Malware

Doina.2497 information

Malware Removal

The Doina.2497 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.2497 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Doina.2497?


File Info:

name: E30A54075ECC9AB1F6D5.mlw
path: /opt/CAPEv2/storage/binaries/1d09971ee436d6d2c9fe4573d0200f383861488e91e4cf0965b9b15b7fcf1c86
crc32: 8B4C7E59
md5: e30a54075ecc9ab1f6d50c8b793e13d2
sha1: 4b0a21677efca198e8947bc783d6843272b15e2b
sha256: 1d09971ee436d6d2c9fe4573d0200f383861488e91e4cf0965b9b15b7fcf1c86
sha512: f8d73e968447657695a2d2963ce0117b159d511ae183f9a80e73b2f8cc3af038e9f2c1ebabc330091e8580ad2743fa1f7b82558445c17e33fd3fc0df64690c6b
ssdeep: 192:iuu/5cPwn07j4fZtphPQ/24zcojEtu/5cPwn07j4fZhh5aADsJFACtyH:ijcPw0q4u4Yo4mcPw0Yh5HDmOuI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T176B3298197492512C33D79324EF64D32E936F22912E98DEA77C8C783EBDED80D065350
sha3_384: 442baf73039196fe177c1ccfba86f2b2b41e3f9456232602d88bddd7f7159e66bf76eec5bae82b6157f1097751d0e340
ep_bytes: 558d6c248881ecdc08000053565733db
timestamp: 2014-01-22 23:25:31

Version Info:

0: [No Data]

Doina.2497 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Doina.2497
FireEyeGeneric.mg.e30a54075ecc9ab1
CAT-QuickHealDownloader.Upatre.27298
McAfeeGeneric-FANY!E30A54075ECC
Cylanceunsafe
ZillyaDownloader.Waski.Win32.90765
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecDownloader.Upatre!g20
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.B
APEXMalicious
TrendMicro-HouseCallTROJ_UPATRE.SM37
ClamAVWin.Malware.Upatre-6997924-0
KasperskyHEUR:Trojan.Win32.Bublik.pef
BitDefenderGen:Variant.Doina.2497
AvastWin32:Upatre-V [Trj]
TencentTrojan-DL.Win32.Agent.16000354
EmsisoftGen:Variant.Doina.2497 (B)
GoogleDetected
F-SecureTrojan.TR/Downloader.Gen
DrWebTrojan.DownLoad4.15303
VIPREGen:Variant.Doina.2497
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
SophosTroj/Upatre-XO
IkarusTrojan.Crypt
JiangminTrojan.Generic.eaeiw
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Zbot!pz
XcitiumTrojWare.Win32.TrojanDownloader.Waski.BU@7nmtnf
ArcabitTrojan.Doina.D9C1
ZoneAlarmHEUR:Trojan.Win32.Bublik.pef
GDataGen:Variant.Doina.2497
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win.UPX.C5033404
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Doina.2497
MAXmalware (ai score=80)
MalwarebytesTrojan.Downloader.UPX
PandaTrj/GdSda.A
RisingSpyware.Zbot!8.16B (TFE:3:zHMEcYKLCaB)
YandexTrojan.GenAsa!uGSW6+/pwxg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/EncPk.ACO!tr
BitDefenderThetaGen:NN.ZexaF.36802.hmX@ayFPp7ai
AVGWin32:Upatre-V [Trj]
Cybereasonmalicious.75ecc9
DeepInstinctMALICIOUS

How to remove Doina.2497?

Doina.2497 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment