Adware

What is “LoadMoney.Adware.Bundler.DDS”?

Malware Removal

The LoadMoney.Adware.Bundler.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What LoadMoney.Adware.Bundler.DDS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine LoadMoney.Adware.Bundler.DDS?


File Info:

name: 9888134429C7CAC8D7B8.mlw
path: /opt/CAPEv2/storage/binaries/ce210e04e152c524d20453cdac3eba85d7434a0c68199936cce0cb1ac086a3f3
crc32: 3E526F6B
md5: 9888134429c7cac8d7b895f19fc26a66
sha1: 14783a823b0400d824226384003967b2eae149d1
sha256: ce210e04e152c524d20453cdac3eba85d7434a0c68199936cce0cb1ac086a3f3
sha512: fbbde233c808acc174165acf6e7243024c9ec22fb682f25a4eaefe125211514ed82803c138e6527cc0228d9585ca2600aa26168ed888fae2d6fdb36c2019d028
ssdeep: 3072:wKea5hAapmI4R0Wkt7VgQF7p10r4X07lLt+NNwCZVyk/86NJFD:wKea5hAOmIEkt2QppmUXYt+NNDZVyhSD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108D3E0779954F5A2C52B887053D7F0876FB4DC326F12086DBA8A59B7E43A0B5023A337
sha3_384: a2f62e523567d6ebd519680b2caa6407c398de5f1f57ef2962f9d9db57ca7457ba086f9271b61084163250519cab47ed
ep_bytes: 895424f4c705f0d041003b5a0100833d
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

LoadMoney.Adware.Bundler.DDS also known as:

LionicTrojan.Win32.Agentb.m5yq
Elasticmalicious (high confidence)
DrWebTrojan.LoadMoney.227
MicroWorld-eScanGen:Variant.Adware.Strictor.46898
FireEyeGeneric.mg.9888134429c7cac8
CAT-QuickHealTrojan.Sisproc.A6
McAfeeDownloader-FWY!9888134429C7
MalwarebytesLoadMoney.Adware.Bundler.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005042e41 )
K7GWTrojan ( 005042e41 )
CrowdStrikewin/grayware_confidence_60% (D)
BitDefenderThetaAI:Packer.7A73BD7A1F
VirITTrojan.Win32.LoadMoney.IT
CyrenW32/LoadMoney.R.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/LoadMoney.CA potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Agent-1372314
KasperskyTrojan.Win32.Agentb.aemn
BitDefenderGen:Variant.Adware.Strictor.46898
NANO-AntivirusTrojan.Win32.Agent.dknrwv
AvastWin32:LoadMoney-AT [Trj]
TencentMalware.Win32.Gencirc.10b295b1
EmsisoftGen:Variant.Adware.Strictor.46898 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
BaiduWin32.Adware.Kryptik.c
VIPREGen:Variant.Adware.Strictor.46898
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
Trapminemalicious.high.ml.score
SophosMal/EncPk-ACB
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Adware.Strictor.46898
JiangminTrojan/Agentb.ahg
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Agentb.aemn
XcitiumTrojWare.Win32.Kryptik.BAJ@57fz7n
ArcabitTrojan.Adware.Strictor.DB732
ZoneAlarmTrojan.Win32.Agentb.aemn
MicrosoftSoftwareBundler:Win32/Ogimant
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.LoadMoney.C219114
ALYacGen:Variant.Adware.Strictor.46898
TACHYONTrojan/W32.Agentb.135168.C
VBA32Malware-Cryptor.Limpopo
Cylanceunsafe
PandaTrj/Genetic.gen
RisingAdware.LoadMoney!1.AE7B (CLASSIC)
YandexTrojan.Agentb!aBrWWHX/+U0
IkarusVirus.Win32.Cryptor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/LoadMoney.CD!tr
AVGWin32:LoadMoney-AT [Trj]
DeepInstinctMALICIOUS

How to remove LoadMoney.Adware.Bundler.DDS?

LoadMoney.Adware.Bundler.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment