Malware

AdWare.MSIL.DomaIQ.abr (file analysis)

Malware Removal

The AdWare.MSIL.DomaIQ.abr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.MSIL.DomaIQ.abr virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine AdWare.MSIL.DomaIQ.abr?


File Info:

name: 371C1DF899F9B148A09E.mlw
path: /opt/CAPEv2/storage/binaries/5a3fc1727ee82d48de48f43762c3879781b64cf44eab01342bbfe5de68478877
crc32: E67BE5D3
md5: 371c1df899f9b148a09e3c6f58c37793
sha1: 8b1474046cc97229823e05689d8c018a1c03b5fd
sha256: 5a3fc1727ee82d48de48f43762c3879781b64cf44eab01342bbfe5de68478877
sha512: 73f4b4950d23370ec1db614d056c085303de39125fb95c384554e0e7a141ffb0786de746f272263f1472d093c44000323e2f5ca5bd0195b4468a2e436fcce8b9
ssdeep: 96:JD6MP7LdxCQv5r/S41104PCvJThcxg/gT:tXPNoY9/BfCvJThsZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17FC1C81197E94B3BDCBA0B7DDD73A3819374E611E963CF2FEC55811A181263C02A1B75
sha3_384: 6021b29759e0a6c310f035f64c3ca111039ce34bcb79937d27673748f0d11a9a6a5328d949d8e399b2151e1788d3500e
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-01-09 16:46:32

Version Info:

Translation: 0x0000 0x04b0
FileDescription: llrssmqsdvwwz
FileVersion: 4.0.6.315
InternalName: setup.exe
LegalCopyright:
OriginalFilename: setup.exe
ProductVersion: 4.0.6.315
Assembly Version: 4.0.6.315

AdWare.MSIL.DomaIQ.abr also known as:

FireEyeGeneric.mg.371c1df899f9b148
CylanceUnsafe
SangforPUP.Win32.DomaIQ.Gen
K7AntiVirusTrojan ( 700000121 )
AlibabaAdWare:MSIL/DomaIQ.6e4594a1
K7GWTrojan ( 700000121 )
CyrenW32/A-5019a7d8!Eldorado
SymantecSecurityRisk.Downldr
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Adware.Domaiq-225
Kasperskynot-a-virus:AdWare.MSIL.DomaIQ.abr
NANO-AntivirusTrojan.Win32.Adw.ddqexe
AvastFileRepMetagen [PUP]
ComodoApplication.MSIL.DomaIQ.A@56xcaz
ZillyaAdware.DomaIQ.Win32.606
TrendMicroTROJ_SPNR.0BAR14
McAfee-GW-EditionBehavesLike.Win32.PUP.xt
SophosDomaIQ pay-per install (PUA)
SentinelOneStatic AI – Malicious PE
GDataMSIL.Application.DomalQ.E
JiangminAdWare/MSIL.eaj
WebrootW32.Rogue.Gen
AviraPUA/DomaIQ.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.3429
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ViRobotAdware.Domaiq.6144.B
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.DomaIQ.R138367
McAfeeArtemis!371C1DF899F9
TACHYONTrojan-Clicker/W32.DN-Agent.6144.B
VBA32AdWare.MSIL.DomaIQ
MalwarebytesPUP.Optional.BundleInstaller
TrendMicro-HouseCallTROJ_SPNR.0BAR14
RisingTrojan.Ymacco!8.11BE1 (CLOUD)
YandexPUA.DomaIQ!PQmHlei8NTk
IkarusPUA.Bundler.DomaIQ
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.JAX!tr
AVGFileRepMetagen [PUP]
PandaPUP/BundleInstaller
CrowdStrikewin/grayware_confidence_90% (W)

How to remove AdWare.MSIL.DomaIQ.abr?

AdWare.MSIL.DomaIQ.abr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment