Trojan

What is “Trojan-Downloader.Win32.Adload.tnzs”?

Malware Removal

The Trojan-Downloader.Win32.Adload.tnzs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tnzs virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.tnzs?


File Info:

name: A0417B2354441B59C971.mlw
path: /opt/CAPEv2/storage/binaries/3e41ffdc9b76b2115abc2f3e075b89380820d789c7107500dcec368389e2b2c2
crc32: 66F96286
md5: a0417b2354441b59c9714c69d862c73c
sha1: 97ec1595c10f101eb25be8a0323c6a4f513fcde5
sha256: 3e41ffdc9b76b2115abc2f3e075b89380820d789c7107500dcec368389e2b2c2
sha512: b27377c48e5445318662786503a006654cfd970c4591e809f44bbb8e565d1431e381f0eae3ddd85178954ea4a310e65a28296a75b3a0fb10f6ffd5b95016d792
ssdeep: 98304:qt3hpgqEhj6c4sr0SN7R2ShMBWlV45J646IWdHp96tPI9Sd+DzucNVpwGcS:c3hmtldr0w78ShcWX4K46F36tPASdKzv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19926330623D981B5E89084342E12970B9D379DFF5839115DFD7CA0981E7BEE6BC4E38A
sha3_384: 6f6cb88b3852046d0fd9370ad0af5cba37f84fbb2aa44a3909cea01c443e47df587d8e3701af3bda48b32a0db345802d
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Ipsum Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan-Downloader.Win32.Adload.tnzs also known as:

LionicTrojan.Win32.Adload.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Cerbu.74750
FireEyeGen:Variant.Adware.Cerbu.74750
ALYacGen:Variant.Adware.Cerbu.74750
CylanceUnsafe
AlibabaAdWare:Win32/AdLoad.6f1c10e7
CyrenW32/Adload.GK.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
ClamAVWin.Adware.Cerbu-9917285-0
KasperskyTrojan-Downloader.Win32.Adload.tnzs
BitDefenderGen:Variant.Adware.Cerbu.74750
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Trojan-downloader.Adload.Lizp
Ad-AwareGen:Variant.Adware.Cerbu.74750
EmsisoftGen:Variant.Adware.Cerbu.74750 (B)
DrWebTrojan.DownLoader44.13476
TrendMicroTROJ_GEN.R002C0WLC21
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
GDataWin32.Backdoor.Bodelph.BWAGGY
JiangminTrojanDownloader.Adload.aiod
WebrootW32.Adware.Gen
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Adware.Cerbu.D123FE
MicrosoftTrojan:Win32/Mamson.A!ac
AhnLab-V3Trojan/Win.Generic.R457707
McAfeeArtemis!A0417B235444
MAXmalware (ai score=61)
VBA32TrojanDownloader.Adload
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002C0WLC21
FortinetW32/Agent.SLC!tr
AVGWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Downloader.Win32.Adload.tnzs?

Trojan-Downloader.Win32.Adload.tnzs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment