Adware

Adware.DotDo.LD (file analysis)

Malware Removal

The Adware.DotDo.LD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.DotDo.LD virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Adware.DotDo.LD?


File Info:

name: 28D6E135790D7F8B2148.mlw
path: /opt/CAPEv2/storage/binaries/22e68d2e97acfa73c42395feee50962002909286001d88aa5008c3cf8612cbb7
crc32: 40295D54
md5: 28d6e135790d7f8b21489cb4a796df9a
sha1: e7068fe63c79056b64fd446d4f7f77d6e5bda73b
sha256: 22e68d2e97acfa73c42395feee50962002909286001d88aa5008c3cf8612cbb7
sha512: 36b18cfacfa3d1446d999d0f2eaa468e5a678765907afcee3f29bce3f5ed01eafe7339d9a6d7e0df2865fef9c11c21edeb432347a9b03707a7d971d6049bf094
ssdeep: 192:EQMJEcxIybM2huVMWcaJHccVxYL1Isl/tkkEHlsez5YfKET//bP1:ToZ3u+AJHccVi6s8kEHPz5YfKs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9826D52F314877FC93D0773D8AB914027B4AE09D6A645AA548B7A3BCCB133180E3E97
sha3_384: 2c1310508588fb275400dd2f296e1ae311384c0ae2bb5dca546b1b4a7abdb210d6ab2469e442f255fdd0f4a45375c9a8
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-10-18 07:03:31

Version Info:

Translation: 0x0000 0x04b0
FileDescription: Seawolf
FileVersion: 5.4.9.139
InternalName: Seawolf.exe
LegalCopyright:
OriginalFilename: Seawolf.exe
ProductName: Seawolf
ProductVersion: 5.4.9.139
Assembly Version: 5.4.9.139

Adware.DotDo.LD also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanAdware.DotDo.LD
FireEyeGeneric.mg.28d6e135790d7f8b
ALYacAdware.DotDo.LD
CylanceUnsafe
AlibabaTrojan:MSIL/Kubik.1268309f
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.Dotdo.HY
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Kubik.gen
BitDefenderAdware.DotDo.LD
NANO-AntivirusTrojan.Win32.Kubik.ixnams
AvastWin32:AdwareX-gen [Adw]
Ad-AwareAdware.DotDo.LD
SophosGeneric ML PUA (PUA)
ComodoApplication.MSIL.Dotdo.ER@8egbxo
VIPREAdware.DotDo
TrendMicroTROJ_GEN.R002C0PKN21
McAfee-GW-EditionTskLnk
EmsisoftAdware.DotDo.LD (B)
IkarusAdWare.MSIL.Dotdo
GDataAdware.DotDo.LD
AviraHEUR/AGEN.1119346
Antiy-AVLTrojan/Generic.ASMalwS.28A9DCC
GridinsoftRansom.Win32.Occamy.sa
MicrosoftTrojan:Win32/Occamy.C22
CynetMalicious (score: 100)
McAfeeTskLnk
MAXmalware (ai score=66)
MalwarebytesAdware.DotDo.Generic.TskLnk
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
TencentMsil.Adware.Dotdo.Htwg
YandexPUA.Dotdo!Z00t8hblAe4
SentinelOneStatic AI – Malicious PE
FortinetAdware/Dotdo
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.5790d7
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Adware.DotDo.LD?

Adware.DotDo.LD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment