Trojan

Trojan-Downloader.Win32.Zload.ug (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Zload.ug is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Zload.ug virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Zload.ug?


File Info:

crc32: 468FCF93
md5: 00d27f790f830e1aadbb63716245a0f7
name: upload_file
sha1: e9f568ac46d96b099baace9495668288ebaad54e
sha256: de0eea8bc0e496186731bd8f46f91ee535a76f97ada7840380902b6a97dbf1e3
sha512: 24f9b752024e18152eee925fd4d2a16bce5eec860d767fdabcd18b8238f9247e151bc6d04f3285211f76a6985cba7e59872d45429a327b910ec1233a5c1ebcfa
ssdeep: 6144:Ds3ToPMXLGnQE9NphY64U/jMIuxF8RrnFnknZn3nRmn/nlnenvnxnGn5nPYnhnp6:A3EPMbGnLphKeMIuxKRUW
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: 360realpro.exe
FileVersion: 8,8,0,1000
OriginalFilename: 360realpro.exe
ProductVersion: 8,8,0,1000
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Zload.ug also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.00d27f790f830e1a
Qihoo-360HEUR/QVM40.1.6AAF.Malware.Gen
McAfeeGenericRXAA-AA!00D27F790F83
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_100% (D)
InvinceaML/PE-A
BitDefenderThetaGen:NN.ZedlaF.34282.Ay9@aKjwBqci
SymantecPacked.Generic.459
KasperskyTrojan-Downloader.Win32.Zload.ug
AlibabaTrojan:Win32/GenKryptik.0c511935
McAfee-GW-EditionArtemis!Trojan
IkarusTrojan.Win32.Krypt
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.C!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan-Downloader.ZLoader.WMNBX0
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Diple
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.ETRL
eGambitUnsafe.AI_Score_100%
FortinetW32/Dridex.DD!tr
AVGFileRepMalware

How to remove Trojan-Downloader.Win32.Zload.ug?

Trojan-Downloader.Win32.Zload.ug removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment