Trojan

What is “Win32/TrojanDownloader.Adload.NTZ”?

Malware Removal

The Win32/TrojanDownloader.Adload.NTZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Adload.NTZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

How to determine Win32/TrojanDownloader.Adload.NTZ?


File Info:

crc32: FF4FCF2D
md5: b2c85ed3d21b1649e8ae2667d1d09d29
name: B2C85ED3D21B1649E8AE2667D1D09D29.mlw
sha1: 0f4590e11686dab905356dcdcb41092dac421a0f
sha256: 265dff83433a3dc4af7792ac575b4ecc054a713bac74621de856a8273917353a
sha512: 87adf6786f7ab13da8cf89f69c90bb1a3a13801225f335a3c17b77f80a56a482ede1746067fae474903cdc6e8d46947e2eb262dfea52a4f68a13d08915e64b4f
ssdeep: 12288:z7blM8aNEiBePS9Bfc9reCCBzgQMoXddvDk67azlqqnHTEknjMxIoYlnlz:z7blbAKqHc9re0QPA67aRq8Imj4Y3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: SMPlayer Downloader
ProductVersion: 18.6.0
FileDescription: SMPlayer Downloader Setup
Translation: 0x0000 0x04b0

Win32/TrojanDownloader.Adload.NTZ also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Adposhel.94
CynetMalicious (score: 99)
ALYacApplication.Bundler.BTC
CylanceUnsafe
ZillyaAdware.CloudScout.Win32.977
SangforPUP.Win32.Bundler.BTC
AlibabaAdWare:Win32/CloudScout.9b8478d9
Cybereasonmalicious.3d21b1
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/TrojanDownloader.Adload.NTZ
APEXMalicious
AvastFileRepMetagen [PUP]
ClamAVWin.Malware.Ursu-7435917-0
Kasperskynot-a-virus:AdWare.Win32.CloudScout.lpc
BitDefenderApplication.Bundler.BTC
NANO-AntivirusTrojan.InnoSetup.CloudScout.fjwvmk
MicroWorld-eScanApplication.Bundler.BTC
TencentWin32.Adware.Cloudscout.Pfsy
SophosGeneric PUA AP (PUA)
ComodoMalware@#1bbtxwiach9jd
BitDefenderThetaAI:Packer.D204062917
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.jc
FireEyeApplication.Bundler.BTC
EmsisoftApplication.Bundler.BTC (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1112383
MicrosoftTrojan:Win32/Occamy.C
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
GDataApplication.Bundler.BTC
AhnLab-V3Malware/Gen.Generic.C2679097
McAfeeArtemis!B2C85ED3D21B
MAXmalware (ai score=99)
VBA32Adware.CloudScout
PandaTrj/CI.A
MaxSecureTrojan.Malware.118212648.susgen
FortinetW32/Adload.NTZ!tr
AVGFileRepMetagen [PUP]

How to remove Win32/TrojanDownloader.Adload.NTZ?

Win32/TrojanDownloader.Adload.NTZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment