Malware

Doina.24715 (B) removal tips

Malware Removal

The Doina.24715 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.24715 (B) virus can do?

  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Doina.24715 (B)?


File Info:

name: 7FEEE7AB13B1DD0E5997.mlw
path: /opt/CAPEv2/storage/binaries/8b2d7924fb1cc0227cc77f137c97172a11302e90a140e48dc569e660337c5ff9
crc32: 67392A89
md5: 7feee7ab13b1dd0e5997dcf951c31352
sha1: bb3e1335adf96ee5be970c988d1cd7e176935b64
sha256: 8b2d7924fb1cc0227cc77f137c97172a11302e90a140e48dc569e660337c5ff9
sha512: 79a8238909a28ba774f5c20d557e272c461475297af1583f975d650c62a1affaf7ab662f229850cab3e17b827deadb0f437457cb0e8bde09d5cf1d4e0ccf7a6a
ssdeep: 384:eDAUAnRTMglj1a1o15R1Ep2i6rvZ1GEC3t0bEYO2QCRs55c7h0GftpBjyTs:eDApRTMnYR151vZQXOwYb7SJiATs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16BE36B134DAC5063C0B7CA34A2BAAF52B77ED6D20F3155132678ECFC0933796A59221E
sha3_384: 146d6796578fa1949a25068da91af323fc119f1f878a0e91bab61ae60ae5360360c928eaa54e0acddb4deed0dbc5aee2
ep_bytes: 558bec6aff685018400068b62e400064
timestamp: 2008-06-29 17:41:40

Version Info:

Comments:
CompanyName:
FileDescription: Microsoft
FileVersion: 1, 0, 0, 1
InternalName: XiaoHao
LegalCopyright: 版权所有 (C) 2008
LegalTrademarks:
OriginalFilename: XiaoHao.EXE
PrivateBuild:
ProductName: XiaoHao 应用程序
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Doina.24715 (B) also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.24715
FireEyeGeneric.mg.7feee7ab13b1dd0e
ALYacGen:Variant.Doina.24715
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/FileInfector.7b9e573a
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b13b1d
BitDefenderThetaAI:Packer.0C37C1DD1F
CyrenW32/Blocker-based!Maximus
SymantecTrojan.Maliframe!html
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Cosne-9884193-0
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Doina.24715
NANO-AntivirusTrojan.Win32.Cosne.bcvcf
AvastWin32:RootkitX-gen [Rtk]
TencentMalware.Win32.Gencirc.114cda43
Ad-AwareGen:Variant.Doina.24715
EmsisoftGen:Variant.Doina.24715 (B)
DrWebTrojan.Siggen3.19586
TrendMicroTROJ_GEN.R002C0OL521
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Doina.24715
JiangminTrojan/Cosne.m
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.942C7A
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.A.Cosne.139268
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.AutoRun.R145645
McAfeeGenericRXAA-AA!7FEEE7AB13B1
MAXmalware (ai score=87)
VBA32Trojan.Tiggre
MalwarebytesMalware.AI.1312217866
TrendMicro-HouseCallTROJ_GEN.R002C0OL521
YandexTrojan.Agent!GEe9qLFxQnQ
IkarusGen.Win32.FileInfector
FortinetW32/PossibleThreat
WebrootW32.Malware.Gen
AVGWin32:RootkitX-gen [Rtk]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Doina.24715 (B)?

Doina.24715 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment