Malware

Doina.1345 removal

Malware Removal

The Doina.1345 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.1345 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Likely virus infection of existing system binary
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Doina.1345?


File Info:

name: C1F0B1E9DE0458DA4E99.mlw
path: /opt/CAPEv2/storage/binaries/b4a6a2298258f6bd085c52ee779e6fbd1a7c99b74cf3c1833a18b4a9be958137
crc32: DCFD9D2D
md5: c1f0b1e9de0458da4e99615633ccdfc9
sha1: 94665a004069242c2764a7d392bfab6382dcb8d7
sha256: b4a6a2298258f6bd085c52ee779e6fbd1a7c99b74cf3c1833a18b4a9be958137
sha512: 1a6122704ae3ce86453a5861370042c0890f7bfbc9a157da6cc6da6fef5af773f9f13c98a1584c80017bff179872e286cf92e7d987e09e27183e9808df007971
ssdeep: 12288:rCyD7ezCllrldTRzZ1HFgVAxXxeq71d313j1tcij1R:rC6iCxdTv1HFgVAxXxeq71h1TLcSv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A15C003769284F6DA4B043004A7ABBBA739AD594B225B47B36CFF6E6F311C1543724B
sha3_384: c96ae4849ac66e9880cc0e68408a8f7b3b0731196adfb21500c9a29e8b2b96cc8cd78404c3db3f03ddee5060588d6aa8
ep_bytes: 558bec6aff68d0c14000685080400064
timestamp: 2011-03-26 05:35:14

Version Info:

0: [No Data]

Doina.1345 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.1345
FireEyeGeneric.mg.c1f0b1e9de0458da
McAfeeGenericRXAA-AA!C1F0B1E9DE04
CylanceUnsafe
K7AntiVirusSpyware ( 0055e3db1 )
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.9de045
CyrenW32/Agent.CHY.gen!Eldorado
ESET-NOD32a variant of Win32/Spy.Agent.OPC
APEXMalicious
ClamAVWin.Trojan.6601069-1
KasperskyTrojan-Spy.Win32.Agent.jxrh
BitDefenderGen:Variant.Doina.1345
NANO-AntivirusTrojan.Win32.TrjGen.boescz
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b28485
Ad-AwareGen:Variant.Doina.1345
DrWebTrojan.PWS.Bonque.44
ZillyaTrojan.Agent.Win32.233308
EmsisoftGen:Variant.Doina.1345 (B)
GDataGen:Variant.Doina.1345
JiangminTrojan.Generic.aroj
AviraHEUR/AGEN.1107121
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.710072
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34294.3qW@aSHHe1oO
ALYacGen:Variant.Doina.1345
VBA32Backdoor.MSIL.IRCBot
MalwarebytesMalware.AI.1668748915
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazp61QZJBc+UCw2/n3CRpE7v)
YandexTrojan.GenAsa!XR2/quIb0Jw
SentinelOneStatic AI – Suspicious PE
FortinetW32/Generic.AC.22793F
AVGWin32:Malware-gen

How to remove Doina.1345?

Doina.1345 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment