Adware

Win32/Adware.LoadMoney.XV information

Malware Removal

The Win32/Adware.LoadMoney.XV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.LoadMoney.XV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Adware.LoadMoney.XV?


File Info:

name: 707703E2A3523556F45F.mlw
path: /opt/CAPEv2/storage/binaries/0087e2b41f41e4d4a20ddab5066b560770fca0213648039b7e34db9ad6995c19
crc32: E33A8415
md5: 707703e2a3523556f45feaf3a85f6311
sha1: d4bc895e4e5e897d16ddcd3447111d0cc895f07d
sha256: 0087e2b41f41e4d4a20ddab5066b560770fca0213648039b7e34db9ad6995c19
sha512: 73af24c521a92af5b113f927a54e1d511ede18348cccfae8d67f5118222ee01ef6b1d8af3194032bf47ba5f884e9b2449259ed14dcb0c810e34e91689c720c45
ssdeep: 3072:7Unco01h1k6pltUss+N7oiTLZl/oC4uDUDk/D:wXehqWUT+N7oaLTADg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DED3E0532B25F2A3E53744F4729AF35A3FF0A8342396A84E93C851C26C7B276061E757
sha3_384: 01d23a780e77ac7749959198c1d3f57c1dacb8a4fd3ed0ca669661df72c6f85ab80cde09cb446012ed15a7105079962b
ep_bytes: 66c7059cc0410071a08d0d10c0410083
timestamp: 1992-06-19 22:22:17

Version Info:

FileDescription: Downloader
FileVersion: 1, 0, 0, 0
InternalName: Downloader
LegalCopyright: Copyright 2013
OriginalFilename: Downloader.exe
ProductName: Downloader
ProductVersion: 1, 0, 0, 0
Translation: 0x0419 0x04e3

Win32/Adware.LoadMoney.XV also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.lXHW
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.LoadMoney.57
FireEyeGeneric.mg.707703e2a3523556
CAT-QuickHealTrojan.Sisproc.A6
SkyhighDownloader-FWY!707703E2A352
McAfeeDownloader-FWY!707703E2A352
Cylanceunsafe
ZillyaAdware.AgentCRT.Win32.942
SangforPUA.Win32.Sign.a
K7AntiVirusTrojan ( 005042e41 )
AlibabaDownloader:Win32/LoadMoney.6679483f
K7GWTrojan ( 005042e41 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaAI:Packer.F9892D1321
VirITTrojan.Win32.Downloader.C
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.LoadMoney.XV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-1369637
Kasperskynot-a-virus:Downloader.Win32.LMN.gen
BitDefenderGen:Variant.Application.LoadMoney.57
NANO-AntivirusTrojan.Win32.LMN.cssrvo
AvastWin32:Adware-gen [Adw]
SophosTroj/LdMon-D
BaiduWin32.Adware.Kryptik.c
F-SecureProgram.APPL/Downloader.ghk
DrWebTrojan.LoadMoney.225
VIPREGen:Variant.Application.LoadMoney.57
TrendMicroTROJ_GEN.R03FC0OC224
Trapminemalicious.high.ml.score
EmsisoftApplication.InstallMon (A)
IkarusVirus.Win32.Cryptor
GDataGen:Variant.Application.LoadMoney.57
JiangminDownloader.LMN.kns
WebrootW32.Malware.gen
VaristW32/LoadMoney.L.gen!Eldorado
AviraAPPL/Downloader.ghk
Antiy-AVLRiskWare[Downloader]/Win32.LMN
KingsoftWin32.Troj.Undef.a
XcitiumTrojWare.Win32.Kryptik.BNMK@54af98
ArcabitTrojan.Application.LoadMoney.57
ViRobotTrojan.Win32.Generic.138128
ZoneAlarmnot-a-virus:Downloader.Win32.LMN.gen
MicrosoftPUAAdvertising:Win32/LoadMoney
GoogleDetected
AhnLab-V3Trojan/Win32.LoadMoney.R88753
Acronissuspicious
VBA32Malware-Cryptor.Limpopo
ALYacGen:Variant.Application.LoadMoney.57
MAXmalware (ai score=97)
MalwarebytesLoadMoney.Adware.Bundler.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03FC0OC224
RisingAdware.LoadMoney!1.AE7B (CLASSIC)
YandexTrojan.GenAsa!vJ9dwbaNaRc
SentinelOneStatic AI – Malicious PE
MaxSecurenot-a-virus:Downloader.LMN.gen
FortinetRiskware/LMN
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.2a3523
DeepInstinctMALICIOUS

How to remove Win32/Adware.LoadMoney.XV?

Win32/Adware.LoadMoney.XV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment