Malware

About “Doina.18312” infection

Malware Removal

The Doina.18312 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.18312 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com

How to determine Doina.18312?


File Info:

crc32: CBBDC22C
md5: 2f3b725bb97e661c967d68b318f4170e
name: 2F3B725BB97E661C967D68B318F4170E.mlw
sha1: 74a3969c88c308c80f4cc3492768ccfdd578afe0
sha256: 31845778b7b5cab14889a8cc0f2d8ea8df5e7a214b4570d17231a2b9458b9d02
sha512: 14a9ca31a3aa0cafc287d95feefb6f6dd960cda373cbddb55c1d5fabfbd360980aef2b594a8fece3128ee24d311cbd9c2cd094a4d4db0b6ee6373d581abcc11c
ssdeep: 768:kYTCcUjPTJylUmWJLzLXTGGRq1xqpIPaXqYnhaiEnGSeDHS45Aizn2IEDeqwLdU:a3xy8PLXiGcFPa6+unxexHgw6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Doina.18312 also known as:

K7AntiVirusTrojan ( 00537f5b1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Doina.18312
ZillyaTrojan.ClipBanker.Win32.732
BitDefenderGen:Variant.Doina.18312
K7GWTrojan ( 00537f5b1 )
Cybereasonmalicious.bb97e6
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/ClipBanker.GU
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/ClipBanker.ac2e9298
NANO-AntivirusTrojan.Win32.ClipBanker.ffldfi
MicroWorld-eScanGen:Variant.Doina.18312
TencentMalware.Win32.Gencirc.114cf8a2
Ad-AwareGen:Variant.Doina.18312
SophosMal/Generic-S
ComodoMalware@#34jhvan84wbdn
BitDefenderThetaAI:Packer.8A3B6DC21F
McAfee-GW-EditionGenericRXGG-BB!2F3B725BB97E
FireEyeGeneric.mg.2f3b725bb97e661c
EmsisoftGen:Variant.Doina.18312 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Agent.gfvt
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1121625
GDataGen:Variant.Doina.18312
AhnLab-V3Trojan/Win32.Korat.C2619113
VBA32BScope.TrojanDropper.Agent
MAXmalware (ai score=90)
RisingTrojan.Generic@ML.100 (RDML:RSPs4F8SIGSOO+Adwh/6zw)
IkarusTrojan.Win32.Clipbanker
FortinetW32/Generic.AC.416E1F
PandaTrj/GdSda.A

How to remove Doina.18312?

Doina.18312 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment