Trojan

About “Trojan-Downloader.Win32.Adload.tlwc” infection

Malware Removal

The Trojan-Downloader.Win32.Adload.tlwc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tlwc virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

Related domains:

olustgtapi.live

How to determine Trojan-Downloader.Win32.Adload.tlwc?


File Info:

name: FEF52EB61B2BA2D9892E.mlw
path: /opt/CAPEv2/storage/binaries/87726fd93541d9f85eae07fe8b91bdac8aca1fe2c0093057b6d35e8f1b82d69c
crc32: 2510B5CF
md5: fef52eb61b2ba2d9892e76ea98b818f9
sha1: 101346e9e8168e0481b71ec2bc719d6b0cf8442a
sha256: 87726fd93541d9f85eae07fe8b91bdac8aca1fe2c0093057b6d35e8f1b82d69c
sha512: 228e3f24a0119560a0ded91d6128abb9e34cb9226496fe0244ccda8644f147cf0c057a919dded69e59437b8b16e2aa0b09479d2202e4da5f88745c72378b0ed6
ssdeep: 98304:21QThUo+P36jEFKkWBxR34peQZRrLHKoSTYtG91K0U70ZMjMOiq:6kUoK3oEFKNxxkPr7HS8tC1Kz7B
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C2361227BB8CE43ED06927344172E11448FFAA6DE527AE16A6F4D49CCF796C01D3B212
sha3_384: ed66589e0024725b7964ded99f44d1ed461d971f183d32975494fc570845aa736ac97103f2315d10247d33b95bb32fb7
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2021-07-22 05:43:38

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Jtplicity, Inc.
FileDescription: IJViewer Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: IJViewer
ProductVersion:
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tlwc also known as:

LionicTrojan.Win32.Adload.a!c
Elasticmalicious (high confidence)
K7AntiVirusTrojan ( 005722f11 )
AlibabaAdWare:Win32/AdLoad.80731933
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tlwc
AvastWin32:Trojan-gen
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1144245
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
GDataWin32.Backdoor.Bodelph.J5ZTXR
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1144245
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Script/Phonzy.C!ml
CynetMalicious (score: 100)
McAfeeArtemis!FEF52EB61B2B
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CKN21
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen

How to remove Trojan-Downloader.Win32.Adload.tlwc?

Trojan-Downloader.Win32.Adload.tlwc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment