Trojan

TrojanDownloader:Win32/Adload!pz malicious file

Malware Removal

The TrojanDownloader:Win32/Adload!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Adload!pz virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine TrojanDownloader:Win32/Adload!pz?


File Info:

name: 9C9D065977406B936F85.mlw
path: /opt/CAPEv2/storage/binaries/1003714c6f8b8701728ef24992e8f3232ae3456f7a7b480674f5b48f527e1b4d
crc32: 161D9F2E
md5: 9c9d065977406b936f857eb66e765f14
sha1: 44bebc12e634e91076cde946716014a4a8c60996
sha256: 1003714c6f8b8701728ef24992e8f3232ae3456f7a7b480674f5b48f527e1b4d
sha512: 33b57f535d259d1aef6e3aa071a2a1785504e48183a93cb96a7cf43e0263348e19b86df1fe8a3a0882fc9bdcbe7853fbd6759d002e22e31693d9cf858698916c
ssdeep: 12288:vtOSJpWFJj39z5PTLEo/83hUCsBfAnJ42wArrR5r7f5:vt1Pc39zpT3/qRMom2wAPHh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9D47E22E6E14437C1B31B799C1BA3689C39BF112928B8467BF91D4C8F3D6913D292D7
sha3_384: 3ea779b0fe2fc48b7e9f81608ffe7cdd67162037b2ab9f06a53f6c204daf3a35e4c3e24922f84c06bc3f0456de6e5b95
ep_bytes: 558bec83c4f0b86cf34700e8546cf8ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

TrojanDownloader:Win32/Adload!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Delf.11
ClamAVWin.Downloader.Zard-9956821-0
FireEyeGeneric.mg.9c9d065977406b93
SkyhighBehavesLike.Win32.ObfuscatedPoly.hh
ALYacGen:Variant.Delf.11
Cylanceunsafe
ZillyaTrojan.Generic.Win32.529190
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojan:Win32/Sadenav.72dce35e
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_90% (D)
VirITTrojan.Win32.Generic.UTR
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Sadenav.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Adload.gen
BitDefenderGen:Variant.Delf.11
NANO-AntivirusTrojan.Win32.MLW.cooik
AvastWin32:Sadenav-I [Trj]
TencentMalware.Win32.Gencirc.10b35275
EmsisoftGen:Variant.Delf.11 (B)
F-SecureTrojan.TR/Sadenav.ikl
DrWebTrojan.DownLoad2.19273
VIPREGen:Variant.Delf.11
TrendMicroTROJ_AGENT_003032.TOMB
SophosMal/Overt-A
IkarusTrojan.Win32.Sadenav
GDataGen:Variant.Delf.11
JiangminTrojan/Generic.lewz
WebrootW32.Trojan.Downloader.Gen
GoogleDetected
AviraTR/Sadenav.ikl
Antiy-AVLTrojan[Downloader]/Win32.Adload
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.Downloader.Adload.SAD@4pq8hs
ArcabitTrojan.Delf.11
ZoneAlarmHEUR:Trojan-Downloader.Win32.Adload.gen
MicrosoftTrojanDownloader:Win32/Adload!pz
VaristW32/Banker.X.gen!Eldorado
AhnLab-V3Win-Trojan/Overtls15.Gen
McAfeeDownloader-COP.a
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallTROJ_AGENT_003032.TOMB
RisingTrojan.Win32.Fednu.fum (CLASSIC)
YandexTrojan.Sadenav!UkIOwHt/pVI
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Overt.A!tr
BitDefenderThetaGen:NN.ZelphiF.36744.LGW@aSNhWPbO
AVGWin32:Sadenav-I [Trj]
Cybereasonmalicious.2e634e
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Adload!pz?

TrojanDownloader:Win32/Adload!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment