Malware

Doina.24679 (B) removal

Malware Removal

The Doina.24679 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.24679 (B) virus can do?

  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Doina.24679 (B)?


File Info:

name: 47F7BEB5529EECBF8D59.mlw
path: /opt/CAPEv2/storage/binaries/8dc807d37104b0121e176f610f261c5680f8b2270bd014a87bdecb6e9844f974
crc32: F3B876B3
md5: 47f7beb5529eecbf8d59a2cd6c6d1aae
sha1: 6901998ffb29a0bb79e07e39b3b2b1d7f4c38f86
sha256: 8dc807d37104b0121e176f610f261c5680f8b2270bd014a87bdecb6e9844f974
sha512: 54c13bad395efcd2a2c17678239219b7d3552d6913fade076f47a0db091def1b409010401d6eada0b25d910103b4cdb63bd6695d66ee3fe2b87f7ce457f30c43
ssdeep: 98304:let+j0gq/JETDEmpjL2JwZfQSYkegZhVvQ/qpyr0k3kI+yl8OkkLBxI+iZ7q1zPE:cI3VgTd+yl8OkkLHI+7NAjtVa/u
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18446D072BF8D44B1D45302314AAB6639957EBD30673582C313943B2E7A713D16B3EAE2
sha3_384: 9805e465da85003765e87c5c18649745c4286f625188f20b74fd029a8b39c1ded6894f138b35dc5d0818eed5437dccd6
ep_bytes: e833ee0000e97ffeffff538bdc515183
timestamp: 2021-12-02 02:19:50

Version Info:

CompanyName: TODO:
FileDescription: FbRobot
FileVersion: 1.0.0.1
InternalName: FbRobot.exe
LegalCopyright: TODO: (C) 。 保留所有权利。
OriginalFilename: FbRobot.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0804 0x04b0

Doina.24679 (B) also known as:

LionicTrojan.Win32.Stealer.i!c
MicroWorld-eScanGen:Variant.Doina.24679
FireEyeGen:Variant.Doina.24679
McAfeeGenericRXQY-RQ!47F7BEB5529E
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 0055912f1 )
AlibabaTrojanPSW:Win32/Stealer.4e7613c0
K7GWPassword-Stealer ( 0055912f1 )
BitDefenderThetaGen:NN.ZexaF.34062.@p0@ayyDRceb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Agent.OHG
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Stealer.xkc
BitDefenderGen:Variant.Doina.24679
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Doina.24679
EmsisoftGen:Variant.Doina.24679 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Doina.24679
AviraTR/PSW.Agent.cjsnq
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Doina.5489152
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.OW.R456221
VBA32Trojan.Sabsik.FL
ALYacGen:Variant.Doina.24679
MAXmalware (ai score=85)
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002H0CL721
IkarusTrojan-PSW.Agent
FortinetW32/Agent.OLG!tr.pws
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Doina.24679 (B)?

Doina.24679 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment