Home Malware Programs Adware Dotdo Ads

Dotdo Ads

Posted: June 1, 2015

Threat Metric

Ranking: 3,974
Threat Level: 8/10
Infected PCs: 170,849
First Seen: June 1, 2015
Last Seen: October 15, 2023
OS(es) Affected: Windows

In case your computer suddenly start displaying annoying advertisements by Dotdo while browsing websites such as Amazon and eBay, it is highly likely that you are a victim of adware. Dotdo is yet another adware that is distributed via questionable marketing methods like bundling. Since adware creators are well aware that users do not remain attentive during installation of software, they often bundle products like Dotdo to non-harmful applications. When users download freeware, they accidentally install both (or more) applications and thus get infected. Once you have installed Dotdo, it automatically starts collecting information related to your browsing activities. However, computer security experts deemed that ads by Dotdo are not reliable as they are tailored, and users are not advised to click them. In case you accidentally click on any of the ads by Dotdo, you will be redirected to a third-party website that might be questionable or promote unreliable applications. In other cases, users might be redirected to malicious websites that might endanger their online security. To remove the annoying ads by Dotdo, it is recommended to utilize a trusted anti-malware tool that will scan and clean up your computer.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Puig\nyssa.exe File name: nyssa.exe
Size: 61.43 KB (61437 bytes)
MD5: 4dcf592b89e908df72eb7c2d3e2a9791
Detection count: 1,387
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Puig\nyssa.exe
Group: Malware file
Last Updated: June 26, 2020
%PROGRAMFILES(x86)%\barba\barba.exe File name: barba.exe
Size: 9.21 KB (9216 bytes)
MD5: cffe5a9930457bbae7b2d0f5ef4fa43d
Detection count: 1,384
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\barba\barba.exe
Group: Malware file
Last Updated: June 26, 2020
%PROGRAMFILES(x86)%\kallen\orangutan.exe File name: orangutan.exe
Size: 49.51 KB (49513 bytes)
MD5: 79abfa0effda89d36ff7d3566ed3c121
Detection count: 1,384
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\kallen\orangutan.exe
Group: Malware file
Last Updated: June 26, 2020
%PROGRAMFILES(x86)%\mozilla firefox\firefox.exe File name: firefox.exe
Size: 135.83 KB (135837 bytes)
MD5: 6e0e064fbbc110a47d72970bda792df1
Detection count: 1,377
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\mozilla firefox\firefox.exe
Group: Malware file
Last Updated: June 26, 2020
%PROGRAMFILES(x86)%\Prieto\cause.exe File name: cause.exe
Size: 10.24 KB (10240 bytes)
MD5: d9656c42aa71d7f2dc01b701c4bb3fa7
Detection count: 445
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Prieto
Group: Malware file
Last Updated: September 21, 2017
%PROGRAMFILES%\Corpulent\scratches.exe File name: scratches.exe
Size: 12.28 KB (12288 bytes)
MD5: c6f4107d14ae08e12be8d15937b9f7d9
Detection count: 208
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Corpulent
Group: Malware file
Last Updated: September 19, 2017
%PROGRAMFILES%\Probenecid\waterman.exe File name: waterman.exe
Size: 12.28 KB (12288 bytes)
MD5: 7167cf8a5f835d778c7e9aad5cf799cf
Detection count: 176
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Probenecid
Group: Malware file
Last Updated: September 19, 2017
%PROGRAMFILES(x86)%\Reacts\rabo.exe File name: rabo.exe
Size: 61.39 KB (61390 bytes)
MD5: a3983cbb901d1714134d3c4f292cf284
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Reacts\rabo.exe
Group: Malware file
Last Updated: June 26, 2020
%PROGRAMFILES%\Fontana\timbre.exe File name: timbre.exe
Size: 12.28 KB (12288 bytes)
MD5: cdd69a3369502463450ad78ffcbdd592
Detection count: 157
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Fontana
Group: Malware file
Last Updated: September 19, 2017
%PROGRAMFILES(x86)%\Rec\direst.exe File name: direst.exe
Size: 12.28 KB (12288 bytes)
MD5: ac2c50ad069aeaf8a689d983c5266728
Detection count: 143
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Rec
Group: Malware file
Last Updated: September 19, 2017
%PROGRAMFILES%\Hallow\breathers.exe File name: breathers.exe
Size: 12.28 KB (12288 bytes)
MD5: 45147c1848c953aaf8e9480953d224b5
Detection count: 119
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Hallow
Group: Malware file
Last Updated: September 19, 2017
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Debord.exe File name: Debord.exe
Size: 9.72 KB (9728 bytes)
MD5: c93deba7bda46f92cb618207d6fcb0e7
Detection count: 117
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Debord.exe
Group: Malware file
Last Updated: June 26, 2020
%LOCALAPPDATA%\kael.exe File name: kael.exe
Size: 11.77 KB (11776 bytes)
MD5: a9b61f1b74d006340e272afe4f3aef94
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: August 26, 2017
%LOCALAPPDATA%\mouthful.exe File name: mouthful.exe
Size: 11.77 KB (11776 bytes)
MD5: 0fb0ca8d0b0b2fb3f6f2e7d957b8d9fb
Detection count: 81
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: August 26, 2017
%PROGRAMFILES%\Ctp\reilly.exe File name: reilly.exe
Size: 10.24 KB (10240 bytes)
MD5: 1e06958a3dd8436e74c7b7da631ed79e
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Ctp
Group: Malware file
Last Updated: September 21, 2017
%PROGRAMFILES(x86)%\Louder\toad.exe File name: toad.exe
Size: 48.67 KB (48674 bytes)
MD5: f123f0abbc2ecb0f54ff0cb83f45d4c7
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Louder\toad.exe
Group: Malware file
Last Updated: June 26, 2020
%PROGRAMFILES%\linda\narita.exe File name: narita.exe
Size: 49.5 KB (49506 bytes)
MD5: 5e9242db8a2d27fe627898576ffc0504
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\linda\narita.exe
Group: Malware file
Last Updated: June 26, 2020
%PROGRAMFILES%\Bunyan\dropoff.exe File name: dropoff.exe
Size: 12.28 KB (12288 bytes)
MD5: c540a8852fe75d751aba383fb149e3e6
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Bunyan
Group: Malware file
Last Updated: September 19, 2017
%LOCALAPPDATA%\activism.exe File name: activism.exe
Size: 11.77 KB (11776 bytes)
MD5: 76544eef0534fcf92077536a0f65df3e
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: August 26, 2017
%LOCALAPPDATA%\wired.exe File name: wired.exe
Size: 11.77 KB (11776 bytes)
MD5: d43be8764d39f66c368b393120b6ce1d
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: August 26, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%HOMEDRIVE%\a\internetport3.exe%HOMEDRIVE%\a\wincheckfe.exe%LOCALAPPDATA%\tinstall[NUMBERS].exeHKEY..\..\..\..{RegistryKeys}SOFTWARE\dingdongdeSOFTWARE\dndingSOFTWARE\idotSOFTWARE\Microsoft\Tracing\ddnow_RASAPI32SOFTWARE\Microsoft\Tracing\ddnow_RASMANCSSOFTWARE\Wow6432Node\dingdongdeSOFTWARE\Wow6432Node\dndingSOFTWARE\Wow6432Node\idotHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}FastIn

Additional Information

The following directories were created:
%PROGRAMFILES(x86)%\FastInternet
Loading...