Trojan

Trojan-Downloader.Win32.Zload.tm (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Zload.tm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Zload.tm virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Downloader.Win32.Zload.tm?


File Info:

crc32: A3A2BBA6
md5: fa7ad76b346b6cd410c3d53616cf28e8
name: upload_file
sha1: 4c3a5c1779676758b7f736f5c2fd2cdcd6e31b47
sha256: f3a538a0a43dc9a99a00e760764a0d43517beb25e832e763538ed29b5a9db058
sha512: dd404f992f6c55e419ced29e339645208f60453b6f476075c729f5e6d55d436712b7088a2eaf50de9c46d17c838510593eb34270fad4209bf7bf6dbb261a360c
ssdeep: 6144:ooPMXLGnQE9NphY64U/jMIuxF8RrnFnknZn3nRmn/nlnenvnxnGn5nPYnhnpanPl:1PMbGnLphKeMIuxKR0I/
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: 360realpro.exe
FileVersion: 8,8,0,1000
OriginalFilename: 360realpro.exe
ProductVersion: 8,8,0,1000
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Zload.tm also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44006849
FireEyeGeneric.mg.fa7ad76b346b6cd4
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.766145
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderThetaGen:NN.ZedlaF.34282.Ay9@aq9i6dli
SymantecPacked.Generic.459
TrendMicro-HouseCallTROJ_GEN.R002H0DJ720
KasperskyTrojan-Downloader.Win32.Zload.tm
AlibabaTrojan:Win32/GenKryptik.0c511935
AegisLabHacktool.Win32.Krap.lKMc
Ad-AwareTrojan.GenericKD.44006849
EmsisoftGen:Variant.Razy.766145 (B)
InvinceaML/PE-A
McAfee-GW-EditionArtemis!Trojan
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.C!ml
ZoneAlarmTrojan-Downloader.Win32.Zload.tm
GDataWin32.Trojan-Downloader.ZLoader.AV2AIV
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXAA-AA!FA7AD76B346B
VBA32BScope.Trojan.Diple
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.ETRL
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_100%
FortinetW32/Dridex.DD!tr
AVGFileRepMalware

How to remove Trojan-Downloader.Win32.Zload.tm?

Trojan-Downloader.Win32.Zload.tm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment