Adware

Win32/Adware.Dotdo.E removal

Malware Removal

The Win32/Adware.Dotdo.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.Dotdo.E virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Win32/Adware.Dotdo.E?


File Info:

name: 2124089535F26A73055E.mlw
path: /opt/CAPEv2/storage/binaries/c7af28199a284929e0f117f840761d05e277a02aa0208bdfa8fa1776c1d0f89e
crc32: 957577EA
md5: 2124089535f26a73055e0bee1150ecef
sha1: a7ba80c9b5ebcbbf96c9df89202772269eaafc94
sha256: c7af28199a284929e0f117f840761d05e277a02aa0208bdfa8fa1776c1d0f89e
sha512: 106e12678e52a44e3158ef3d6bbda4db47aec2b7e5225d0d4af78fe1f89b0b2a3abf505337e69a21cfac623148446a67aa301999cbfd284319967ef1d3b45219
ssdeep: 192:hUWZ+f3hN8qfL6AKBKkNQce0yQVw0o+8K:h1wffdKBKYde0NB8
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18802A7187BF08632DDFF0AB05CB2936057B1BA4BC536CB0E1CC5450A5DABB549CE1E6A
sha3_384: 1f75c4127f8c4d348009e6cb65e545d4fd8d3a07d7998410dea86c41ced7d5b41d97af99979198572d0a78dcacd86849
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-11-10 18:01:53

Version Info:

Translation: 0x0000 0x04b0
Comments: attract
CompanyName: freezing
FileDescription: attract
FileVersion: 6.4.1.20
InternalName: instruct.exe
LegalCopyright: Copyright © freezing 2015
LegalTrademarks: © 2015 freezing
OriginalFilename: instruct.exe
ProductName: attract
ProductVersion: 6.4.1.20
Assembly Version: 6.4.1.20

Win32/Adware.Dotdo.E also known as:

MicroWorld-eScanIL:Trojan.MSILZilla.11471
FireEyeIL:Trojan.MSILZilla.11471
CAT-QuickHealTrojan.Generic.TRFH1117
SkyhighGenericRXHD-QA!2124089535F2
McAfeeGenericRXHD-QA!2124089535F2
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.535f26
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Adware.Dotdo.E
BitDefenderIL:Trojan.MSILZilla.11471
NANO-AntivirusTrojan.Win32.Dotdo.ecvkcw
SophosGeneric ML PUA (PUA)
VIPREIL:Trojan.MSILZilla.11471
EmsisoftIL:Trojan.MSILZilla.11471 (B)
IkarusPUA.Dotdo
XcitiumApplication.MSIL.Dotdo.ABV@6edto7
ArcabitIL:Trojan.MSILZilla.D2CCF
GDataMSIL.Adware.DotDo.D
GoogleDetected
ALYacIL:Trojan.MSILZilla.11471
MAXmalware (ai score=80)
MalwarebytesAdware.DotDo.DotPrx
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Dotdo
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_90% (D)

How to remove Win32/Adware.Dotdo.E?

Win32/Adware.Dotdo.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment