Adware

How to remove “Win32/Adware.LoadMoney.PL”?

Malware Removal

The Win32/Adware.LoadMoney.PL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.LoadMoney.PL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win32/Adware.LoadMoney.PL?


File Info:

name: 6EED17FB0140D3420B15.mlw
path: /opt/CAPEv2/storage/binaries/427ea2b2c7d947cf099ff5fdec2a520861820264436156e3460048484b75d530
crc32: 07827D1F
md5: 6eed17fb0140d3420b15d1fc62aef264
sha1: 0b4f916741e6f7081649bce33794d7132b195170
sha256: 427ea2b2c7d947cf099ff5fdec2a520861820264436156e3460048484b75d530
sha512: 9b30cfd328da7aa2b5359c3318bba876778c964c4e88a9c9468528751651a0936b343a49a2cc54967b9c1d6723d183885b12012b0b4a891d194f2c4f40ab99ef
ssdeep: 12288:MjL2kwCIr/SpoLQOhf1VpJg/ZcIDbbG489UonCs:MXa7sOhfqcMb3891p
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100C41253F1D0FE65C09F9639042FDB62CF2EE8688325610D6A5F36D9F8E54705B2832A
sha3_384: 3664c17b390a17b5d774cb5ec4371d015711b9a4ef090757697a55539696ab8f5921648f308cec5d58c9903e71627867
ep_bytes: 833d28a04700010f854b8107008d05cc
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Windows® NetMeeting®
FileVersion: 5.1.2600.2180
InternalName: conf
LegalCopyright: © Корпорация Майкрософт, 1996-2001
LegalTrademarks: Microsoft® является охраняемым товарным знаком корпорации Майкрософт (Microsoft Corp.). Windows® является охраняемым товарным знаком корпорации Майкрософт (Microsoft Corp.).
OriginalFilename: conf.exe
ProductName: Windows® NetMeeting®
ProductVersion: 3.01
Translation: 0x0419 0x04b0

Win32/Adware.LoadMoney.PL also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.CodecPack.lvqi
tehtrisGeneric.Malware
DrWebTrojan.LoadMoney.301
MicroWorld-eScanGen:Trojan.Heur.Renos.Hy0@culOGook
FireEyeGeneric.mg.6eed17fb0140d342
CAT-QuickHealTrojan.Sisproc.A6
ALYacGen:Trojan.Heur.Renos.Hy0@culOGook
CylanceUnsafe
VIPREGen:Trojan.Heur.Renos.Hy0@culOGook
SangforVirus.Win32.Save.a
K7AntiVirusAdware ( 004d48581 )
AlibabaDownloader:Win32/Plocust.ee720e21
K7GWAdware ( 004d48581 )
Cybereasonmalicious.b0140d
BitDefenderThetaAI:Packer.560088C122
CyrenW32/S-2b508265!Eldorado
SymantecTrojan.Gen
Elasticmalicious (high confidence)
ESET-NOD32Win32/Adware.LoadMoney.PL
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:Downloader.Win32.Plocust.heur
BitDefenderGen:Trojan.Heur.Renos.Hy0@culOGook
NANO-AntivirusTrojan.Win32.Plocust.dfffkg
SUPERAntiSpywareTrojan.Agent/Gen-Winlock
TencentWin32.Trojan.Generic.Wmhl
Ad-AwareGen:Trojan.Heur.Renos.Hy0@culOGook
EmsisoftGen:Trojan.Heur.Renos.Hy0@culOGook (B)
ComodoTrojWare.Win32.Kryptik.CHYN@5e1m7b
BaiduWin32.Virus.Krap.a
ZillyaAdware.LoadMoneyGen.Win32.7
TrendMicroTROJ_OGIMANT.SMA
McAfee-GW-EditionPacked-CQ
Trapminesuspicious.low.ml.score
SophosTroj/LdMon-J
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.Renos.Hy0@culOGook
JiangminDownloader.Plocust.uy
WebrootW32.Malware.Heur
GoogleDetected
AviraADWARE/WebAlta.qoys
Antiy-AVLTrojan/Generic.ASMalwS.6
KingsoftWin32.Troj.Agent.lk.(kcloud)
ArcabitTrojan.Heur.Renos.ED7B65
MicrosoftSoftwareBundler:Win32/Ogimant
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.LoadMoney.R115978
McAfeePacked-CQ
MAXmalware (ai score=80)
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesAdware.LoadMoney
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_OGIMANT.SMA
RisingAdware.LoadMoney!1.B21E (CLASSIC)
YandexTrojan.DR.Agent!ZM0YxGCojPI
IkarusTrojan-Dropper.Win32.Agent
FortinetRiskware/LMN
AVGWin32:LoadMoney-APM [Adw]
AvastWin32:LoadMoney-APM [Adw]
CrowdStrikewin/grayware_confidence_70% (W)

How to remove Win32/Adware.LoadMoney.PL?

Win32/Adware.LoadMoney.PL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment