Trojan

Trojan-Downloader.Win32.Adload.tpys (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Adload.tpys is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Adload.tpys virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Likely virus infection of existing system binary

How to determine Trojan-Downloader.Win32.Adload.tpys?


File Info:

name: 2E1A28026F68C0F9A6F7.mlw
path: /opt/CAPEv2/storage/binaries/2703713da848f39fb24f9c41d0c19e792b5766a78db5b623c0272b231b6a363d
crc32: 28E82B1E
md5: 2e1a28026f68c0f9a6f75a5955953128
sha1: c3c30baed561222f6c972a4731e77356f227fd18
sha256: 2703713da848f39fb24f9c41d0c19e792b5766a78db5b623c0272b231b6a363d
sha512: 21ce99bee771e55060d46a21c5b16096e516d522bf9375a814499a074e287f3485c5435a814a31235256e07ca5f960da3028aaa4d7ab7f2c4c57253ef0e490e0
ssdeep: 98304:MrGNFmS++r4rXW6MhYJDC9+1rlpDSVPToY3e8rjn1DecmM2ARJdxWKlat:6Gj1SW7hOOspaPy8rL1F52+f1gt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1572633E6D1EF907EE674E73A1D64EE2D214B2C000D746608734C9BCEDBB2297F46A215
sha3_384: d85adab4b064456206ec55f0e8328a39ae60745369bc5e968d2095640024abb4673089c4b229b214f6e5d95e761e5912
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: DbitsSoft
FileDescription: Icture Doctor Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan-Downloader.Win32.Adload.tpys also known as:

LionicTrojan.Win32.Adload.a!c
MalwarebytesAdware.DownloadAssistant
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
CyrenW32/Agent.DWZ.gen!Eldorado
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0CLJ21
Paloaltogeneric.ml
ClamAVWin.Malware.Filerepmalware-9916442-0
KasperskyTrojan-Downloader.Win32.Adload.tpys
AlibabaAdWare:Win32/AdLoad.01534ab8
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
JiangminTrojanDownloader.Adload.aina
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Backdoor.Bodelph.O9ELLB
McAfeeArtemis!2E1A28026F68
VBA32TrojanDownloader.Adload
CylanceUnsafe
PandaTrj/CI.A
YandexTrojan.DL.Adload!g52767knfbc
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Trojan-Downloader.Win32.Adload.tpys?

Trojan-Downloader.Win32.Adload.tpys removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment