Malware

How to remove “Doina.30555”?

Malware Removal

The Doina.30555 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.30555 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Doina.30555?


File Info:

name: 94FE44A83B8C59915E49.mlw
path: /opt/CAPEv2/storage/binaries/7ac1e655803214ed87847c06458fb95d683c21708b8fd94f7176950f0aa3da93
crc32: 6789659E
md5: 94fe44a83b8c59915e49ad6ef38545f1
sha1: b54e8b1c5b8ac9617d001ab244891d1aeab80f70
sha256: 7ac1e655803214ed87847c06458fb95d683c21708b8fd94f7176950f0aa3da93
sha512: 28c01c1995f84cf82549b4581de4d710c94192699c90c83c17b52f3d2552f9925df855d5a44ba95069f0543d71f77feb482d2015902fca0d6bc44c170e96f0c9
ssdeep: 12288:FYeXCcsXwfwxcZ1o2YknzB/sI/M1VC8oL0ce8N:FYeXHQk+eLBUIi88oL0P8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F9423A7C71741F2E86696B34EA1210FB1305D02A09D5D19E2084717E5F3E1DBBBE7A3
sha3_384: 85107c6c5bfc8ce4db27b14a9a43aa9bbf4579bdde0d62e75ab0142d7a90a5d125b1f8b920c51653e2cad5f73d78ee25
ep_bytes: 60e9a2de03008d049357e95af8ffff05
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Doina.30555 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.30555
FireEyeGeneric.mg.94fe44a83b8c5991
McAfeeGenericRXRK-EV!94FE44A83B8C
CylanceUnsafe
K7AntiVirusTrojan ( 0057e5351 )
K7GWTrojan ( 0057e5351 )
Cybereasonmalicious.83b8c5
BitDefenderThetaAI:Packer.A0EC6DAC1F
CyrenW32/VMProtect.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.WV
ClamAVWin.Malware.Doina-9936431-0
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Doina.30555
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10cffa9b
Ad-AwareGen:Variant.Doina.30555
EmsisoftGen:Variant.Doina.30555 (B)
ZillyaTrojan.VMProtect.Win32.57682
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosML/PE-A
IkarusTrojan.Win32.VMProtect
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.3501F21
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Doina.30555
AhnLab-V3Trojan/Win.Generic.C4899751
ALYacGen:Variant.Doina.30555
MAXmalware (ai score=87)
VBA32BScope.Trojan.Woreflint
MalwarebytesMalware.AI.4166255999
APEXMalicious
RisingTrojan.Convagent!8.12323 (RDMK:cmRtazpBovu9TRZPyjautlNvDH3L)
YandexTrojan.Agent!MrqO5+iOh1U
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_77%
FortinetW32/VMProtect.WV!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Doina.30555?

Doina.30555 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment