Adware

What is “Win32/Adware.LoadMoney.XV”?

Malware Removal

The Win32/Adware.LoadMoney.XV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.LoadMoney.XV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Adware.LoadMoney.XV?


File Info:

name: CDD70B7424E51852BFA5.mlw
path: /opt/CAPEv2/storage/binaries/842a9822532482a3b39e736c030b494808255a6baa3746caa5cfdd1f56ef3988
crc32: 36062C55
md5: cdd70b7424e51852bfa5856dce5175f0
sha1: 42f3fcffd90e5f59f63824f7a551948a28a9c01a
sha256: 842a9822532482a3b39e736c030b494808255a6baa3746caa5cfdd1f56ef3988
sha512: f8bc9ac36aeff65228ca5408ee5d3434006d493d4329b2d871a9abb07bfb510d770991c1ab598948c4442dab3e1aea79b5a99c92195c8f573116e0b3394fa7ef
ssdeep: 3072:16vuWLkWLzd0UOhH5Qqb0v/ySMos28SeygUDQ/1:16vpLzd0JH5QqbY6TJGDq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142D3F169E96DF5EEC10B4038A48DF9472F71DC61A379E9DCB21F6C822867261211F723
sha3_384: 926abeb7f0e60626e8782d6d66816690955d268cbb40fb581170227b5d24723fb4ed6a2898e03c19e057edcf5a4650c4
ep_bytes: 832da2b5410000753b89a8194000ff25
timestamp: 1992-06-19 22:22:17

Version Info:

FileDescription: Downloader
FileVersion: 1, 0, 0, 0
InternalName: Downloader
LegalCopyright: Copyright 2013
OriginalFilename: Downloader.exe
ProductName: Downloader
ProductVersion: 1, 0, 0, 0
Translation: 0x0419 0x04e3

Win32/Adware.LoadMoney.XV also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.CodecPack.lz8p
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.LoadMoney.57
ClamAVWin.Trojan.Loadmoney-11757
FireEyeGeneric.mg.cdd70b7424e51852
CAT-QuickHealTrojan.Sisproc.A6
SkyhighDownloader-FWY!CDD70B7424E5
McAfeeDownloader-FWY!CDD70B7424E5
Cylanceunsafe
VIPREGen:Variant.Application.LoadMoney.57
SangforPUA.Win32.Sign.a
K7AntiVirusTrojan ( 0040f6ca1 )
AlibabaDownloader:Win32/LoadMoney.6b6f153d
K7GWTrojan ( 0040f6ca1 )
CrowdStrikewin/grayware_confidence_100% (W)
BaiduWin32.Adware.Kryptik.c
VirITTrojan.Win32.Downloader.C
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.LoadMoney.XV
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:Downloader.Win32.LMN.gen
BitDefenderGen:Variant.Application.LoadMoney.57
NANO-AntivirusTrojan.Win32.LMN.dkxddd
AvastWin32:DropperX-gen [Drp]
RisingAdware.LoadMoney!1.AE7B (CLASSIC)
SophosTroj/LdMon-D
F-SecureProgram.APPL/Downloader.ghk
DrWebTrojan.LoadMoney.225
ZillyaAdware.AgentCRT.Win32.942
TrendMicroTROJ_GEN.R002C0OBM24
Trapminemalicious.high.ml.score
EmsisoftApplication.InstallMon (A)
IkarusVirus.Win32.Cryptor
GDataGen:Variant.Application.LoadMoney.57
JiangminDownloader.LMN.jvc
WebrootW32.Malware.gen
GoogleDetected
AviraAPPL/Downloader.ghk
Antiy-AVLRiskWare[Downloader]/Win32.LMN
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.BEUX@52xauq
ArcabitTrojan.Application.LoadMoney.57
ZoneAlarmnot-a-virus:Downloader.Win32.LMN.gen
MicrosoftPUAAdvertising:Win32/LoadMoney
VaristW32/LoadMoney.L.gen!Eldorado
AhnLab-V3Trojan/Win32.LoadMoney.C218025
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.iy1@ayJEU@kc
ALYacGen:Variant.Application.LoadMoney.57
MAXmalware (ai score=100)
VBA32BScope.Downloader.LMN
MalwarebytesLoadMoney.Adware.Bundler.DDS
PandaTrj/Genetic.gen
TencentTrojan.Win32.Downloader.abp
YandexPUA.Downloader!T7eeZn/zt58
SentinelOneStatic AI – Malicious PE
FortinetRiskware/LMN
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.fd90e5
DeepInstinctMALICIOUS

How to remove Win32/Adware.LoadMoney.XV?

Win32/Adware.LoadMoney.XV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment