Home Malware Programs Trojans Trojan-Downloader.Win32.Adload.sll

Trojan-Downloader.Win32.Adload.sll

Posted: June 28, 2010

Trojan-Downloader.Win32.Adload.sll is a malicious backdoor Trojan that runs in the background and allows remote access to the compromised system. Trojan-Downloader.Win32.Adload.sll contains a hacktool for attackers to break into the PC. Trojan-Downloader.Win32.Adload.sll can change Windows Explorer settings to download other malicious files from external servers. Trojan-Downloader.Win32.Adload.sll monitors user activities to obtain valuable personal information. Trojan-Downloader.Win32.Adload.sll poses a dangerous threat to any computer or system and should be terminated immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\037
    2 %System%\7010022-60
    3 %System%\799d.exe
    4 %System%\977o.dll
    5 %System%\9bee.dll
    6 %Windir%\1b6u.bmp
    7 %Windir%\91bd.exe
    8 %Windir%\f91d.flv
    9 %Windir%\Tasks\ms.job
    10 %Windir%\Temp\Temporary Internet Files\Content.IE5\6FEFGHCV\desktop.ini
    11 %Windir%\Temp\Temporary Internet Files\Content.IE5\801TQV1F\desktop.ini
    12 %Windir%\Temp\Temporary Internet Files\Content.IE5\desktop.ini
    13 %Windir%\Temp\Temporary Internet Files\Content.IE5\index.dat
    14 %Windir%\Temp\Temporary Internet Files\Content.IE5\LM9FGLDN\desktop.ini
    15 %Windir%\Temp\Temporary Internet Files\Content.IE5\XP8RJTCV\desktop.ini

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
Loading...