Malware

Doina.40693 malicious file

Malware Removal

The Doina.40693 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.40693 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Korean

How to determine Doina.40693?


File Info:

name: BB17C073FC881149D1CF.mlw
path: /opt/CAPEv2/storage/binaries/3d14b0bf0cad8d2e3653e6ab8b88d8d17ac30d327b169813e312ae2ba47ef8e8
crc32: EC32CE6C
md5: bb17c073fc881149d1cf8fd7542ff574
sha1: 8e0095e1944b59f5589d56c900b312bfb9d2cc4c
sha256: 3d14b0bf0cad8d2e3653e6ab8b88d8d17ac30d327b169813e312ae2ba47ef8e8
sha512: 6ed2f145fd5db9c27c055173cdb2c224006c11fe78a12fb6f0f2917bf471aa97bdd36afdbfe9fbea6c62866fe4364d11a98c5afe776094851ef8635e46ebb6dc
ssdeep: 49152:jPYB6LqVU/uxYJ+xsx0ir2uak2kBLK6utfMe7UnAjuEupQqHwLUBXWIFJLB90Yb:jPU6mxY880irBak2kBG6uJDMlEupQqHB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3A57D217A489876C3130E32BD5DF3BCF1ADA52007E541EF5297AE187D2A583BA14D2F
sha3_384: 9441a7b5c58975170186481277a4f84d782f9e56cca45fad8a336c14930e174d1359a9b0f43672af862e17fae77707ed
ep_bytes: e838080000e97afeffff8b4df464890d
timestamp: 2022-07-21 08:32:14

Version Info:

0: [No Data]

Doina.40693 also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanGen:Variant.Doina.40693
FireEyeGen:Variant.Doina.40693
McAfeeArtemis!BB17C073FC88
CylanceUnsafe
VIPREGen:Variant.Doina.40693
SymantecML.Attribute.HighConfidence
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Doina.40693
AvastFileRepMalware
Ad-AwareGen:Variant.Doina.40693
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Doina.40693 (B)
GDataWin32.Trojan.PSE.1OAM93Y
ArcabitTrojan.Doina.D9EF5
MicrosoftTrojan:Win32/Wacatac.B!ml
BitDefenderThetaGen:NN.ZexaF.34806.!vY@aqFVmZpO
ALYacGen:Variant.Doina.40693
MAXmalware (ai score=84)
TrendMicro-HouseCallTROJ_GEN.R002H09GL22
RisingMalware.Generic!8.BA4C (CLOUD)
FortinetW32/PossibleThreat
AVGFileRepMalware
PandaTrj/Chgt.AD

How to remove Doina.40693?

Doina.40693 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment