PUA

About “PUAAdvertising:Win32/LoadMoney” infection

Malware Removal

The PUAAdvertising:Win32/LoadMoney is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUAAdvertising:Win32/LoadMoney virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PUAAdvertising:Win32/LoadMoney?


File Info:

crc32: 1E18FBF4
md5: 063a5ab22b75256629b2ed346e15fde5
name: 063A5AB22B75256629B2ED346E15FDE5.mlw
sha1: d11bf790ceefee0bb9d13522b30325ab77cd1a8c
sha256: 82fea670c09ed14c11817c9eb9d5e99cb3099b3ac0f640f0a6fbf07b2ced189b
sha512: 474d3a2e6422f61de4fd5aa6de3197b0d1da20c88e7e93cc348bb36edc96c35b2829f3cfa269ac3b7ccde842124dcd9b57bcddf4483bd34f8aca2441e536b062
ssdeep: 3072:I624bzC3A8QWRiKFTiXFKiKFToOd54jCUgup5bownVS570M9kdatGCO+xmBc+hM+:Ib+TK9UzK9oOdUguBVs7nyatGt+SYFw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: BAAipdate
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
OleSelfRegister: D
ProductVersion: 6.1.7600.16385
FileDescription: BitLocker Access Agent ipdate Utility
OriginalFilename: BAAipdate.EXE
Translation: 0x0409 0x04b0

PUAAdvertising:Win32/LoadMoney also known as:

K7AntiVirusTrojan ( 0053f76c1 )
LionicTrojan.Win32.NetStream.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Proxy2.1618
CynetMalicious (score: 99)
ALYacTrojan.Agent.EBMU
CylanceUnsafe
ZillyaTrojan.Generic.Win32.920772
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 0053f76c1 )
Cybereasonmalicious.22b752
CyrenW32/Agent.BAE.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HDGW
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.EBMU
NANO-AntivirusTrojan.Win32.NetStream.fuugrm
MicroWorld-eScanTrojan.Agent.EBMU
TencentMalware.Win32.Gencirc.10ba0458
Ad-AwareTrojan.Agent.EBMU
ComodoTrojWare.Win32.TrojanProxy.Bunitu.PO@8av0fb
BitDefenderThetaGen:NN.ZexaF.34236.Zq1@au4sKtbi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.SHADE.SMB.hp
McAfee-GW-EditionTrickbot-FRDP!063A5AB22B75
FireEyeGeneric.mg.063a5ab22b752566
EmsisoftAdware.Agent (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.NetStream.np
AviraHEUR/AGEN.1110112
Antiy-AVLTrojan/Generic.ASMalwS.2C2664B
MicrosoftPUAAdvertising:Win32/LoadMoney
ZoneAlarmHEUR:Trojan.Win32.NetStream.gen
GDataTrojan.Agent.EBMU
AhnLab-V3Trojan/Win32.Kryptik.R284993
Acronissuspicious
McAfeeTrickbot-FRDP!063A5AB22B75
MAXmalware (ai score=100)
VBA32BScope.Trojan.Ditertag
MalwarebytesTrojan.Bunitu
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.SHADE.SMB.hp
RisingTrojan.Kryptik!1.BA4B (CLASSIC)
YandexTrojan.GenAsa!3hxq805E9bU
IkarusPUA.Multibar
MaxSecureTrojan.Malware.74476717.susgen
FortinetW32/Kryptik.HDAL!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove PUAAdvertising:Win32/LoadMoney?

PUAAdvertising:Win32/LoadMoney removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment