Malware

What is “Win32:LoadMoney-ATF [Adw]”?

Malware Removal

The Win32:LoadMoney-ATF [Adw] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:LoadMoney-ATF [Adw] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32:LoadMoney-ATF [Adw]?


File Info:

name: 9FB0D6319133498987C9.mlw
path: /opt/CAPEv2/storage/binaries/210326eaf31f7ac51944f8d40bbcc981a1b9932d9858060efdeeeffafb990386
crc32: D055402E
md5: 9fb0d6319133498987c9b3f80b24ae6a
sha1: e2c156794760df4e4b195ea08622b4c6b49f449d
sha256: 210326eaf31f7ac51944f8d40bbcc981a1b9932d9858060efdeeeffafb990386
sha512: 7e71fcdbcbd137f0f50f5fda375a70173d573e40ad009127119b2500ccbe5a9a7a461cf9d64f209954905dd43089052e9cfaab008495dc05fc487d06e6903a9d
ssdeep: 1536:8ngspT7WBlZ10z0r6z/j/WAvw3EcyE2Os4ZL/:8gs57WBlL0zBzrvgjL/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126E3E81BF9B37270CAC4C4B5F149A0B20D175D0D260118537B68BE463FAE96AE7AEF50
sha3_384: 3b172f12ab8803311db74472febabeb765cf76cc0cf9fc4366df0d5105e9fedadd8a6ea8cab08bf52012e6432dc0fddc
ep_bytes: 60be155042008dbeebbffdff5783cdff
timestamp: 2013-08-17 23:18:02

Version Info:

0: [No Data]

Win32:LoadMoney-ATF [Adw] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.lW9K
tehtrisGeneric.Malware
MicroWorld-eScanGen:Application.LoadMoney.1
FireEyeGeneric.mg.9fb0d63191334989
CAT-QuickHealPUA.LLCMail.DC7
SkyhighBehavesLike.Win32.PWSZbot.cm
McAfeeGenericRXAA-AA!9FB0D6319133
MalwarebytesGeneric.Malware.AI.DDS
ZillyaAdware.LMN.Win32.4020
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0053a0bf1 )
K7GWTrojan ( 0053a0bf1 )
CrowdStrikewin/grayware_confidence_100% (W)
ArcabitApplication.LoadMoney.1
VirITTrojan.Win32.LoadMoney.DB
SymantecTrojan.ADH
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/LoadMoney.Y.gen potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Loadmoney-12742
Kasperskynot-a-virus:AdWare.Win32.LMN.apm
BitDefenderGen:Application.LoadMoney.1
NANO-AntivirusTrojan.Win32.LoadMoney.dnqcen
AvastWin32:LoadMoney-ATF [Adw]
RisingTrojan.Agent!1.9CB1 (CLOUD)
EmsisoftGen:Application.LoadMoney.1 (B)
BaiduWin32.Trojan.Kryptik.dl
F-SecurePotentialRisk.PUA/LoadMoney.Gen
DrWebTrojan.LoadMoney.1
VIPREGen:Application.LoadMoney.1
TrendMicroTROJ_GEN.R002C0OBF24
Trapminemalicious.moderate.ml.score
SophosTroj/LdMon-A
IkarusTrojan.Win32.Spy
JiangminTrojan/Generic.atwqf
GoogleDetected
AviraPUA/LoadMoney.Gen
VaristW32/LoadMoney.F.gen!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.LoadMoney.gen
Kingsoftmalware.kb.b.921
XcitiumApplication.Win32.LoadMoney.jet@5448tv
MicrosoftPUAAdvertising:Win32/LoadMoney
ZoneAlarmnot-a-virus:AdWare.Win32.LMN.apm
GDataGen:Application.LoadMoney.1
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.LoadMoney.R228107
VBA32BScope.Downloader.LMN
ALYacGen:Application.LoadMoney.1
MAXmalware (ai score=99)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0OBF24
TencentMalware.Win32.Gencirc.1402bbfc
YandexPUA.DL.Agent!PRScAIAVQA4
SentinelOneStatic AI – Malicious PE
MaxSecureHoax.W32.ArchSMS.gen_281259
FortinetW32/Kryptik.CGBF!tr
AVGWin32:LoadMoney-ATF [Adw]
Cybereasonmalicious.94760d
DeepInstinctMALICIOUS

How to remove Win32:LoadMoney-ATF [Adw]?

Win32:LoadMoney-ATF [Adw] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment