Adware

What is “Win32/Adware.LoadMoney.SO”?

Malware Removal

The Win32/Adware.LoadMoney.SO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.LoadMoney.SO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Adware.LoadMoney.SO?


File Info:

name: 001AF9B44B0978BF5394.mlw
path: /opt/CAPEv2/storage/binaries/c7b254dffbb1961e99008d60c84da6a50f1cdc2d2be36ff9169dd583dcd42715
crc32: 3B2CE228
md5: 001af9b44b0978bf53948e2525ba9010
sha1: 8bde73ad589b676846cb2ce6b9ed0dbed5815f82
sha256: c7b254dffbb1961e99008d60c84da6a50f1cdc2d2be36ff9169dd583dcd42715
sha512: 5e2b73758441369e0e621935cce33e93d083e74bdd0f154286a6979a57ef1cfac67032f807c73e69f5dbc5dab8b116738d3a8fcc2ecb5b2ceb0d89ccca66894f
ssdeep: 6144:XtWF851plCjMDOm0iuLPiwSj6xDPdgpAW5DDCV7bZ7e761rAk1CavC4URZaL19o2:XtPlDO5e5QDdgpAoHaQcmenUraL3oam
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0C41261D5F8FD18D8AF473E053E96A8CB2F5C848320519D565F35AAECB20F24A48F1B
sha3_384: b5ab1a2168b8f570b7e07ed9c847c02b10d98951240fe2f19ae8698a890a4ea01019791b8372df1f73d7544a40633e40
ep_bytes: 833d28a04700010f85b7830700ff05bd
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Windows® NetMeeting®
FileVersion: 5.1.2600.2180
InternalName: conf
LegalCopyright: © Корпорация Майкрософт, 1996-2001
LegalTrademarks: Microsoft® является охраняемым товарным знаком корпорации Майкрософт (Microsoft Corp.). Windows® является охраняемым товарным знаком корпорации Майкрософт (Microsoft Corp.).
OriginalFilename: conf.exe
ProductName: Windows® NetMeeting®
ProductVersion: 3.01
Translation: 0x0419 0x04b0

Win32/Adware.LoadMoney.SO also known as:

LionicTrojan.Win32.Prek.m23s
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.Renos.Hy0@c86DT0lk
ClamAVWin.Trojan.Agent-1382338
CAT-QuickHealTrojan.Sisproc.A6
SkyhighBehavesLike.Win32.Infected.hh
McAfeePacked-CQ
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.Heur.Renos.Hy0@c86DT0lk
SangforTrojan.Win32.Save.a
AlibabaDownloader:Win32/Plocust.af2cd22e
Cybereasonmalicious.d589b6
BaiduWin32.Virus.Krap.a
SymantecTrojan.Gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.LoadMoney.SO
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:Downloader.Win32.Plocust.gcwp
BitDefenderGen:Trojan.Heur.Renos.Hy0@c86DT0lk
NANO-AntivirusTrojan.Win32.Plocust.eeyehk
AvastWin32:LoadMoney-APM [Adw]
TencentWin32.Trojan-Downloader.Plocust.Bzlw
EmsisoftGen:Trojan.Heur.Renos.Hy0@c86DT0lk (B)
F-SecureAdware.ADWARE/WebAlta.qoys
DrWebTrojan.LoadMoney.304
ZillyaAdware.LoadMoneyGen.Win32.7
TrendMicroTROJ_OGIMANT.SMA
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.001af9b44b0978bf
SophosTroj/LdMon-J
IkarusVirus.Win32.Cryptor
GDataGen:Trojan.Heur.Renos.Hy0@c86DT0lk
JiangminDownloader.Plocust.n
WebrootW32.Malware.Heur
GoogleDetected
AviraADWARE/WebAlta.qoys
Antiy-AVLTrojan[Downloader]/Win32.Plocust.gcwp
Kingsoftmalware.kb.a.997
XcitiumTrojWare.Win32.Kryptik.CHYN@5e1m7b
ArcabitTrojan.Heur.Renos.E2F329
ZoneAlarmnot-a-virus:Downloader.Win32.Plocust.gcwp
MicrosoftSoftwareBundler:Win32/Ogimant
VaristW32/S-2b508265!Eldorado
AhnLab-V3Adware/Win32.LoadMoney.R114819
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Trojan.Heur.Renos.Hy0@c86DT0lk
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_OGIMANT.SMA
RisingAdware.LoadMoney!1.B21E (CLASSIC)
YandexTrojan.GenAsa!4zXysUuWj7c
SentinelOneStatic AI – Malicious PE
FortinetRiskware/LMN
BitDefenderThetaAI:Packer.A77844C722
AVGWin32:LoadMoney-APM [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Win32/Adware.LoadMoney.SO?

Win32/Adware.LoadMoney.SO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment