Malware

Doina.43012 malicious file

Malware Removal

The Doina.43012 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.43012 virus can do?

  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Doina.43012?


File Info:

name: E992BACD6B9126ECD088.mlw
path: /opt/CAPEv2/storage/binaries/0cd9e66580edba2daef92f61b2e58c2f79df2af12455f044316d8a06a9712af7
crc32: 4DA7708A
md5: e992bacd6b9126ecd08832746d679440
sha1: 17f5870269cb6ef5b60a55d570e90bb2777e05b4
sha256: 0cd9e66580edba2daef92f61b2e58c2f79df2af12455f044316d8a06a9712af7
sha512: e246acd3d7def4171c4e9ebbfdade29e72c9d3a0a031a39305b37b82e5cc1a846fe1d606f01917aca2f7d5c473220832c4831051b94133c83e61bdab5c5e67e9
ssdeep: 1536:3D+/hMOiO1qne11VfHiToYx0r2i6VpW/ZIa1Lms9d+0F9dz:T+Eeqe1vqToYir2vTWdas3DR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DEA35D10F641C0A9E4D241FA86DECBBAD5696F30434920D3B3E4E997E73A1E1AF31947
sha3_384: 54cb8d6bf192e3c20b87e0727d469a110cebaf757ff1b7a120321aa9f5a6d6f3090eeff940a7369f7ad3c066412eee65
ep_bytes: 558bec6aff6810ea400068e86c400064
timestamp: 2012-11-09 12:33:19

Version Info:

0: [No Data]

Doina.43012 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lEaD
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.43012
ClamAVWin.Trojan.Barys-9754805-0
FireEyeGeneric.mg.e992bacd6b9126ec
ALYacGen:Variant.Doina.43012
MalwarebytesAlyak.Backdoor.RAT.DDS
VIPREGen:Variant.Doina.43012
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f87a1 )
AlibabaTrojanDownloader:Win32/Vobfus.8f9148bd
K7GWTrojan-Downloader ( 00321db61 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan-Downloader.Agent.bl
VirITTrojan.Win32.Spy.XTB
CyrenW32/A-f8397cd9!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Alyak.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.auyq
BitDefenderGen:Variant.Doina.43012
NANO-AntivirusTrojan.Win32.Graftor.bclgey
AvastWin32:Downloader-LMY [Trj]
TencentTrojan.Win32.Agent.afo
TACHYONTrojan/W32.Vobfus.102569
EmsisoftGen:Variant.Doina.43012 (B)
F-SecureTrojan.TR/Graftor.66987458
DrWebTrojan.PWS.Spy.16043
ZillyaDownloader.Agent.Win32.157692
TrendMicroTROJ_AGENT_056749.TOMB
McAfee-GW-EditionBehavesLike.Win32.Infected.cm
Trapminemalicious.high.ml.score
SophosMal/Generic-R
IkarusTrojan-PSW.OnlineGames
GDataWin32.Trojan.PSE.1IE1F5X
JiangminTrojan/Generic.aoxqe
AviraTR/Graftor.66987458
Antiy-AVLTrojan/Win32.Unknown
XcitiumTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
ArcabitTrojan.Doina.DA804
ViRobotTrojan.Win.Z.Doina.102569.C
ZoneAlarmTrojan.Win32.Vobfus.auyq
MicrosoftTrojanDownloader:Win32/Kanav.CH!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Downloader.R47380
Acronissuspicious
McAfeeGeneric BackDoor.cy
MAXmalware (ai score=80)
VBA32Exploit.Vanak
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_056749.TOMB
RisingDownloader.Agent!1.66A5 (CLASSIC)
YandexTrojan.GenAsa!0dOtDiZzGAs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.RAK!tr.dldr
BitDefenderThetaAI:Packer.6136652F1F
AVGWin32:Downloader-LMY [Trj]
Cybereasonmalicious.d6b912
DeepInstinctMALICIOUS

How to remove Doina.43012?

Doina.43012 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment