Home Malware Programs Trojans TrojanDownloader:Win32/Adload.DA

TrojanDownloader:Win32/Adload.DA

Posted: May 28, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 71
First Seen: May 28, 2012
OS(es) Affected: Windows

TrojanDownloader:Win32/Adload.DA is a Trojan downloader that downloads and installs other files, including PC threats, without your permission. The C&C site that TrojanDownloader:Win32/Adload.DA uses to conduct these activities has been blacklisted for various types of malicious behavior, and its Korean domain is indicative of TrojanDownloader:Win32/Adload.DA potentially being a significant threat to Korea-based PCs in particular. Symptoms of TrojanDownloader:Win32/Adload.DA's attacks may vary with the files that TrojanDownloader:Win32/Adload.DA downloads but often include blocked security software and disabled Internet access. However, SpywareRemove.com malware researchers are glad to note that you can disable TrojanDownloader:Win32/Adload.DA and related PC threats via Windows Safe Mode, after which you can remove TrojanDownloader:Win32/Adload.DA with the anti-malware product of your choice.

Where One TrojanDownloader:Win32/Adload.DA Equals a Fleet of Other Trojans

TrojanDownloader:Win32/Adload.DA is designed to install other types of hostile software onto your PC, and, accordingly, may show no symptoms or various symptoms, depending on what TrojanDownloader:Win32/Adload.DA is configured to install. However, SpywareRemove.com malware researchers rate the following PC threats as being especially likely, since TrojanDownloader:Win32/Adload.DA's Command & Control server has also been found to host these Trojans: BckIRCBot.CYG, Trojan-Dropper.Win32.Agent.fsit, Trojan horse SHeur3.CKTI, TrjThed.E, JS:Trojan.JS.Iframe.V, Trojan horse Downloader.Generic_r.HI, W32Mytob.QL.worm and W32HotBar.L.gen!Eldorado. In particular, you should pay close attention to network security and security for removable media devices, since worms like W32Mytob.QL.worm and similar PC threats installed by TrojanDownloader:Win32/Adload.DA may infect new computers via these mechanisms.

The site that TrojanDownloader:Win32/Adload.DA uses for its misdeeds, opencapture.co.kr, has been blacklisted by various organizations for phishing attacks, browser exploits and, of course, hosting malicious software. If TrojanDownloader:Win32/Adload.DA or an associated PC threat redirects your browser to come into contact with opencapture.co.kr, SpywareRemove.com malware researchers recommend that you immediately close your browser and scan your PC to protect it from potential browser-based attacks, including the automatic installation of other harmful software.

Piercing the Wall TrojanDownloader:Win32/Adload.DA Erects Between You and the Net

TrojanDownloader:Win32/Adload.DA attacks often include symptoms such as completely disabled Internet connectivity, as well as disabled Windows anti-malware applications (for example, Windows Defender). While these symptoms may make it seem as though TrojanDownloader:Win32/Adload.DA is excessively difficult to remove TrojanDownloader:Win32/Adload.DA, in reality, SpywareRemove.com malware researchers have found that booting Windows into Safe Mode will disable the relevant attack functions and allow you to disinfect TrojanDownloader:Win32/Adload.DA appropriately. As a Windows-based Trojan, TrojanDownloader:Win32/Adload.DA hasn't been reported to have any amount of cross-compatibility with other operating systems.

Tapping F8 while your PC reboots will allow you to bring up the boot menu for entering Safe Mode, although this merely disables, rather than deleting, TrojanDownloader:Win32/Adload.DA and related PC threats. Afterwards, scanning your entire computer with a reputable anti-malware application should be the first thing on your to-do list for getting rid of TrojanDownloader:Win32/Adload.DA and its friends. You may also need to update your anti-malware scanner's threat database, since is still in propagation as of 2012 (although initial detections for TrojanDownloader:Win32/Adload.DA began in late 2011).

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



opencp01.exe File name: opencp01.exe
Size: 616.96 KB (616960 bytes)
MD5: fc42a8ae397183f56e554292e64ce4d5
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 29, 2012
Loading...