Trojan

About “Trojan-Downloader.Win32.Adload.tnyn” infection

Malware Removal

The Trojan-Downloader.Win32.Adload.tnyn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tnyn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.tnyn?


File Info:

name: 492109E00AEBDC67507F.mlw
path: /opt/CAPEv2/storage/binaries/47a0043c09ac86359976e98c460424887c38d27aef99d8626588a192e63b0062
crc32: 3B9388BB
md5: 492109e00aebdc67507f9ddd19e95d7a
sha1: c67718a16b8744746017b48cf622c9b79ba4d019
sha256: 47a0043c09ac86359976e98c460424887c38d27aef99d8626588a192e63b0062
sha512: dbcfd3c68fa515d8d56ee25c2ace587bfe123f72f9266529e5be406370a6ecfafc46afe92f52b21a7b676613a6e806cecc79432b9a2ce90738ef69c67ec7b233
ssdeep: 98304:qiZObOVMaIsmMRyHNrI43+t1Y0/u4UiSpq9pm3kVJG8r0hPV4lrwGcS:WbOVZIXhIMF4UiPakO8rOPWkRS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE26335F9D8448BCD58929BF4EE828E70513FD0AB6317C0578ECAC1DC52323D169BAA7
sha3_384: a1e26e752f1deb0c7fabcd9ca17156c36c07ae93ca1a72a67ae119c68ae172a07d8083c8e44e51d5874fe03747d3fd3d
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Optio Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan-Downloader.Win32.Adload.tnyn also known as:

DrWebTrojan.DownLoader44.13115
McAfeeArtemis!492109E00AEB
CylanceUnsafe
K7AntiVirusTrojan ( 005722fe1 )
AlibabaAdWare:Win32/AdLoad.09fb9da6
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DL821
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.tnyn
AvastWin32:DropperX-gen [Drp]
IkarusTrojan-Dropper.Win32.Agent
GDataWin32.Backdoor.Bodelph.W6UHIK
JiangminTrojanDownloader.Adload.aiod
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
MalwarebytesAdware.DownloadAssistant
FortinetW32/Agent.SLC!tr
AVGWin32:DropperX-gen [Drp]

How to remove Trojan-Downloader.Win32.Adload.tnyn?

Trojan-Downloader.Win32.Adload.tnyn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment