Malware

Doina.18132 removal tips

Malware Removal

The Doina.18132 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.18132 virus can do?

  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to modify browser security settings
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Doina.18132?


File Info:

crc32: 252E9C76
md5: bcda8a9a642c5ecc321f74d5fc9ab20d
name: BCDA8A9A642C5ECC321F74D5FC9AB20D.mlw
sha1: 2109e32d512a9924028eb31118a12526b8f6f645
sha256: 78d433f793ad22fdf44b05dd7c572362738a716fc99a80b3d03dbf2a71d7e792
sha512: e6482130188b92a7c967429deeaa671bd728743d5f9ee7f576f556b1b05ed19afa28a23402fd54670b8f5ca2800fa65d68d3104b7a7b16cf9d2b805fd4560beb
ssdeep: 24576:yvxk3VxrihQS/ye05lN9i0Onbk9IG9Pe92jAmV6Ij8s2xAgKR+77619c9UiQeQI:yvxk3Dihj/q5lDiNnbmIGlrjBVvj52xP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: 1.exe
FileVersion: 1.0.0.1
CompanyName: -
ProductName: -
ProductVersion: 1.0.0.1
FileDescription: -
OriginalFilename: 1.exe
Translation: 0x0412 0x04b0

Doina.18132 also known as:

LionicTrojan.Win32.Khalesi.4!c
McAfeeArtemis!BCDA8A9A642C
CylanceUnsafe
ZillyaTrojan.Khalesi.Win32.64
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/LockScreen.9efc5940
K7GWTrojan ( 00517c541 )
K7AntiVirusTrojan ( 00517c541 )
SymantecPUA.Ransom
ESET-NOD32a variant of Win32/LockScreen.BQP
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Khalesi.efl
BitDefenderGen:Variant.Doina.18132
NANO-AntivirusTrojan.Win32.Khalesi.ewaxfx
MicroWorld-eScanGen:Variant.Doina.18132
TencentMalware.Win32.Gencirc.1149566f
Ad-AwareGen:Variant.Doina.18132
SophosMal/Generic-R + Mal/Behav-118
ComodoMalware@#3b4gi3pgajtel
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXJJ-BS!3711E6B5E636
FireEyeGen:Variant.Doina.18132
EmsisoftTrojan.LockScreen (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Khalesi.afrk
AviraHEUR/AGEN.1100699
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.230E063
MicrosoftTrojan:Win32/Occamy.C78
GDataGen:Variant.Doina.18132
VBA32BScope.Trojan.Khalesi
MAXmalware (ai score=97)
PandaTrj/CI.A
RisingTrojan.LockScreen!1.B39F (CLASSIC)
IkarusTrojan.RansomKD
FortinetW32/LockScreen.BPL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Doina.18132?

Doina.18132 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment