PUA

How to remove “PUA.LoadmoneyPMF.S19249780”?

Malware Removal

The PUA.LoadmoneyPMF.S19249780 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.LoadmoneyPMF.S19249780 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PUA.LoadmoneyPMF.S19249780?


File Info:

name: AC9088997102A6FAF1E0.mlw
path: /opt/CAPEv2/storage/binaries/acf2698b07a2a3f662ddb96099b024cd74042065440e14cb716eb17d4ee7286c
crc32: 0D9FDB1F
md5: ac9088997102a6faf1e09705bc291900
sha1: eed9cf672f9f2daf5bb8842635b67992199545cd
sha256: acf2698b07a2a3f662ddb96099b024cd74042065440e14cb716eb17d4ee7286c
sha512: c6698e58af6f9d822bb3e97fe71676244ab4f3d34b2a4aa44d1eb89f4efe64dd3e6e6f6e87fe164ad20ebdae9c4150ab742acf9663ae8c76ceca42bd00900fae
ssdeep: 3072:+5ERKdsNSE8jWf+FnGevgjFA+WzmLpJhJ4RpS:+wB8qonGeoFA0lyp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DD047D1136D0C0B1D6B3023609E9AB71A6BDFD714F618B5B77984B4D1EB42C0BA36B63
sha3_384: dd7c448ca33a5ef4f6fe002adaf77731134d1cbf77da87d3b21c6d2245a344fe61f820aad0abcbf9b2d60bf1476a8802
ep_bytes: e83c720000e97ffeffff558bec8b4508
timestamp: 2018-04-02 14:25:18

Version Info:

CompanyName: Mail.Ru
FileDescription: Mail.Ru Launcher
FileVersion: 3.15.0.75
InternalName: launcher
LegalCopyright: Copyright 2015
OriginalFilename: launcher.exe
ProductName: Mail.Ru Launcher
ProductVersion: 3.15.0.75
Comments:
Translation: 0x0409 0x04b0

PUA.LoadmoneyPMF.S19249780 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.74312
FireEyeGeneric.mg.ac9088997102a6fa
CAT-QuickHealPUA.LoadmoneyPMF.S19249780
ALYacTrojan.GenericKDZ.74312
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005170991 )
K7GWAdware ( 005170991 )
Cybereasonmalicious.97102a
ArcabitTrojan.Generic.D12248
CyrenW32/S-2773094c!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/MailRu.R potentially unwanted
APEXMalicious
ClamAVWin.Malware.Mailru-6804164-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Machaer.gen
BitDefenderTrojan.GenericKDZ.74312
SUPERAntiSpywarePUP.Downloader/Variant
AvastWin32:PUP-gen [PUP]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.GenericKDZ.74312
ComodoApplication.Win32.MailRu.M@7oho6u
DrWebTrojan.Revizer.1409
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftApplication.Downloader (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Machaer.ad
AviraAPPL/MailRu.B
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASBOL.C4F7
MicrosoftPUAAdvertising:Win32/LoadMoney
ViRobotTrojan.Win32.Mailru.Gen.B
GDataTrojan.GenericKDZ.74312
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.MailRu.R232581
McAfeePUP-HAI
VBA32BScope.Adware.Machaer
MalwarebytesRiskWare.Agent
YandexTrojan.GenAsa!jAEP24k3Yx8
IkarusPUA.MailRu
eGambitUnsafe.AI_Score_99%
FortinetW32/MailRu.M!tr
AVGWin32:PUP-gen [PUP]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureAdware.Adware.Machaer.gen_172020

How to remove PUA.LoadmoneyPMF.S19249780?

PUA.LoadmoneyPMF.S19249780 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment