Malware

Doina.13846 (B) information

Malware Removal

The Doina.13846 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.13846 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Doina.13846 (B)?


File Info:

crc32: 30AE24CF
md5: 065fe1831a5593ce403c97608cab355e
name: 065FE1831A5593CE403C97608CAB355E.mlw
sha1: cdcac276cd6509963fee6573bb8c1a5936bda4b6
sha256: 2ee388b7f6e83189ff697e1cce26564dfa65f7e0b3c2b75fd2950c4fb8870a41
sha512: 95ed946d37ed3e50e14d13e01b1590209efa978b9871b42dbcfa2949e76f844e280e4ee817d38d704ac3fa752265986864e171b8dfd7b8818787dbedcc718831
ssdeep: 6144:SQ85D45Pn0UoQUzmTHg9nPxkuxuYRcWddsXurfrxlu:SQGD4lvoHgHE9uYpddsX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2005
InternalName: TimeTip
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: TimeTip Application
ProductVersion: 1, 0, 0, 1
FileDescription: TimeTip MFC Application
OriginalFilename: TimeTip.EXE
Translation: 0x0409 0x04b0

Doina.13846 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop17.14600
CynetMalicious (score: 100)
ALYacGen:Variant.Doina.13846
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:Win32/Zegost.accc1fbf
K7GWTrojan ( 0057cdbb1 )
Cybereasonmalicious.31a559
CyrenW32/Trojan.ZYZK-7889
SymantecBackdoor.Zegost
ESET-NOD32Win32/Farfli.CWO
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Doina.13846
NANO-AntivirusTrojan.Win32.Inject.chipuz
MicroWorld-eScanGen:Variant.Doina.13846
TencentWin32.Trojan.Generic.Eex
Ad-AwareGen:Variant.Doina.13846
SophosMal/PePatch-K
BitDefenderThetaGen:NN.ZexaF.34690.ty0@a4uDf4oj
VIPRETrojan.Win32.Rimecud.d (v)
TrendMicroTROJ_GEN.R005C0DEI21
McAfee-GW-EditionBehavesLike.Win32.Chir.fh
FireEyeGeneric.mg.065fe1831a5593ce
EmsisoftGen:Variant.Doina.13846 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
MicrosoftBackdoor:Win32/Zegost.CQ!bit
GridinsoftTrojan.Heur!.03006021
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Doina.13846
AhnLab-V3Backdoor/Win32.Zegost.R351139
McAfeePacked-MZ!065FE1831A55
MAXmalware (ai score=89)
VBA32Backdoor.Lotok
MalwarebytesMalware.AI.317239866
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005C0DEI21
RisingBackdoor.Zegost!8.177 (CLOUD)
IkarusTrojan.Win32.Spy
FortinetW32/SERVSTART.D!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Doina.13846 (B)?

Doina.13846 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment