Malware

Doina.18602 information

Malware Removal

The Doina.18602 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.18602 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Doina.18602?


File Info:

name: 123DA278C7E62AF7E56E.mlw
path: /opt/CAPEv2/storage/binaries/d9947020fe30cdbf74737479fc3bbe704560b2a8aa764f38aeacaa18d70533d7
crc32: EE0B2B50
md5: 123da278c7e62af7e56e1c598bb9bb68
sha1: 0e865011ac4793200354b462e82e4339ad6b272f
sha256: d9947020fe30cdbf74737479fc3bbe704560b2a8aa764f38aeacaa18d70533d7
sha512: 2a694d178cc5b3aabfcfc653041bd0932aa886a01e4919c8aaec48ff3fb12e6d3cdb2b99b663baf856f2696049ec2e20aa6ef18c92a6d0f84c62cb18f8d2cd9b
ssdeep: 49152:hpG4TGRmjEYeZDe0J9hDPEpNG9Ns6zgiH9mRGengcjHo1zWzLUIUQZSODteN8E39:PGLkjgDxXDPEz/liHq3gzsPUIUIS8OD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2E5220A3491BCB2E3D4317C18D64F36676DAD7C1E2CBA8393C3FB193A760A158A6475
sha3_384: 0190b7032a9c0121c7459d0723873734f3c344c51a4f253c9cfd9a9482c0cf1187498d0a6f6747076f2765870aab8960
ep_bytes: 558bec6aff68b0da42006898a5410064
timestamp: 2016-11-09 01:29:32

Version Info:

0: [No Data]

Doina.18602 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Doina.4!c
MicroWorld-eScanGen:Variant.Doina.18602
FireEyeGen:Variant.Doina.18602
McAfeeArtemis!123DA278C7E6
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaRootkit:Win32/Generic.4029de0c
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.8c7e62
SymantecTrojan.Gen.MBT
APEXMalicious
BitDefenderGen:Variant.Doina.18602
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Doina.18602
EmsisoftGen:Variant.Doina.18602 (B)
DrWebTrojan.MulDrop17.51589
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
SophosMal/Generic-R
GDataGen:Variant.Doina.18602
Antiy-AVLTrojan/Generic.ASMalwS.330A8FB
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacGen:Variant.Doina.18602
MAXmalware (ai score=82)
VBA32Trojan.MulDrop
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTROJ_GEN.R002H0CKJ21
eGambitUnsafe.AI_Score_70%
FortinetW32/Rootkit.A
AVGWin32:Malware-gen

How to remove Doina.18602?

Doina.18602 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment