PUA

Win32:LoadMoney-ZM [PUP] malicious file

Malware Removal

The Win32:LoadMoney-ZM [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:LoadMoney-ZM [PUP] virus can do?

  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:LoadMoney-ZM [PUP]?


File Info:

name: CCDEE48D960BF07BB207.mlw
path: /opt/CAPEv2/storage/binaries/e1a531e85df0a0b0a376400b94ddefe4755c1f197e5b600f29e8ff9249c81f77
crc32: 8FEBFAEE
md5: ccdee48d960bf07bb207384e21ece4fa
sha1: c6d1a69b051a0b05e00d0e4f8cc1d3759159b621
sha256: e1a531e85df0a0b0a376400b94ddefe4755c1f197e5b600f29e8ff9249c81f77
sha512: 20e6195c006b788ebacbc45853464e48e5718447a2d5226712f17a1638286e26b7dd21f2e5a9b988fce346f92a3c605bd288d1bdb8197a28d799bca7442c262a
ssdeep: 12288:+ohh+i3JzZoh738zqbtnRgOaJyYVh+xQqi:+Oh+iRgD82btnRgOaJyYVh+Gqi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7948E22B795E472C01302B16E16CA78A5F6BCB2E936454777D84F1DAFB01C25A3AF43
sha3_384: 129499b479c493cdc477fb196813b3411088ab126e339d09da323c339dd6870175de28e9cf268d4dea51bbce7673248f
ep_bytes: e8077e0000e979feffffcccccccccccc
timestamp: 2015-02-25 12:00:51

Version Info:

0: [No Data]

Win32:LoadMoney-ZM [PUP] also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.LoadMoney.1!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Adware.Graftor.202302
FireEyeGeneric.mg.ccdee48d960bf07b
CAT-QuickHealDownloader.Lmn.6035
ALYacGen:Variant.Adware.Graftor.202302
MalwarebytesLoadMoney.Adware.Bundler.DDS
VIPREGen:Variant.Adware.Graftor.202302
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004b87be1 )
AlibabaAdWare:Win32/LoadMoney.c67a9486
K7GWAdware ( 004b87be1 )
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW32/S-edc5e9ac!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Adware.LoadMoney.RM
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Adware.Graftor.202302
NANO-AntivirusTrojan.Win32.LoadMoney.jqlqpi
ViRobotAdware.Loadmoney.435712.DP
AvastWin32:LoadMoney-ZM [PUP]
RisingTrojan.Generic@AI.100 (RDML:BXwGkV50FNg6AzIxvnAV4A)
EmsisoftGen:Variant.Adware.Graftor.202302 (B)
DrWebTrojan.LoadMoney.469
ZillyaAdware.LoadMoneyGen.Win32.4
TrendMicroTROJ_GEN.R002C0PFG23
McAfee-GW-EditionBehavesLike.Win32.FakeAVWinwebSecurity.gh
SophosGeneric Reputation PUA (PUA)
IkarusWorm.VBS.Agent
GDataGen:Variant.Adware.Graftor.202302
JiangminDownloader.Generic.borw
MAXmalware (ai score=68)
Antiy-AVLRiskWare[Downloader]/Win32.AGeneric
ArcabitTrojan.Adware.Graftor.D3163E
MicrosoftPUA:Win32/Puwaders.C!ml
GoogleDetected
AhnLab-V3Adware/Win.LoadMoney.R506126
McAfeeGenericRXUD-FQ!CCDEE48D960B
VBA32TrojanDropper.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PFG23
TencentMalware.Win32.Gencirc.10bc0953
YandexTrojan.GenAsa!8TPVfTZcbZ4
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/LoadMoney
AVGWin32:LoadMoney-ZM [PUP]
Cybereasonmalicious.d960bf
DeepInstinctMALICIOUS

How to remove Win32:LoadMoney-ZM [PUP]?

Win32:LoadMoney-ZM [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment