Adware

About “Adware:MSIL/Dotdo.SR!MSR” infection

Malware Removal

The Adware:MSIL/Dotdo.SR!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:MSIL/Dotdo.SR!MSR virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Adware:MSIL/Dotdo.SR!MSR?


File Info:

name: E87CD612A259BFB5499A.mlw
path: /opt/CAPEv2/storage/binaries/eb76f73d6e08277fa7702a460845438f8ca74d9625dffc9852ad465c0a00b954
crc32: DCB7237C
md5: e87cd612a259bfb5499abb8c0b8e0ec6
sha1: 1fa772da6470d7b34e1e5c89fcb502b188e7d735
sha256: eb76f73d6e08277fa7702a460845438f8ca74d9625dffc9852ad465c0a00b954
sha512: 706f56296d2b04a84648837061713c1188bb48aef2278f04f0d88ae902e8bcf4e4251f4d59fe38dd2e3ad334d7ec8bcfef181144eed26269f904c547d71bb698
ssdeep: 96:8TS8nk4oN1GKZj+GcKzPpfv/YbWua1zNt:m5qnTZHzdX7us
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C12D90663CD4393DF261B3388A2CA481E21BD73A657071A270CF1FE5EBEF184B69954
sha3_384: e17f336cac526752fd1ec9e403d408ab0c4f045d0ce22900f6d538e8872ae103c8bacbc119059ef1c3182207cbd7994b
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-08-17 08:09:50

Version Info:

Translation: 0x0000 0x04b0
FileDescription: banded
FileVersion: 5.3.8.12
InternalName: norville.exe
LegalCopyright:
OriginalFilename: norville.exe
ProductName: banded
ProductVersion: 5.3.8.12
Assembly Version: 5.3.8.12

Adware:MSIL/Dotdo.SR!MSR also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.e87cd612a259bfb5
SkyhighAdware-TskLnk
McAfeeAdware-TskLnk
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (D)
AlibabaAdWare:MSIL/Dotdo.bce20acf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.Dotdo.FN
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Agent.gen
NANO-AntivirusRiskware.Win32.Dotdo.fgtjdx
AvastWin32:Adware-gen [Adw]
TencentMsil.AdWare.Agent.Cwnw
F-SecureHeuristic.HEUR/AGEN.1312851
SophosGeneric Reputation PUA (PUA)
IkarusAdWare.MSIL.Dotdo
WebrootW32.Malware.Gen
GoogleDetected
AviraHEUR/AGEN.1312851
Antiy-AVLGrayWare[AdWare]/MSIL.Dotdo
Kingsoftmalware.kb.c.999
XcitiumApplication.MSIL.Dotdo.FD@7xsnmu
ZoneAlarmnot-a-virus:HEUR:AdWare.MSIL.Agent.gen
MicrosoftAdware:MSIL/Dotdo.SR!MSR
VaristW32/Dotdo.G.gen!Eldorado
MalwarebytesAdware.DotDo.Generic.TskLnk
PandaTrj/CI.A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Ursu.44BE!tr
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove Adware:MSIL/Dotdo.SR!MSR?

Adware:MSIL/Dotdo.SR!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment