Trojan

Trojan-Downloader.Win32.Adload.tltu removal instruction

Malware Removal

The Trojan-Downloader.Win32.Adload.tltu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tltu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

Related domains:

wpad.local-net
olustgtapi.live

How to determine Trojan-Downloader.Win32.Adload.tltu?


File Info:

name: 767B70D3E0BD83CAEC29.mlw
path: /opt/CAPEv2/storage/binaries/174c071f2b446a784b247e4bfefc63cab2418ce091f9e2e9d99b85f80c048cf8
crc32: 783A7B50
md5: 767b70d3e0bd83caec2972442b08fc9e
sha1: 906883bef415aa55152535903b713f21f4f50cbe
sha256: 174c071f2b446a784b247e4bfefc63cab2418ce091f9e2e9d99b85f80c048cf8
sha512: 00612efd3d9e6f10046c5541a4f1eb79c6be702cf3531db708c7c38d2d97a79f819c5486d7fc31dda49bf0431db440e100700ec770d7afd73860c3ce0e447437
ssdeep: 98304:R1QTnWbnWiyJxcj6KPfqy8PmrWE0i+2G3m8ChsJYq:XIWqiQunH4miE/fq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18D36F1953B19D525C19EA370A7236280A4F7AE28B593DD2DF5F4F40CC73AAC02D2F256
sha3_384: 38c155f38bea129d49a98050bc993558b03906362ae5b70d4766da906b7ed29cfdb8b52ba189454e3da5ebd680007e94
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2021-07-22 05:43:38

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Itplicity, Inc.
FileDescription: IIViewer Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: IIViewer
ProductVersion:
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tltu also known as:

LionicTrojan.Win32.Adload.a!c
Elasticmalicious (high confidence)
K7AntiVirusTrojan ( 005722f11 )
AlibabaAdWare:Win32/AdLoad.b1c39a23
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tltu
AvastWin32:Trojan-gen
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
GDataWin32.Backdoor.Bodelph.1R3SPF
AviraHEUR/AGEN.1144245
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Script/Phonzy.C!ml
CynetMalicious (score: 100)
McAfeeArtemis!767B70D3E0BD
VBA32TrojanDownloader.Adload
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CKN21
TencentWin32.Trojan-downloader.Adload.Ahot
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen

How to remove Trojan-Downloader.Win32.Adload.tltu?

Trojan-Downloader.Win32.Adload.tltu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment