Malware

What is “Application.LoadMoney.589”?

Malware Removal

The Application.LoadMoney.589 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.LoadMoney.589 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Application.LoadMoney.589?


File Info:

name: 78B47588326F6ABAAF38.mlw
path: /opt/CAPEv2/storage/binaries/7ea64d6faaac11adce677806a15c5c30e857f7c65c1d0d1760e3a764b8c61591
crc32: 13310775
md5: 78b47588326f6abaaf38dd4fd533de95
sha1: 0b1f5f8f28774c06515fee9926332ee8d8028509
sha256: 7ea64d6faaac11adce677806a15c5c30e857f7c65c1d0d1760e3a764b8c61591
sha512: d76c84fc0d65ec65821a618c56c8747e254d77d1e4c79e2a14b297a59b92ced9f36daeac6ea3acc29d34e70371daa6b798769886aaa17933a304214b4fe17ecf
ssdeep: 768:MHvHVtTgeneecqEpZLcVQBm47D0rgsBTKDj0WSKEyXNkiDFlB4OMZek0goUU1IK7:2pgAcnAqQkFSKEQ6QFT497oU3duEUr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C8634A45E750F03AEC33857205252AA553B67E3419665A2F6F0CBD247AF13E3E23A363
sha3_384: 58ec68610a70caa5c67d32e7214e187bad7762619baf08cd794b5cd08192c9b4849394e334cf288b35ec3707cbe9a97f
ep_bytes: 558bec51518365fc008d45fc50ff1574
timestamp: 2012-12-14 15:00:52

Version Info:

FileDescription: Downloader
FileVersion: 1, 0, 0, 0
InternalName: Downloader
LegalCopyright: Copyright c 2005 - 2012
OriginalFilename: Downloader.exe
ProductName: Downloader
ProductVersion: 1, 0, 0, 0
Translation: 0x0419 0x04e3

Application.LoadMoney.589 also known as:

MicroWorld-eScanGen:Variant.Application.LoadMoney.589
ClamAVWin.Trojan.Agent-428043
FireEyeGeneric.mg.78b47588326f6aba
CAT-QuickHealTrojan.Downloader.Agent.VF5
McAfeePUP-FFK
CylanceUnsafe
ZillyaDownloader.Agent.Win32.157817
SangforTrojan.Win32.Save.a
K7AntiVirusDialer ( 0040f5991 )
K7GWAdware ( 004ed1fd1 )
Cybereasonmalicious.8326f6
BaiduWin32.Adware.Generic.ar
VirITAdware.Win32.Downware.BCS
CyrenW32/GenTroj.BH.gen!Eldorado
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/LoadMoney.A potentially unwanted
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:Downloader.Win32.Agent.vf
BitDefenderGen:Variant.Application.LoadMoney.589
NANO-AntivirusTrojan.Win32.Agent.cwqurv
SUPERAntiSpywarePUP.DownWare/Variant
AvastFileRepMalware [Trj]
TencentAdware.Win32.DL.Lmn.b
Ad-AwareGen:Variant.Application.LoadMoney.589
SophosMal/Dwnldr-Y
ComodoApplicUnwnt.Win32.LoadMoney.B@4th5ev
DrWebAdware.Downware.746
VIPREGen:Variant.Application.LoadMoney.589
McAfee-GW-EditionPUP-FFK
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Application.LoadMoney.589 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Riskware.StartPage.J
JiangminDownloader.Agent.mjr
WebrootW32.Malware.gen
AviraAPPL/LoadMoney.7008
MAXmalware (ai score=70)
Antiy-AVLTrojan/Generic.ASMalwS.FB
KingsoftWin32.HeurC.KVM019.a.(kcloud)
ArcabitTrojan.Application.LoadMoney.589
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Kazy.R46467
ALYacGen:Variant.Application.LoadMoney.589
VBA32Downware.LMN.gen
MalwarebytesPUP.Optional.DownWare.RU
RisingDownloader.Small!1.65D6 (CLASSIC)
YandexPUA.Downloader!pysJuOGspLo
IkarusTrojan.Win32.Spy
MaxSecurenot-a-virus:.Downloader.Agent.vf
FortinetW32/Agent.FEZ!tr.dldr
AVGFileRepMalware [Trj]
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Application.LoadMoney.589?

Application.LoadMoney.589 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment