PUA

How to remove “Win32:LoadMoney-CA [PUP]”?

Malware Removal

The Win32:LoadMoney-CA [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:LoadMoney-CA [PUP] virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win32:LoadMoney-CA [PUP]?


File Info:

name: 7AFBE1B67573B1E460B8.mlw
path: /opt/CAPEv2/storage/binaries/6fc222c394d93206589672ad7fffd677219eb02b29c50ccdb6a7096dd060e8af
crc32: DAB00637
md5: 7afbe1b67573b1e460b8d1c70999af30
sha1: 7ba0b51a1120c4b80de2b69bfe4d587d671a2de4
sha256: 6fc222c394d93206589672ad7fffd677219eb02b29c50ccdb6a7096dd060e8af
sha512: 64c7dc8d8e93a8ab03ca69b353ffe45ba7bf5a7cd5415dbb7b20fc39840b8ba3ea5d72447e134bd7ed88bbaea2714d41a3c25c820ade7fea783363664c675c0d
ssdeep: 3072:7YTbZc+8Yg9Ae7G53FL6a8TzrZJUPiJQjBadNApA/gYNTgi:7YPZc+9NnFOJfrZJUPi5ge
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12C944F51E243C8B5DC1303F5D896EBF51D12AD24FD2149EF728B7E09FA3369210A9A27
sha3_384: f453cea740c4cafe43579cfb725e3c440809fd56a302055c504433a630c009bd4ca0fbf077942e1cca3db444b7b58555
ep_bytes: 5589e583ec18c7042402000000ff1558
timestamp: 2013-09-07 19:33:42

Version Info:

FileDescription: Downloader for Get-Tune.Net
FileVersion: 1, 0, 0, 1
InternalName: Downloader for Get-Tune.Net
LegalCopyright: Copyright c 2005 - 2013
OriginalFilename: Downloader.exe
ProductName: Downloader for Get-Tune.Net
ProductVersion: 1, 0, 0, 1
Translation: 0x0419 0x04e3

Win32:LoadMoney-CA [PUP] also known as:

BkavW32.AIDetectMalware
AVGWin32:LoadMoney-CA [PUP]
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader11.6514
MicroWorld-eScanGen:Application.LoadMoney.1
CAT-QuickHealTrojanDownloader.LMN.A7
SkyhighBehavesLike.Win32.PWSZbot.gm
McAfeePUP-FFK
Cylanceunsafe
ZillyaDownloader.LMNGen.Win32.8
SangforTrojan.Win32.Save.a
K7AntiVirusDialer ( 0040f6271 )
K7GWDialer ( 0040f6271 )
Cybereasonmalicious.67573b
VirITTrojan.Win32.DownLoader11.JQO
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/LoadMoney.AW potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Adware.LoadMoney-3644756-1
Kasperskynot-a-virus:AdWare.Win32.LMN.apm
BitDefenderGen:Application.LoadMoney.1
NANO-AntivirusRiskware.Win32.LMN.cykkaf
AvastWin32:LoadMoney-CA [PUP]
EmsisoftGen:Application.LoadMoney.1 (B)
F-SecurePotentialRisk.PUA/LoadMoney.Gen7
BaiduWin32.Trojan.Kryptik.dl
VIPREGen:Application.LoadMoney.1
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7afbe1b67573b1e4
SophosTroj/LdMon-C
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.atwqf
WebrootPua.Gen
GoogleDetected
AviraPUA/LoadMoney.Gen7
MAXmalware (ai score=78)
Antiy-AVLTrojan[Downloader]/Win32.LMN
Kingsoftmalware.kb.a.973
MicrosoftTrojan:Win32/Dorv.A
XcitiumTrojWare.Win32.Kryptik.AXJX@4vl4hu
ArcabitApplication.LoadMoney.1
ViRobotTrojan.Win32.Generic.312216.A
ZoneAlarmnot-a-virus:AdWare.Win32.LMN.apm
GDataWin32.Trojan.PSE.2U6HON
VaristW32/LoadMoney.B.gen!Eldorado
AhnLab-V3PUP/Win32.LoadMoney.C206415
ALYacGen:Application.LoadMoney.1
VBA32Downware.LMN.gen
MalwarebytesGeneric.Malware.AI.DDS
RisingDownloader.Small!1.65D6 (CLASSIC)
YandexPUA.Downloader!QMv3OvOXF+A
IkarusTrojan.Win32.Spy
MaxSecureDownloader.LMN.a
FortinetW32/Generic.AC.6F6F!tr
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Win32:LoadMoney-CA [PUP]?

Win32:LoadMoney-CA [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment