Adware

About “Win32/Adware.LoadMoney.XV” infection

Malware Removal

The Win32/Adware.LoadMoney.XV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.LoadMoney.XV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Adware.LoadMoney.XV?


File Info:

name: 6B5D197D08F3664F5A74.mlw
path: /opt/CAPEv2/storage/binaries/052471975f281ab2fd713dfa1ae936155d2f7c351fa9c6405ba933d844336610
crc32: BF3B1524
md5: 6b5d197d08f3664f5a746b9c26da0eca
sha1: fb52f821f0cc387d276cd06ff05e1f06e0fcf782
sha256: 052471975f281ab2fd713dfa1ae936155d2f7c351fa9c6405ba933d844336610
sha512: 41865b8e62cc664121d3b9a99b00426e77b3d7b3619f5948478e08e8ca44a9ffac19b7fbdfc0aebcbb0a1f87bb55a2997f7ed771d039d1fdaf3f356697ad7905
ssdeep: 3072:znobrEYCcJzkcdF5IDtUss+N7oiTLZl/oe4uDUDl/K:bBYCAYcvqDtUT+N7oaLTADE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15AD3E0A31A15F293E13340F072C9F2973FF4EC296316A81B938895D66C7B276162E753
sha3_384: 864739f53eee4d710e81e48c57df4b5566388abbac4cf5f2ad14f03bf31914666dbb5099defcafddd3e6e69a90a4bf12
ep_bytes: 66c7059cc0410071a08d0d10c0410083
timestamp: 1992-06-19 22:22:17

Version Info:

FileDescription: Downloader
FileVersion: 1, 0, 0, 0
InternalName: Downloader
LegalCopyright: Copyright 2013
OriginalFilename: Downloader.exe
ProductName: Downloader
ProductVersion: 1, 0, 0, 0
Translation: 0x0419 0x04e3

Win32/Adware.LoadMoney.XV also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.LoadMoney.57
FireEyeGeneric.mg.6b5d197d08f3664f
CAT-QuickHealTrojan.Sisproc.A6
SkyhighDownloader-FWY!6B5D197D08F3
ALYacGen:Variant.Application.LoadMoney.57
Cylanceunsafe
ZillyaAdware.AgentCRT.Win32.942
SangforPUA.Win32.Sign.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaDownloader:Win32/LoadMoney.85da4ba9
K7GWTrojan ( 005042e41 )
K7AntiVirusTrojan ( 005042e41 )
ArcabitTrojan.Application.LoadMoney.57
BitDefenderThetaAI:Packer.A66C7E0B21
VirITTrojan.Win32.Downloader.C
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.LoadMoney.XV
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R03FC0OCI24
ClamAVWin.Trojan.Agent-1369637
Kasperskynot-a-virus:Downloader.Win32.LMN.gen
BitDefenderGen:Variant.Application.LoadMoney.57
NANO-AntivirusTrojan.Win32.LMN.cssrvo
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan-Downloader.Lmn.Pzfl
EmsisoftApplication.InstallMon (A)
BaiduWin32.Adware.Kryptik.c
F-SecureProgram.APPL/Downloader.ghk
DrWebTrojan.LoadMoney.225
VIPREGen:Variant.Application.LoadMoney.57
TrendMicroTROJ_GEN.R03FC0OCI24
Trapminemalicious.high.ml.score
SophosTroj/LdMon-D
IkarusVirus.Win32.Cryptor
JiangminDownloader.LMN.jiy
GoogleDetected
AviraAPPL/Downloader.ghk
VaristW32/LoadMoney.L.gen!Eldorado
Antiy-AVLRiskWare[Downloader]/Win32.LMN
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.BNMK@54af98
MicrosoftPUAAdvertising:Win32/LoadMoney
ViRobotTrojan.Win32.Generic.138128
ZoneAlarmnot-a-virus:Downloader.Win32.LMN.gen
GDataGen:Variant.Application.LoadMoney.57
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.LoadMoney.R88753
Acronissuspicious
McAfeeDownloader-FWY!6B5D197D08F3
VBA32Malware-Cryptor.Limpopo
MalwarebytesLoadMoney.Adware.Bundler.DDS
PandaTrj/Genetic.gen
RisingAdware.LoadMoney!1.AE7B (CLASSIC)
YandexTrojan.GenAsa!vJ9dwbaNaRc
SentinelOneStatic AI – Malicious PE
MaxSecurenot-a-virus:Downloader.LMN.gen
FortinetRiskware/LMN
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.d08f36
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/LoadMoney.XV

How to remove Win32/Adware.LoadMoney.XV?

Win32/Adware.LoadMoney.XV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment