Trojan

What is “Trojan-Downloader.Win32.Adload.tmpl”?

Malware Removal

The Trojan-Downloader.Win32.Adload.tmpl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tmpl virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits possible ransomware file modification behavior
  • Likely virus infection of existing system binary

How to determine Trojan-Downloader.Win32.Adload.tmpl?


File Info:

name: 2FB062AC13902184F401.mlw
path: /opt/CAPEv2/storage/binaries/a6e3ed8d8c0a2ae556c2472b819e0d1ff7d52c18c959106a829058cd94e9c7b5
crc32: E297B10E
md5: 2fb062ac13902184f401125c2922e78d
sha1: 83082604bf07d44439e49da6a407fc16b7dc96ae
sha256: a6e3ed8d8c0a2ae556c2472b819e0d1ff7d52c18c959106a829058cd94e9c7b5
sha512: b25911d1b34f6b84adcff6174bbad5e1bb9f110a40a76b726949be90ce5a4332d82e24cf9c3cc3bc12642e5751369f39346d8aea6a95b9c06f265c36b4d21143
ssdeep: 98304:LEJTTwTOZqtDThGjdnP5J2KbHcA2csZ34nWblFbFgaPCzJU4dO3QBDDKzhsI6nid:yiTUzNrcLHZ38Whx2aPszQP2X1nWB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D486223F7268653ED0AA0B3245738260697BBF91B81ACC1E17F0391DDF765602E3EA15
sha3_384: 2426af395e6b54883fa531607caf13886cf38dec4bf3c234fc7c50e8cb067389daff226f18251e694eca24890698db18
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-03-14 17:59:41

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Isl Usage Analyzer Free 1.6.3.0 Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Isl Usage Analyzer Free 1.6.3.0
ProductVersion:
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Adload.tmpl also known as:

MicroWorld-eScanTrojan.GenericKD.38151542
FireEyeTrojan.GenericKD.38151542
CAT-QuickHealTrojanDownloader.Adload
ALYacTrojan.GenericKD.38151542
SangforTrojan.Win32.Adload.tmpl
K7AntiVirusTrojan ( 005722f11 )
AlibabaAdWare:Win32/AdLoad.f84fa512
K7GWTrojan ( 005722f11 )
Cybereasonmalicious.4bf07d
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002C0WL121
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tmpl
BitDefenderTrojan.GenericKD.38151542
AvastWin32:Trojan-gen
TencentWin32.Trojan-downloader.Adload.Hvtg
Ad-AwareTrojan.GenericKD.38151542
EmsisoftTrojan.GenericKD.38151542 (B)
TrendMicroTROJ_GEN.R002C0WL121
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
SophosMal/Generic-S
APEXMalicious
GDataWin32.Backdoor.Bodelph.CKSVR8
AviraHEUR/AGEN.1144245
MAXmalware (ai score=85)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Sabsik!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R455676
McAfeeArtemis!2FB062AC1390
VBA32TrojanDownloader.Adload
MalwarebytesAdware.DownloadAssistant
IkarusTrojan-Dropper.Win32.Agent
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Downloader.Win32.Adload.tmpl?

Trojan-Downloader.Win32.Adload.tmpl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment