Malware

Doina.36529 removal instruction

Malware Removal

The Doina.36529 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.36529 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • CAPE detected the Alfonoso malware family
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system

How to determine Doina.36529?


File Info:

name: 184091B4BD9F02938F43.mlw
path: /opt/CAPEv2/storage/binaries/125c425b04053c5817557f7098dc8af428914c9f897c622f6958d80854e41cd8
crc32: 434C6742
md5: 184091b4bd9f02938f43e165acac2523
sha1: 4dc08e51ea6c3ce1ebb2e55e59e8cd4546510d38
sha256: 125c425b04053c5817557f7098dc8af428914c9f897c622f6958d80854e41cd8
sha512: 843af3679dd02479235e8524dc31e6d35f2f2634c19d1c2bdb34d606fa5c317a9f3bf7b51c07f747e86984ce20136bbdb572b357254b9bb3d99a0bcb76e51b84
ssdeep: 12288:QokfGiD8pdNn9KCT7tDlWCXJq7C7HbyyU9lbALDa/epZpiD:QoCDMNn9KCf1lWCXJWC7vU9lqPk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174C4BE0BE6429076E4632430229D8F6698BD7A3049236577B7C42D2D5EB01F2EB36F77
sha3_384: f9d52bb8cc84cb33d002c8dbdf13705437ab7e170c597511702b27ee1af59cda8757772195f2050aebea946a5166899f
ep_bytes: e884040000e974feffff558bec81ec24
timestamp: 2022-04-17 21:02:57

Version Info:

0: [No Data]

Doina.36529 also known as:

LionicTrojan.Win32.Shurk.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.36529
FireEyeGeneric.mg.184091b4bd9f0293
ALYacGen:Variant.Fragtor.29099
MalwarebytesGeneric.Trojan.Malicious.DDS
SangforTrojan.Win32.Shurk.gen
K7AntiVirusPassword-Stealer ( 005724dd1 )
AlibabaTrojanPSW:Win32/Phoenix.1025cb96
K7GWPassword-Stealer ( 005724dd1 )
BitDefenderThetaGen:NN.ZexaF.34606.IuW@a0WQw3hi
CyrenW32/Agent.DJJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Agent.OKX
APEXMalicious
ClamAVWin.Malware.Zusy-9812688-0
KasperskyHEUR:Trojan-PSW.Win32.Shurk.gen
BitDefenderGen:Variant.Doina.36529
TencentMalware.Win32.Gencirc.10d03d4d
Ad-AwareGen:Variant.Doina.36529
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0DDO22
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
EmsisoftGen:Variant.Fragtor.29099 (B)
AviraHEUR/AGEN.1213248
Antiy-AVLTrojan/Generic.ASMalwS.3566F95
KingsoftWin32.PSWTroj.Undef.(kcloud)
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Phoenix.C5094321
Acronissuspicious
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=86)
TrendMicro-HouseCallTROJ_GEN.R002C0DDO22
RisingStealer.Agent!8.C2 (CLOUD)
YandexTrojan.PWS.Agent!uLEZElhspcU
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.OKX!tr.pws
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Doina.36529?

Doina.36529 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment