PUA

How to remove “Dotdo (PUA)”?

Malware Removal

The Dotdo (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dotdo (PUA) virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Dotdo (PUA)?


File Info:

crc32: 1F4B7AB9
md5: 9488708d42ddf3074eb83a85431fb014
name: 9488708D42DDF3074EB83A85431FB014.mlw
sha1: c8bfb8fead3e3fdddbce87f00e5ce73b4b1a6c47
sha256: c4c0d6633f1c96797b995a424ac1d8f92d6f6d472e4ab24317d6e2689ed6495c
sha512: 755a113dafb3589681348dfb1de93fc76581775f659baceb7534afa35c162b7c00a87322d4b5633954048d56f67a9c22c60c3772ace9c813d6edaef56a642f70
ssdeep: 96:ghIdqJYK/Vyd5duIFldr9rjC2LhOsClXk4VLke3ASzNt:ghIoqPd5duIFTRru28Bk4tF3j
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Castaneda.exe
FileVersion: 0.0.0.0
Comments: Castaneda
ProductName: Castaneda
ProductVersion: 0.0.0.0
FileDescription: Castaneda
OriginalFilename: Castaneda.exe

Dotdo (PUA) also known as:

K7AntiVirusAdware ( 0055c5971 )
LionicTrojan.MSIL.Kubik.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.42523
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.47433243
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
K7GWAdware ( 0055c5971 )
CyrenW32/DotDo.AD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.Dotdo.HY
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
KasperskyHEUR:Trojan.MSIL.Kubik.gen
BitDefenderTrojan.GenericKD.47433243
MicroWorld-eScanTrojan.GenericKD.47433243
TencentMsil.Trojan.Kubik.Htca
Ad-AwareTrojan.GenericKD.47433243
SophosDotdo (PUA)
ComodoApplication.MSIL.Dotdo.GI@8dtvh3
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
FireEyeGeneric.mg.9488708d42ddf307
EmsisoftTrojan.GenericKD.47433243 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.alhli
AviraHEUR/AGEN.1124738
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Generic.D2D3C61B
GDataTrojan.GenericKD.47433243
AhnLab-V3PUP/Win32.DotDo.R300830
McAfeeRDN/Generic PUP.x
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
MalwarebytesAdware.DotDo.Generic.TskLnk
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kubik.gen!tr
AVGWin32:AdwareX-gen [Adw]

How to remove Dotdo (PUA)?

Dotdo (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment