Adware

MSIL/Adware.Dotdo.HY removal guide

Malware Removal

The MSIL/Adware.Dotdo.HY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Adware.Dotdo.HY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Adware.Dotdo.HY?


File Info:

crc32: E193E471
md5: 45f13d1b4192bca939b3e4f0c2c9ebea
name: 45F13D1B4192BCA939B3E4F0C2C9EBEA.mlw
sha1: 523c1a82a1a46104037b383e521d39b493445a13
sha256: 24bd2f0dc91342536b0ff989ade33c64b1757043b280fd40e4940b34e0905bfe
sha512: 17f6257dc80b511a495f245898683dc1b4d286349012f2c211cf120b89e1b2378887c502bff84805d92642aba9075b1ab105209fe416c68aacf29eb77f3aeeaa
ssdeep: 384:TckHr6SXQHuLIdP9Qqcpwc7WrNvfy5/0:Yksdlvc76Bvfyt0
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 8.5.9.30
InternalName: Fuse.exe
FileVersion: 8.5.9.30
ProductName: Fuse
ProductVersion: 8.5.9.30
FileDescription: Fuse
OriginalFilename: Fuse.exe

MSIL/Adware.Dotdo.HY also known as:

LionicTrojan.Win32.DotDo.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaAdware.Dotdo.Win32.24732
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Kubik.d1fc73a2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.Dotdo.HY
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
KasperskyHEUR:Trojan.MSIL.Kubik.gen
NANO-AntivirusTrojan.Win32.Kubik.ixbhki
TencentMsil.Adware.Dotdo.Pfjl
SophosGeneric PUA FC (PUA)
ComodoApplication.MSIL.Dotdo.ER@8egbxo
F-SecureHeuristic.HEUR/AGEN.1119346
McAfee-GW-EditionTskLnk
FireEyeGeneric.mg.45f13d1b4192bca9
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1119346
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3PUP/Win32.DotDo.R242066
McAfeeTskLnk
MalwarebytesAdware.DotDo.Generic.TskLnk
PandaTrj/GdSda.A
IkarusAdWare.MSIL.Dotdo
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Dotdo
AVGWin32:AdwareX-gen [Adw]

How to remove MSIL/Adware.Dotdo.HY?

MSIL/Adware.Dotdo.HY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment