Adware

Adware.DNSUnlocker malicious file

Malware Removal

The Adware.DNSUnlocker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.DNSUnlocker virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Adware.DNSUnlocker?


File Info:

name: D1629B0D2AC259770DE3.mlw
path: /opt/CAPEv2/storage/binaries/1f5a76e38308f697fdb2af04353853fbb76d6bc07fcc44b9015f0d1247ff95f5
crc32: 4C0ACAA1
md5: d1629b0d2ac259770de3c23065e7ea6b
sha1: 698fc2e061910c3a6281ce1474018d989176a522
sha256: 1f5a76e38308f697fdb2af04353853fbb76d6bc07fcc44b9015f0d1247ff95f5
sha512: bc445d76dfcebf488a582f735f640eb2217a65385bd891617475c02cbb860a52f94d002ad47f41a80befdcac57d2bbe3839f75dcadec58fc3fd39dc688739315
ssdeep: 24576:vBW8ZdoB+30imZv39VsSyBRhSGS4cP0yfBi5BAhu0tlqmuBYKq7I6Khyk0tu:Yjm0DZbFyB3Df2cj4lqnLSKhj0g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DF652243F3D300B1F07969398C648494ED6379A918F0606A2EF9EB0D5F7E6C68CB9752
sha3_384: 0efb8daefce268e808236838b77013595b089997ccb1d362e242324ced40d36869f6ed8b9a5e7576512739a268fe3927
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2016-04-06 14:39:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion:
LegalCopyright:
ProductName:
ProductVersion:
Translation: 0x0000 0x04b0

Adware.DNSUnlocker also known as:

LionicAdware.Win32.Adposhel.2!c
Elasticmalicious (high confidence)
DrWebTrojan.Adposhel.33
MicroWorld-eScanAdware.GenericKD.30926322
FireEyeAdware.GenericKD.30926322
McAfeeAdware-Adposhel
CylanceUnsafe
SangforSuspicious.Win32.Heur.gen
AlibabaAdWare:Win32/Adposhel.3cbefc72
Cybereasonmalicious.d2ac25
BitDefenderThetaGen:NN.ZedlaF.34182.cv4@aOd00!b
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Adware.Adposhel.AW
TrendMicro-HouseCallTROJ_GEN.R007C0OB222
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.Adposhel.lqwq
BitDefenderAdware.GenericKD.30926322
NANO-AntivirusRiskware.Win32.Adposhel.fapgjo
SUPERAntiSpywareAdware.AdPoshel/Variant
AvastNSIS:Adposhel-B [Trj]
TencentWin32.Trojan.Generic.Woza
SophosGeneric PUA GJ (PUA)
ComodoApplicUnwnt@#2irl0r9p4nq0r
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R007C0OB222
McAfee-GW-EditionAdware-Adposhel
SentinelOneStatic AI – Suspicious PE
EmsisoftAdware.GenericKD.30926322 (B)
IkarusPUA.Adposhel
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1206214
Antiy-AVLTrojan/Generic.ASMalwS.25E7296
MicrosoftTrojan:Win32/Occamy.C1F
ZoneAlarmnot-a-virus:AdWare.Win32.Adposhel.lqwq
GDataWin32.Application.Agent.AFW
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.Adposhel.R226701
VBA32Trojan.Adposhel
ALYacAdware.GenericKD.30926322
MalwarebytesAdware.DNSUnlocker
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexPUA.Adposhel!M+vQq2HD1Bk
MAXmalware (ai score=95)
FortinetW32/Adposhel.AW
WebrootAdware.Fastdata.X
AVGNSIS:Adposhel-B [Trj]
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Adware.DNSUnlocker?

Adware.DNSUnlocker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment