrojan.GenericKD.38104018 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
SophosMal/Generic-S
AviraHEUR/AGEN.1144245
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Backdoor.Bodelph.WYE9Q7
CynetMalicious (score: 100)
VBA32TrojanDownloader.Adload
ALYacTrojan.GenericKD.38104018
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CKM21
YandexTrojan.DL.Adload!/mZ7/pO7wxI
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Trojan-Downloader.Win32.Adload.tlsk?

Trojan-Downloader.Win32.Adload.tlsk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment