Malware

What is “Doina.31834 (B)”?

Malware Removal

The Doina.31834 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.31834 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Doina.31834 (B)?


File Info:

name: D7A10E2D00C64A3FDE79.mlw
path: /opt/CAPEv2/storage/binaries/43c0c13b5649dd6c402d0d4a5d5bb6a1c40be25772dd6cea09b2ad20c7a837a4
crc32: 398A8623
md5: d7a10e2d00c64a3fde79e69ad3ac8d55
sha1: 7b2c4dfa63d6caa7fbee0ee5fdc93e7d581c4fa9
sha256: 43c0c13b5649dd6c402d0d4a5d5bb6a1c40be25772dd6cea09b2ad20c7a837a4
sha512: 3981df43b6709e5230c672d95ac583dc965b51753e7185d696cb15d1190d193c4746696c09d87b780951fee95e4341e455abf49e1b747b614ec277d25c72be52
ssdeep: 6144:a+otUjkHZMrI7S9ZV3PNJvvKBJZwB62zwHDor5QkA7mGPhoBKEZCOHofMZsoic:aD3yE78PNNGwB/4gZAaGpqKEZCOUMZx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T162B4016D6F1158A1D96EE83254D30F2DDF92652C0E88CEE570A8B4279E6F70C6C83B4D
sha3_384: f8373dc5c56c88efaf345e8a9d6c9a60720f26b9cbaba419a263120af3f3387b8646476db588f450e628644a2f7397ac
ep_bytes: eb023d9650eb05f2dd98bf55e8180000
timestamp: 2022-02-02 20:45:29

Version Info:

Translation: 0x0000 0x04b0

Doina.31834 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.31715
CynetMalicious (score: 100)
FireEyeGeneric.mg.d7a10e2d00c64a3f
McAfeeRDN/Generic.rp
CylanceUnsafe
SangforSpyware.Win32.Stealer.ky
K7AntiVirusTrojan ( 0058deff1 )
K7GWTrojan ( 0058deff1 )
BitDefenderThetaGen:NN.ZexaF.34212.EqX@aujw0cd
CyrenW32/Agent.EBR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Obsidium.GD
TrendMicro-HouseCallTROJ_GEN.R002C0PB622
Paloaltogeneric.ml
ClamAVWin.Packed.Midie-9938550-0
KasperskyTrojan-Spy.Win32.Stealer.bbpl
BitDefenderGen:Variant.Doina.31834
MicroWorld-eScanGen:Variant.Doina.31834
AvastWin32:Trojan-gen
TencentWin32.Trojan-spy.Stealer.Wstl
Ad-AwareGen:Variant.Doina.31834
TrendMicroTROJ_GEN.R002C0PB622
EmsisoftGen:Variant.Doina.31834 (B)
IkarusTrojan.Win32.Obsidium
GDataGen:Variant.Doina.31834
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.35220EF
GridinsoftMalware.Win32.GenericMC.cc
MicrosoftExploit:Win32/ShellCode!ml
AhnLab-V3Infostealer/Win.Taurus.C4949413
VBA32BScope.Trojan.Injuke
ALYacGen:Variant.Doina.31834
MalwarebytesTrojan.MalPack
APEXMalicious
RisingMalware.Undefined!8.C (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Doina.31834 (B)?

Doina.31834 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment