Adware

Should I remove “Win32/Adware.Dotdo.AA”?

Malware Removal

The Win32/Adware.Dotdo.AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.Dotdo.AA virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Adware.Dotdo.AA?


File Info:

name: 0A02F979693B67CC8557.mlw
path: /opt/CAPEv2/storage/binaries/4fdcdd223be5c8f0533e14fdc2c24d9e9e9b61139d627c392082ccb5cfdadfd7
crc32: 2034E098
md5: 0a02f979693b67cc8557404650969485
sha1: 9fcd373ea369ea0c2eeff739f9d16a7716c36e56
sha256: 4fdcdd223be5c8f0533e14fdc2c24d9e9e9b61139d627c392082ccb5cfdadfd7
sha512: 6a0654ef01be187389a9eda9c9758869a56850b8d061569905737f1cf9287f5f8b178a7e89e805738639acf1dd0cad3ca2692fe75f8812fdfc92a6232521a86f
ssdeep: 1536:QpgpHzb9dZVX9fHMvG0D3XJeSo4CCzpDOf2f:mgXdZt9P6D3XJbCCzpDOOf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7537C1EFAF6486BC56205301E73FB79C237DD660AD04A4717F83A3E6632143D52A2E9
sha3_384: 6746b2753801d2771a31ffed9878f0509f1a3de48fbcccb020cc3fb60f9f600d6d907fdf6957dca97506c6499e016380
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

Win32/Adware.Dotdo.AA also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Nemesis.44
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 0052de381 )
K7AntiVirusAdware ( 0052de381 )
ESET-NOD32Win32/Adware.Dotdo.AA
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.Agent.gen
NANO-AntivirusTrojan.Nsis.Dotdo.fbvnjr
EmsisoftGen:Variant.Adware.Nemesis.44 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PL521
SophosGeneric ML PUA (PUA)
AviraHEUR/AGEN.1142479
ArcabitTrojan.Adware.Nemesis.44
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
MalwarebytesAdware.DotDo.Generic
SentinelOneStatic AI – Suspicious PE
FortinetW32/Nemesis.AOB!tr

How to remove Win32/Adware.Dotdo.AA?

Win32/Adware.Dotdo.AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment