Adware

What is “Adware:MSIL/Dotdo.SR!MSR”?

Malware Removal

The Adware:MSIL/Dotdo.SR!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:MSIL/Dotdo.SR!MSR virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Adware:MSIL/Dotdo.SR!MSR?


File Info:

name: E02F43DBE9F2187F43FA.mlw
path: /opt/CAPEv2/storage/binaries/09a12b9e4c0649d0bf6f665b50323c287ccaad2d8dcd89e98a048a78f5533d64
crc32: F5ADCEE0
md5: e02f43dbe9f2187f43fa2845dffde45b
sha1: e848c1322d94be2f5a30fc9309ed7675000159ad
sha256: 09a12b9e4c0649d0bf6f665b50323c287ccaad2d8dcd89e98a048a78f5533d64
sha512: fc43a0114c5d1aa9646d2d50e757a703d6b8f3c59a69ebcb084ad7a95f017adb94c4c171dc5d1907ea1e8ca0aac06bf55a60484236043b6678ea1c69029f1e37
ssdeep: 96:wbkZPQv1cdPMvfOdSKcMWx8omJipER5cxSwbghqxPyehhMzNt:cSdEedxQ8YpER5kSwrx6oM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA120A41B34846E7D8BA4336DAB387456674FE18A5078F2F71E0FC27BD2A27549A3630
sha3_384: 8730aeeacba580187e720bb46fca9ee849fc2b367e40d9ed0113540d18a86465260370443f06cb5de817445ca953885f
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-06-22 07:02:18

Version Info:

Translation: 0x0000 0x04b0
FileDescription: peregrine
FileVersion: 7.6.3.60
InternalName: unsanitary.exe
LegalCopyright:
OriginalFilename: unsanitary.exe
ProductName: peregrine
ProductVersion: 7.6.3.60
Assembly Version: 7.6.3.60

Adware:MSIL/Dotdo.SR!MSR also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.Clicker.PJ
FireEyeGeneric.mg.e02f43dbe9f2187f
SkyhighAdware-TskLnk
McAfeeAdware-TskLnk
Cylanceunsafe
ZillyaAdware.Dotdo.Win32.20731
SangforSuspicious.Win32.Save.a
AlibabaAdWare:MSIL/Dotdo.c7cdc6f8
ArcabitAdware.Clicker.PJ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.Dotdo.FN
CynetMalicious (score: 100)
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Agent.gen
BitDefenderAdware.Clicker.PJ
AvastWin32:Adware-gen [Adw]
TencentMsil.AdWare.Agent.Tzfl
EmsisoftAdware.Clicker.PJ (B)
F-SecureHeuristic.HEUR/AGEN.1312851
VIPREAdware.Clicker.PJ
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
VaristW32/Dotdo.G.gen!Eldorado
AviraHEUR/AGEN.1312851
MAXmalware (ai score=66)
Kingsoftmalware.kb.c.978
XcitiumApplication.MSIL.Dotdo.FD@7xsnmu
MicrosoftAdware:MSIL/Dotdo.SR!MSR
ZoneAlarmnot-a-virus:HEUR:AdWare.MSIL.Agent.gen
GDataAdware.Clicker.PJ
GoogleDetected
ALYacAdware.Clicker.PJ
MalwarebytesAdware.DotDo.Generic.TskLnk
PandaTrj/CI.A
RisingAdware.Dotdo/MSIL!1.B5C2 (CLOUD)
YandexPUA.Dotdo!NayZCc2/EUg
IkarusAdWare.MSIL.Dotdo
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Ursu.44BE!tr
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Adware:MSIL/Dotdo.SR!MSR?

Adware:MSIL/Dotdo.SR!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment