Published May 12, 2014 | Updated Mar 08, 2018

MSIL/Dofoil

Severe |Detected with Windows Defender Antivirus

Aliases: No associated aliases

Summary

Windows Defender Antivirus detects and removes this threat.

See the family description for more information.Win32/Dofoil

On March 6, 2018, behavior monitoring and machine learning technologies in Windows Defender Antivirus stopped a Dofoil variant (also known as Smoke Loader) that tried to infect more than 400,000 computers. The massive campaign aimed to install a cryptocurrency miner that uses victim computers' resources for coin mining purposes. Learn how artificial intelligence stopped the attack within minutes:

Behavior monitoring combined with machine learning spoils a massive Dofoil coin mining campaign

Windows Defender Antivirus Updating your antimalware definitions automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. and running a full scan might help address these remnant artifacts.

You can also visit our or search the for more help.advanced troubleshooting pageMicrosoft virus and malware community

To ensure you have the best protection, enable the following:

To access these settings on the Windows Defender Security Center app, use the Windows search box to find and open the . Navigate to .Windows Defender Security CenterVirus & threat protection settings

To prevent future infection, follow our guide on .preventing malware infection

Secure configuration
Prevent malware infection
  • Cloud-delivered protection
  • Automatic sample submission
Follow us