Adware

Should I remove “MSIL/Adware.Dotdo.GJ”?

Malware Removal

The MSIL/Adware.Dotdo.GJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Adware.Dotdo.GJ virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Adware.Dotdo.GJ?


File Info:

name: 780E095ADA049FE1D542.mlw
path: /opt/CAPEv2/storage/binaries/43b5dbb78e832c527a3a92e7f4eda1b28575c23b36bf86391a10f1b09c0190e7
crc32: D85CD525
md5: 780e095ada049fe1d54291fd3748b665
sha1: f2b63d7d1b4810ce359b890ba0e74499b89cc327
sha256: 43b5dbb78e832c527a3a92e7f4eda1b28575c23b36bf86391a10f1b09c0190e7
sha512: 1966e600c46a3880cde4ff16b9031b11160a1f079575f313a5e01d7ef02931acb5ca27e791fa23efb5b250d86d92788477dbbe7b3b58e4cedafeb34f699f0e25
ssdeep: 48:6ieMSqMJ0X9vrh1oqXg/TW3JGyzua9zTHrj+tWakFcLcHSvpd4r3F:8+id/TWtua9zTHrjxwgSvpST
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12CB1A41687E42337E8728B76FD7313A4A278EB22EBB7470E084445076C166345D3AF66
sha3_384: c0f18f519e34ed968cb44adfecabe80e27e02941e61276442de292b6f9e5ba03cf7aa7fee9f610f7d3f13a7bc5551e62
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-05-07 09:18:48

Version Info:

Translation: 0x0000 0x04b0
FileDescription: mismanaged
FileVersion: 2.6.5.90
InternalName: antic.exe
LegalCopyright:
OriginalFilename: antic.exe
ProductVersion: 2.6.5.90
Assembly Version: 2.6.5.90

MSIL/Adware.Dotdo.GJ also known as:

LionicAdware.MSIL.Agent.2!c
FireEyeGeneric.mg.780e095ada049fe1
McAfeeArtemis!780E095ADA04
MalwarebytesMachineLearning/Anomalous.93%
SangforAdware.Msil.Dotdo.V6tt
CyrenW32/Razy.CZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Adware.Dotdo.GJ
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Agent.gen
AvastWin32:AdwareX-gen [Adw]
TencentMalware.Win32.Gencirc.1159550d
F-SecureHeuristic.HEUR/AGEN.1308571
ZillyaAdware.Dotdo.Win32.78589
McAfee-GW-EditionBehavesLike.Win32.AdwareTskLnk.zt
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1308571
Antiy-AVLTrojan/Win32.Occamy
Kingsoftmalware.kb.c.1000
XcitiumApplication.MSIL.Dotdo.GJ@89zuv7
ViRobotAdware.Dotdo.5123
ZoneAlarmnot-a-virus:HEUR:AdWare.MSIL.Agent.gen
MicrosoftPUA:Win32/Presenoker
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DotDo.C3264788
VBA32Adware.MSIL.Agent
Cylanceunsafe
PandaTrj/CI.A
RisingTrojan.Fuerboos!8.EFC8 (CLOUD)
YandexPUA.Dotdo!Zjk9l7KOjsk
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Dotdo
AVGWin32:AdwareX-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove MSIL/Adware.Dotdo.GJ?

MSIL/Adware.Dotdo.GJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment