Trojan

Trojan-Downloader.Win32.Adload.toaa removal tips

Malware Removal

The Trojan-Downloader.Win32.Adload.toaa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.toaa virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Downloader.Win32.Adload.toaa?


File Info:

name: F90376F2EB0FF486AE0D.mlw
path: /opt/CAPEv2/storage/binaries/470a41662baf6e593eeff8a4220924610f5968eaedfab339c98b4ac1af9d9939
crc32: 2C43A034
md5: f90376f2eb0ff486ae0d0483683e572b
sha1: 4502a6fc88af6ecb077d87e5f3d4645b470201cd
sha256: 470a41662baf6e593eeff8a4220924610f5968eaedfab339c98b4ac1af9d9939
sha512: 6edbb7f10fe4aa9d503ec52bca69a90bd934e2ced601de8fa84111e483664336c7dc014700666086321d432b69d06307b73a5e6b7ef74edafd43f9fcd4e8bb8f
ssdeep: 98304:qQytEUfSBrqfkN3ILawndSHlUQpTLV7J0PnFFBw/50ZQ3JwGcS:NVIIbEATLV90P9wv3GRS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18C263302CB0A48B6C12215F12C12E7F4A833273D78ADB4AB2057C91B5FF7698A75D797
sha3_384: 3d49cb677605f9e1f0654769a600bb3949b8f31797b0d3b27b2fffef54464d4f2bcf5e8c5c8462de8f5e81689fa053cb
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Officia Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan-Downloader.Win32.Adload.toaa also known as:

FireEyeGen:Variant.Adware.Cerbu.74750
McAfeeArtemis!F90376F2EB0F
CylanceUnsafe
K7AntiVirusTrojan ( 005722fe1 )
AlibabaAdWare:Win32/AdLoad.23769c3f
K7GWTrojan ( 005722fe1 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Adload.toaa
BitDefenderGen:Variant.Adware.Cerbu.74750
MicroWorld-eScanGen:Variant.Adware.Cerbu.74750
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Trojan-downloader.Adload.Ebpz
Ad-AwareGen:Variant.Adware.Cerbu.74750
EmsisoftGen:Variant.Adware.Cerbu.74750 (B)
DrWebTrojan.DownLoader44.13483
TrendMicroTROJ_GEN.R002C0WLC21
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.rc
SophosMal/Generic-S
GDataWin32.Backdoor.Bodelph.9XXR1X
JiangminTrojanDownloader.Adload.aiod
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.R457707
ALYacGen:Variant.Adware.Cerbu.74750
MAXmalware (ai score=64)
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002C0WLC21
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/CI.A

How to remove Trojan-Downloader.Win32.Adload.toaa?

Trojan-Downloader.Win32.Adload.toaa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment