Malware

Doina.17475 removal

Malware Removal

The Doina.17475 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.17475 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk

How to determine Doina.17475?


File Info:

name: 1BA52FD459AE5AF40304.mlw
path: /opt/CAPEv2/storage/binaries/aea2a3c9adef73dbc086c82fb64a8b991d5168e5643c0aaf2f669ee1377f6e1c
crc32: 9BC395E9
md5: 1ba52fd459ae5af4030432d0a32402ef
sha1: 9d561702374873704afb4b2b905b1b0d785ac084
sha256: aea2a3c9adef73dbc086c82fb64a8b991d5168e5643c0aaf2f669ee1377f6e1c
sha512: f383e4e6e952f00c0236ee3c51a3a531b04426e9e8349a502f7453758be84dce4f9736a357d52f409bdcbf14cd0f67ab28b013b7d10d865c52c4a4771021586e
ssdeep: 12288:7UaYoU4WCQ36vziYXlah7l9pPdImBB7nSUNUnSb:coU4WCZGXb7BB7nBHb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155C47C213AD0E072D16231F14A5AD3747AF9A4305E36960B6BD40B7C6F349D29A2E37F
sha3_384: 8072e2fcca6b2f03d7694d7ab68c333d196a271ee7ec15f4c2eda9369cc22175623c48721cfb7c34e9a9c60580dc0824
ep_bytes: e83cc20000e978feffff6a0c68d0a847
timestamp: 2022-02-22 20:51:39

Version Info:

Comments: GalGa Operation.
CompanyName: GalGa Company.
FileDescription: GalGa System
FileVersion: 1.0.0.1
InternalName: GalGa..exe
LegalCopyright: GalGa Company.. All rights reserved 2017.
OriginalFilename: GalGa.exe.
ProductName: GalGa System.
ProductVersion: 1.0.0.1
Translation: 0x0412 0x03b5

Doina.17475 also known as:

LionicTrojan.Multi.Generic.4!c
DrWebTrojan.MulDrop20.3421
MicroWorld-eScanGen:Variant.Doina.17475
FireEyeGen:Variant.Doina.17475
ALYacGen:Variant.Doina.17475
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Generic.f69fdc34
K7GWTrojan-Downloader ( 0058ec951 )
K7AntiVirusTrojan-Downloader ( 0058ec951 )
CyrenW32/Trojan.QRUC-7894
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FXV
TrendMicro-HouseCallTROJ_GEN.R03FH0CBQ22
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Doina.17475
AvastWin32:Trojan-gen
TencentWin32.Trojan-downloader.Agent.Eaxp
Ad-AwareGen:Variant.Doina.17475
EmsisoftGen:Variant.Doina.17475 (B)
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataGen:Variant.Doina.17475
AviraTR/Dldr.Agent.bzine
MAXmalware (ai score=86)
ArcabitTrojan.Doina.D4443
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Generic.C4534483
McAfeeArtemis!1BA52FD459AE
VBA32Trojan.Sabsik.TE
MalwarebytesTrojan.Downloader
RisingDownloader.Agent!8.B23 (CLOUD)
IkarusTrojan-Downloader.Win32.Agent
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Agent.FXV!tr.dldr
AVGWin32:Trojan-gen

How to remove Doina.17475?

Doina.17475 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment