Malware

Doina.12533 removal guide

Malware Removal

The Doina.12533 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.12533 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Doina.12533?


File Info:

name: 61F2B1894B7A7BEE9A11.mlw
path: /opt/CAPEv2/storage/binaries/a0faf43a9d2d69455107e57984007d24b21b022eb7573b5afc6b2db946414a5b
crc32: 5EEECFCF
md5: 61f2b1894b7a7bee9a11805018c1a856
sha1: 52e37896aa384427f97fd205334c87fce128fa6a
sha256: a0faf43a9d2d69455107e57984007d24b21b022eb7573b5afc6b2db946414a5b
sha512: 572a875978fa0d4fcde9d866ac2abbba61bc1c4f2956082a771b04e67482917de5b530f2f1bc38361f81eea89421f9fab85c15b9dd23cc1f66854e15f415684d
ssdeep: 6144:Xef88ZsSEfRr+I023GthmI6+QIiECzZo8Dss:Of88ZsSeRr+I0PXd6+b0T5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BD54F226B0B31671EAC0DC3055B956629F7B2E3887CDC7E39B4805376AF00E3A57E261
sha3_384: 7e1e63a58224a8bf8ba09ab90aab852349734d436fed5362b625f5c523569ffbedf9047114d0f4003a728fbf250bf899
ep_bytes: 558bec6aff6808714000686043400064
timestamp: 2012-03-01 09:19:58

Version Info:

0: [No Data]

Doina.12533 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.12533
FireEyeGeneric.mg.61f2b1894b7a7bee
CAT-QuickHealBackdoor.Kanav.MUE.AP3
ALYacGen:Variant.Doina.12533
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_70% (D)
BaiduWin32.Trojan-Downloader.Agent.bl
VirITTrojan.Win32.Generic.CGPT
CyrenW32/Sadenav.D.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Alyak.E
APEXMalicious
ClamAVWin.Trojan.Agent-339112
KasperskyTrojan-Spy.Win32.Zbot.icyn
BitDefenderGen:Variant.Doina.12533
NANO-AntivirusTrojan.Win32.Clicker.wpsgp
AvastWin32:Zbot-QIJ [Trj]
TencentMalware.Win32.Gencirc.10b71670
Ad-AwareGen:Variant.Doina.12533
EmsisoftGen:Variant.Doina.12533 (B)
ComodoTrojWare.Win32.TrojanDownloader.Small.REK@4n2or7
F-SecureTrojan.TR/Spy.Zbot.icyna
DrWebTrojan.Click2.16782
ZillyaTrojan.Jorik.Win32.60949
TrendMicroBKDR_KANAV.AC
McAfee-GW-EditionGeneric BackDoor.xt
SophosMal/EncPk-AJG
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Doina.12533
JiangminTrojan/Generic.xchx
AviraTR/Spy.Zbot.icyna
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.BCEED
ViRobotDropper.Agent.45056.V
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.OnlineGameHack.R21565
Acronissuspicious
McAfeeGeneric BackDoor.xt
VBA32BScope.Trojan.Win32.Inject.2
TrendMicro-HouseCallBKDR_KANAV.AC
RisingTrojan.Generic@AI.100 (RDMK:cmRtazpQYwmetcmthiVt78GLmLx3)
YandexTrojan.GenAsa!tjLTCZR7jYs
IkarusTrojan.Win32.Alyak
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Dloader.RAK!tr
BitDefenderThetaGen:NN.ZexaF.34606.rmZ@aW2Ysud
AVGWin32:Zbot-QIJ [Trj]
Cybereasonmalicious.94b7a7
PandaGeneric Malware

How to remove Doina.12533?

Doina.12533 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment