Trojan

What is “Trojan-Downloader.Win32.Adload.tnol”?

Malware Removal

The Trojan-Downloader.Win32.Adload.tnol is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tnol virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.tnol?


File Info:

name: A9CBE5C93393AE320DBD.mlw
path: /opt/CAPEv2/storage/binaries/c6607e0a5288ff191b8a0ee38aaac36a217e72328d4a5bcadd96bb1aa566d2cc
crc32: 764206BC
md5: a9cbe5c93393ae320dbd2b83493d98b3
sha1: 635dc41bdf74995cee055ace3f4eac0fbd14c2cb
sha256: c6607e0a5288ff191b8a0ee38aaac36a217e72328d4a5bcadd96bb1aa566d2cc
sha512: a720d3c8a0d56f023b6996bd9a41babf77eda04535b917c490333b3356d6393f3104163ecc4fbeab46895ea5bbea2a2279bdc3f3c1ca8392d74d60e2c515217d
ssdeep: 98304:MxPa9scZ5FlCGL2vnQ+ZDBoFQEu8eoDaom5rNZoi7YChHz57rtiFVOVxRlat:wPChZ5PCRNd8U8LPm5rLl17rtqEbRgt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T179363365F3E18078D955483B0C36C1B0B9D3BE1A0B9B5A6A138852C97F7AB30BC77365
sha3_384: afa0e3571e0bed3147e47fb253db68a3d73196ab7d0c84982341dc3740399ed5ae126c4da4e08b8da01d34209445c509
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Officiis Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan-Downloader.Win32.Adload.tnol also known as:

LionicTrojan.Win32.Adload.a!c
McAfeeArtemis!A9CBE5C93393
MalwarebytesAdware.DownloadAssistant
K7AntiVirusTrojan ( 005722fe1 )
AlibabaAdWare:Win32/AdLoad.66c736f8
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tnol
AvastWin32:Trojan-gen
TencentWin32.Trojan-downloader.Adload.Lplj
DrWebTrojan.DownLoader44.11585
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataWin32.Backdoor.Bodelph.QEAQCV
JiangminTrojanDownloader.Adload.aina
WebrootW32.Adware.Gen
AviraTR/Drop.Agent.lyrty
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
VBA32TrojanDownloader.Adload
TrendMicro-HouseCallTROJ_GEN.R002H0DL621
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Downloader.Win32.Adload.tnol?

Trojan-Downloader.Win32.Adload.tnol removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment