Malware

Doina.36614 malicious file

Malware Removal

The Doina.36614 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.36614 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Arabic (Saudi Arabia)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Doina.36614?


File Info:

name: 2AE0F580728C43B3A388.mlw
path: /opt/CAPEv2/storage/binaries/1f3b4ceea2e3054162260bb827a5c867d5615b15c68e065d97a99a892d5cad4e
crc32: 9B55A70A
md5: 2ae0f580728c43b3a3888dfbe76ad689
sha1: f64e59f71e7bab02819e83ed70cf0f7a2b3b0657
sha256: 1f3b4ceea2e3054162260bb827a5c867d5615b15c68e065d97a99a892d5cad4e
sha512: 67d452bc78ba3d064c2506e8f55a2e6692c5fccc98d323c8d9f7f141d7e7f04ad0eb782126926507b854678dcde4208ffa84ca705e0b45b28bfb562ca5b7a483
ssdeep: 6144:BaZFX6xDomWa1O3ozPCHdnzn0tKGXOVXFo:BI6xDwoW9nLvVXO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C746B113B91C836C29624774956C275AAA6BD319F2196C37BD12F3FFF302D2A938306
sha3_384: 943f19b631fc8519aa10484ed34695b26e0690e86a70cb9c142d3d23c81faf59749a2051f1e0dcaa2de58223fae829fb
ep_bytes: e83ee70000e978feffffcccccccccccc
timestamp: 2015-08-20 11:19:48

Version Info:

CompanyName: Audio Drive Inc
FileDescription: AudioDrive
FileVersion: 2.00
InternalName: AudioDrive
LegalCopyright: Audio Drive Inc ©2015
LegalTrademarks: Audio Drive Inc.
OriginalFilename: AudioDrive
ProductName: AudioDrive
ProductVersion: 2.00
Translation: 0x0809 0x04b0

Doina.36614 also known as:

BkavW32.Common.6961E900
LionicTrojan.Win32.Dynamer.4!c
DrWebTrojan.DownLoader15.55763
MicroWorld-eScanGen:Variant.Doina.36614
FireEyeGeneric.mg.2ae0f580728c43b3
SkyhighBehavesLike.Win32.NetLoader.fm
McAfeeGenericR-EMO!2AE0F580728C
Cylanceunsafe
ZillyaTrojan.Agent.Win32.576152
SangforTrojan.Win32.AridViper.IOC
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Dynamer.b77ad956
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Doina.D8F06
BitDefenderThetaGen:NN.ZexaF.36744.vq0@aGgd0FfO
VirITTrojan.Win32.DownLoader15.DEMT
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.XMG
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Doina.36614
NANO-AntivirusTrojan.Win32.Dwn.dxgych
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11943e88
EmsisoftGen:Variant.Doina.36614 (B)
F-SecureHeuristic.HEUR/AGEN.1320770
VIPREGen:Variant.Doina.36614
SophosMal/Generic-R
JiangminTrojan.Generic.sqj
AviraHEUR/AGEN.1320770
MAXmalware (ai score=100)
Antiy-AVLTrojan[APT]/Win32.Desertfalcon
XcitiumMalware@#2owwzdh5q9y5k
MicrosoftTrojan:Win32/Dynamer!ac
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Doina.36614
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C412392
ALYacGen:Variant.Doina.36614
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
RisingTrojan.Dynamer!8.3A0 (KTSE)
YandexTrojan.GenAsa!H/GnSe6bZ5A
IkarusTrojan-Spy.Win32.Agent
MaxSecureTrojan.Malware.8777150.susgen
FortinetW32/Agent.XMG!tr
AVGWin32:Malware-gen
Cybereasonmalicious.71e7ba
DeepInstinctMALICIOUS

How to remove Doina.36614?

Doina.36614 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment