Trojan

Trojan-Downloader.Win32.Adload.tntt (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Adload.tntt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tntt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.tntt?


File Info:

name: 601AEF4804A8640C4CDE.mlw
path: /opt/CAPEv2/storage/binaries/b57706edcc214124a7e1cf631c16ebc587c7c432a3e6aedd09dd6186177f018b
crc32: 79B41591
md5: 601aef4804a8640c4cdef3380158b630
sha1: 4f9d785ca3841684074d36a7a290e47cd4173799
sha256: b57706edcc214124a7e1cf631c16ebc587c7c432a3e6aedd09dd6186177f018b
sha512: 26e29dc67276ca22eafa691c8ab0d083634a45b552bbff90e5de86e29b1d0ce345cceb7cc1783683efac7e5db3734deaec490d06e4f15dd60f5db1e32dec8a1a
ssdeep: 98304:MOXwJGDgg4A6FpPrNbEkpYo51u+FgDgTFIHl8WAKOeJs1RNihylat:jg5VhbbpYE13gDghIFKeuLIhygt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1112633798FE5827AE440E57C6FF6A3EC93306138221A15A4B5EB59493EFE570183C70B
sha3_384: dd7545f975117de96e07f8948c6bfb9c25ccd8c7d44f7f8328cd79c7f7d5bd43e19bdf10b6f0ed0f08c67aab7f839929
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Incidunt Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan-Downloader.Win32.Adload.tntt also known as:

LionicTrojan.Win32.Adload.a!c
CylanceUnsafe
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tntt
AvastWin32:Trojan-gen
TencentWin32.Trojan-downloader.Adload.Wkby
SophosMal/Generic-S
DrWebTrojan.DownLoader44.12033
McAfee-GW-EditionArtemis
IkarusTrojan-Dropper.Win32.Agent
GDataWin32.Backdoor.Bodelph.YL2XBI
JiangminTrojanDownloader.Adload.aina
AviraTR/Drop.Agent.ahrtz
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!601AEF4804A8
VBA32TrojanDownloader.Adload
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002H0CL721
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen

How to remove Trojan-Downloader.Win32.Adload.tntt?

Trojan-Downloader.Win32.Adload.tntt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment