Adware

Win32/Adware.LoadMoney.AAI removal tips

Malware Removal

The Win32/Adware.LoadMoney.AAI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.LoadMoney.AAI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Clears web history

How to determine Win32/Adware.LoadMoney.AAI?


File Info:

name: E96ACC6CE9C9BBE6FF22.mlw
path: /opt/CAPEv2/storage/binaries/e9d07caced0d7bec09dd6d8f82759ecfc61d5da9e10d82a4f86f2f20aac57475
crc32: 4BB4174E
md5: e96acc6ce9c9bbe6ff220c4f998f2f8b
sha1: a3d166c0c061a22194633329b567a72cfc1d888b
sha256: e9d07caced0d7bec09dd6d8f82759ecfc61d5da9e10d82a4f86f2f20aac57475
sha512: 46e4a643dcbc20923281e11e86c6d9f706d6818b07c1cec41fc449d41b286f0bd0038c7c88d95406abef1a40b442bea01d74b7a27dcab6d595d31fc3224b2f37
ssdeep: 3072:qZAkSIvzAmdYRZDicWtDp53EGAwfwQddgPGXSkP:OA5GdmDUtDpBxAMwQbgPG5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FCD3F187FDE0E0FDC87794F891ADB0DEEE99DDC5C3417B16071F1689B219208E626222
sha3_384: a66557d2ba150bb6732f617ed35b1cb9f56e50d037521606d6141ff569151aa88697ef63a20b3e804fbc342ac1b82676
ep_bytes: 833d6ce4410000752c8b155de4410085
timestamp: 1992-06-19 04:10:01

Version Info:

0: [No Data]

Win32/Adware.LoadMoney.AAI also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Cidox.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.e96acc6ce9c9bbe6
McAfeeArtemis!E96ACC6CE9C9
CylanceUnsafe
VIPREVirtumonde
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f23c1 )
AlibabaTrojanDropper:Win32/Vundo.45f30ced
K7GWTrojan ( 0040f23c1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Adware.Kryptik.c
VirITTrojan.Win32.SMSSend.DMX
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.LoadMoney.AAI
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Razy.12645
NANO-AntivirusTrojan.Win32.Cidox.bcymvt
MicroWorld-eScanGen:Variant.Ser.Razy.12645
AvastWin32:Vundo-ACX [Trj]
TencentWin32.Trojan.Generic.Akys
Ad-AwareGen:Variant.Ser.Razy.12645
ComodoTrojWare.Win32.Kryptik.AOKV@4sn0fa
DrWebTrojan.SMSSend.2363
ZillyaBackdoor.Cidox.Win32.1049
EmsisoftGen:Variant.Ser.Razy.12645 (B)
GDataGen:Variant.Ser.Razy.12645
JiangminBackdoor/Cidox.it
eGambitGeneric.Backdoor
AviraDR/Delphi.Gen7
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.61905B
KingsoftWin32.Hack.Cidox.p.(kcloud)
ViRobotBackdoor.Win32.A.Cidox.138240.A
MicrosoftTrojanDropper:Win32/Vundo.AA
AhnLab-V3Spyware/Win32.Zbot.R46689
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.iyW@aWN2Iklk
ALYacGen:Variant.Ser.Razy.12645
TACHYONBackdoor/W32.Cidox.138240.B
MalwarebytesSpyware.ZeuS
RisingSpyware.Voltar!1.AF1D (CLOUD)
YandexTrojan.Kryptik!Qu+XXyVCEY8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.EQPB!tr
WebrootW32.Malware.Gen
AVGWin32:Vundo-ACX [Trj]
PandaTrj/OCJ.B

How to remove Win32/Adware.LoadMoney.AAI?

Win32/Adware.LoadMoney.AAI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment