Adware

Adware.CsdiMonetize.2 (B) removal instruction

Malware Removal

The Adware.CsdiMonetize.2 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.CsdiMonetize.2 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid

How to determine Adware.CsdiMonetize.2 (B)?


File Info:

name: C390AED588A509DAA8E8.mlw
path: /opt/CAPEv2/storage/binaries/c4fa61353b06c30f47e40f30637b9099d07efa839f992f8aea02ce9949bc0c57
crc32: BBE13B93
md5: c390aed588a509daa8e8bf1ce49ffb48
sha1: 8f6d8cb916e32712c7974e3248a3b3bfca9e9fb4
sha256: c4fa61353b06c30f47e40f30637b9099d07efa839f992f8aea02ce9949bc0c57
sha512: b3ef89d41d66ae941499b4d41fd19b85449326e58db68a372d1e93afc0305b8a4307d92a872b3519a014f823f0606905c8e1608e4a9c00f36dcb44b1bbe42a9e
ssdeep: 24576:H0lZaF+0Z6zIaeFRiw7zathdmhYMLC8NtZLj7u0Dii1jKd9lEbEbvIPTUCR8:Ul8FqzM8hI/Ntlj7ulgUvcR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7459ED63F2D7B53C3DE0E37E4D13A5A8BF4C1219F8BE34A748A18618C87F9A4901566
sha3_384: 7c49b30f714b32a1b9a30e5319a1e66d3a9b85cb7eaac6c26b122def6407c3ad978e642114ad600759eee9cca09e3a41
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-01-05 00:43:13

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: determinesspecificsettings
FileVersion: 1.0.0.0
InternalName: determinesspecificsettings.exe
LegalCopyright: Copyright © 2017
LegalTrademarks:
OriginalFilename: determinesspecificsettings.exe
ProductName: determinesspecificsettings
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Adware.CsdiMonetize.2 (B) also known as:

LionicAdware.MSIL.Eorezo.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.CsdiMonetize.2
FireEyeGeneric.mg.c390aed588a509da
CAT-QuickHealPUA.CsdimonetizeFC.S20328448
CylanceUnsafe
VIPREAdware.Eorezo
SangforAdware.Win32.CsdiMonetize.2
AlibabaAdWare:MSIL/Eorezo.a79854de
Cybereasonmalicious.588a50
BitDefenderThetaGen:NN.ZemsilCO.34114.kn0@a0LRZ3e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.CsdiMonetize.AG
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Eorezo.gen
BitDefenderGen:Variant.Adware.CsdiMonetize.2
NANO-AntivirusRiskware.Win32.EoRezo.exdnoz
AvastWin32:AdwareX-gen [Adw]
RisingAdware.WizzNetwork!1.CDFD (CLASSIC)
Ad-AwareGen:Variant.Adware.CsdiMonetize.2
SophosCsdiMonetize (PUA)
ZillyaAdware.Eorezo.Win32.38931
McAfee-GW-EditionGenericRXDR-EB!C390AED588A5
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Adware.CsdiMonetize.2 (B)
IkarusAdWare.MSIL.Csdimonetize
GDataGen:Variant.Adware.CsdiMonetize.2
JiangminAdWare.MSIL.jnrt
WebrootW32.Malware.Gen
AviraADWARE/EoRezo.EO
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 99)
McAfeeGenericRXDR-EB!C390AED588A5
VBA32Adware.MSIL.Eorezo
MalwarebytesMalware.AI.1339161439
APEXMalicious
TencentMsil.Adware.Csdimonetize.Sxxo
YandexPUA.Eorezo!KMpkk8H0YRU
MAXmalware (ai score=69)
FortinetAdware/CsdiMonetize
AVGWin32:AdwareX-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Adware.CsdiMonetize.2 (B)?

Adware.CsdiMonetize.2 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment