Malware

UDS:AdWare.NSIS.Dotdo malicious file

Malware Removal

The UDS:AdWare.NSIS.Dotdo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:AdWare.NSIS.Dotdo virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid

How to determine UDS:AdWare.NSIS.Dotdo?


File Info:

name: 112C96CD3E037B48F984.mlw
path: /opt/CAPEv2/storage/binaries/26d03d35fb8290e28fd7215cf912abc90abafe6b62db9862f1973ad01b98b2d7
crc32: 4297D55A
md5: 112c96cd3e037b48f984fa34450717a0
sha1: 83f46ef3696b5ae3e6dce8439793e5bda1ac194e
sha256: 26d03d35fb8290e28fd7215cf912abc90abafe6b62db9862f1973ad01b98b2d7
sha512: 6dbfd8747b55551911036d6b28a586740158c43aed8e236ccf0653fb3fed4dc9d5264902e6572d8f9c0cf56530709e20b51f539c564ab6c05301b462d5033542
ssdeep: 768:4nnw4xRMjJ8FBDOLQmzPjhAVHx10Z0D3yuInmBd0cpbT2nJjuL4B9:Snw8RSijDtSA5xeZ0DbBCcpbCBuLc9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B6039E0367A0D8FBD9B103B01D7AAF2BEFFA81181195670B0B846F5A7D23583461F293
sha3_384: 233b4a0d470313451ca2ecdd531097a9a8330bb685b3d63d72f0d051c7bfadd11acf6a7ca2b09a44c2d1cca3b7ed72e0
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2017-08-01 00:34:02

Version Info:

0: [No Data]

UDS:AdWare.NSIS.Dotdo also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!e
Elasticmalicious (high confidence)
DrWebAdware.Dotdo.196
FireEyeGeneric.mg.112c96cd3e037b48
McAfeeArtemis!112C96CD3E03
CylanceUnsafe
AlibabaAdWare:MSIL/Dotdo.4c189436
CrowdStrikewin/grayware_confidence_100% (W)
CyrenW32/Dotdo.G.gen!Eldorado
ESET-NOD32multiple detections
Paloaltogeneric.ml
Kasperskynot-a-virus:UDS:AdWare.NSIS.Dotdo.gen
NANO-AntivirusRiskware.Win32.Dotdo.fmrmvs
AvastWin32:Adware-gen [Adw]
TencentNsis.Adware.Dotdo.Ducq
ComodoApplication.MSIL.Razy.B@7xyy94
McAfee-GW-EditionBehavesLike.Win32.AdwareTskLnk.nh
SophosGeneric PUA ID (PUA)
IkarusAdWare.MSIL.Dotdo
AviraHEUR/AGEN.1224587
MAXmalware (ai score=100)
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DealPly.C2197855
Acronissuspicious
VBA32Adware.Dotdo
MalwarebytesAdware.DotDo.Generic.TskLnk
APEXMalicious
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:Xx6CR9wSdORA7yhRwBkVew)
YandexPUA.Dotdo!jY7WPK28kss
SentinelOneStatic AI – Malicious PE
FortinetAdware/TskLnk
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A

How to remove UDS:AdWare.NSIS.Dotdo?

UDS:AdWare.NSIS.Dotdo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment