Malware

Doina.42552 removal instruction

Malware Removal

The Doina.42552 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.42552 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk

How to determine Doina.42552?


File Info:

name: 330111EDCEEDE313CFCE.mlw
path: /opt/CAPEv2/storage/binaries/7443869c260b2dab355263df2d64b88bf15d7710ab5f0338d309ff982c9a24f0
crc32: FFFD617B
md5: 330111edceede313cfce07619cac6e0b
sha1: acaf8ab045cbb11b721314d1001cedfa9e3f78b4
sha256: 7443869c260b2dab355263df2d64b88bf15d7710ab5f0338d309ff982c9a24f0
sha512: 286e30caea0818051801430cf8a05a013f70a85ec6b9b4d867af25869dac13ab5a0952795ac99e8680e71992770c1be6aa06ec59eade2c21358c455f7039293d
ssdeep: 6144:4/zFuodQTX2s1zdSGGaLbqc2afAOY9Oxd9Q1s:4/QNH5bf7d9QC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C854080065814431E7720A3D09E9EFA47529BD330B5599EFF7A87A3D8E302D3663396E
sha3_384: 5d218b58b85fa71cd5b69243f0988d8c2216178aefaf88389b56ccb10197545b13f8e736cf5540df9d635b6d7a4841cf
ep_bytes: e8fa050000e988feffff3b0d74104300
timestamp: 2022-08-26 07:20:52

Version Info:

CompanyName: 360.cn
FileDescription: 360软件管家
FileVersion: 2, 6, 0, 2140
InternalName: SoftupNotify.exe
LegalCopyright: (C) 360.cn Inc. All Rights Reserved.
OriginalFilename: SoftupNotify.exe
ProductName: 360软件管家
ProductVersion: 2, 6, 0, 2140
Translation: 0x0804 0x04b0

Doina.42552 also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Jaik.93273
FireEyeGeneric.mg.330111edceede313
McAfeeArtemis!330111EDCEED
CylanceUnsafe
SangforTrojan.Win32.Agent.Vfkh
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderThetaGen:NN.ZexaE.34606.rC2@aebzpwpj
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agentb.kwgr
BitDefenderGen:Variant.Doina.42552
AvastFileRepMalware [Misc]
RisingTrojan.Agent!8.B1E (CLOUD)
Ad-AwareGen:Variant.Doina.42552
EmsisoftGen:Variant.Jaik.93273 (B)
VIPREGen:Variant.Jaik.93273
McAfee-GW-EditionArtemis!Trojan
Trapminesuspicious.low.ml.score
SophosGeneric PUA KM (PUA)
GDataGen:Variant.Doina.42552
AviraTR/Redcap.dwggv
ArcabitTrojan.Jaik.D16C59
ZoneAlarmTrojan.Win32.Agentb.kwgr
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
ALYacGen:Variant.Jaik.93273
MAXmalware (ai score=81)
TrendMicro-HouseCallTROJ_GEN.R002H09HT22
SentinelOneStatic AI – Suspicious PE
AVGFileRepMalware [Misc]

How to remove Doina.42552?

Doina.42552 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment