Malware

Application.Doina.63200 malicious file

Malware Removal

The Application.Doina.63200 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Doina.63200 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Application.Doina.63200?


File Info:

name: 3005051589F528DC93DD.mlw
path: /opt/CAPEv2/storage/binaries/39264bd518b06ac5a269e7ebabdf6a6a2825e04c3636c2f824520ee777e739d4
crc32: 354BF294
md5: 3005051589f528dc93dd50afe0a8c47b
sha1: e6927904bcd355ec3cfa6d40d1dd57c9f90fe031
sha256: 39264bd518b06ac5a269e7ebabdf6a6a2825e04c3636c2f824520ee777e739d4
sha512: 1f3e91454eee314fdb3b969ab6e454f66acabe121da5fa09d052ad9eae9b110e88e865ab5ad43e23de8b86b2bebe54ae9e10d882c5f959ce18f3e9fa944bc496
ssdeep: 98304:TiZGmx/BVetF7m1GCbdGmdkVhIHVruP3WpF3UdE1hZHEdLFMZ2b:Xmx/wW/wlhgJuP32+dmhZk/MZ2b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13076B02E6BD60032CE5361756A5FA504E334D0036319CAE77ADCC3981FB1AE29676BF4
sha3_384: b04153d0a8bca17c32ee081920061f1339b1e1da64996285e062ffbc637ee7398a8ec4e2d2f9b1c4c4eed3ec3186e97e
ep_bytes: e8be0e0000e978feffffe9e186f1ffe9
timestamp: 2021-02-24 09:53:18

Version Info:

0: [No Data]

Application.Doina.63200 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Convagent.n!c
MicroWorld-eScanGen:Variant.Application.Doina.63200
FireEyeGeneric.mg.3005051589f528dc
SkyhighBehavesLike.Win32.Expiro.wc
ALYacGen:Variant.Application.Doina.63200
Cylanceunsafe
SangforTrojan.Win32.Patched.Vx28
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Convagent.9bd92059
K7GWTrojan ( 005ab4bf1 )
K7AntiVirusTrojan ( 005ab4bf1 )
ArcabitTrojan.Application.Doina.DF6E0
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.NKM
CynetMalicious (score: 100)
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Application.Doina.63200
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Patched-AWX [Trj]
TencentTrojan.Win32.Pathced_ya.16001052
EmsisoftGen:Variant.Application.Doina.63200 (B)
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.Beetle.2
VIPREGen:Variant.Application.Doina.63200
SophosMal/Generic-S
JiangminTrojan.Generic.hpxmn
VaristW32/Convagent.EC.gen!Eldorado
AviraTR/Patched.Gen
Antiy-AVLTrojan/Win32.Patched
KingsoftWin32.Hack.Convagent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmVirus.Win32.Senoval.a
GDataGen:Variant.Application.Doina.63200
GoogleDetected
AhnLab-V3Malware/Win.Generic.R603688
McAfeeArtemis!3005051589F5
MAXmalware (ai score=72)
VBA32BScope.TrojanDownloader.Emotet
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AC
TrendMicro-HouseCallTROJ_GEN.R002H09IP23
RisingBackdoor.Convagent!8.123DC (CLOUD)
IkarusTrojan.Win32.Patched
FortinetW32/Patched.IP!tr
BitDefenderThetaGen:NN.ZexaF.36608.@B0@a8ar65ni
AVGWin32:Patched-AWX [Trj]
DeepInstinctMALICIOUS

How to remove Application.Doina.63200?

Application.Doina.63200 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment