Trojan

What is “Trojan-Downloader.Win32.Adload.tlyd”?

Malware Removal

The Trojan-Downloader.Win32.Adload.tlyd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tlyd virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

Related domains:

wpad.local-net
olustgtapi.live

How to determine Trojan-Downloader.Win32.Adload.tlyd?


File Info:

name: 02CBBFE626CA169CBA87.mlw
path: /opt/CAPEv2/storage/binaries/a8f1e068684deb166c73fcf8a76b50e299051215c6a8ce3dd26a2dfc25e9d06a
crc32: 8AFB9E16
md5: 02cbbfe626ca169cba87a1eafeb8c7fc
sha1: 3a51e3f55d536e2a886ea5cb018617e8ca51db4d
sha256: a8f1e068684deb166c73fcf8a76b50e299051215c6a8ce3dd26a2dfc25e9d06a
sha512: 22cd7e8e448df308b4c18b350570ece2f16466ef705647e1ba86902ad74db8b287ef39695dc1928a454d8b5a17cb5f5556f01acb0cd4f268bccb0eed7408030a
ssdeep: 98304:D1QT1d09m+vMvOZmjPTKfXKGnuHcuzINHf91ihuaAiXLYeUn:p+S92skTzGnuHN0/XhaLYeO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3261227F289753EC4AA27354673A42058FBB669F416BE1637F0C48CCF764C01E3AA65
sha3_384: 7d40765f583255153431d2624e8f96274ca8d9212f371be3284550b9f5d12b8e2e5294ea5cd9f7a1a453550480dd1715
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2021-07-22 05:43:38

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Ktplicity, Inc.
FileDescription: IKViewer Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: IKViewer
ProductVersion:
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tlyd also known as:

LionicTrojan.Win32.Adload.a!c
Elasticmalicious (high confidence)
McAfeeArtemis!02CBBFE626CA
K7AntiVirusTrojan ( 005722f11 )
AlibabaAdWare:Win32/AdLoad.8094a11e
K7GWTrojan ( 005722f11 )
CyrenW32/Agent.DPY.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tlyd
AvastWin32:Trojan-gen
TencentWin32.Trojan-downloader.Adload.Fih
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.CSDImonetize.rc
IkarusTrojan-Dropper.Win32.Agent
GDataWin32.Backdoor.Bodelph.4DHPOJ
AviraHEUR/AGEN.1144245
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CKO21
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen

How to remove Trojan-Downloader.Win32.Adload.tlyd?

Trojan-Downloader.Win32.Adload.tlyd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment