Malware

Doina.48214 malicious file

Malware Removal

The Doina.48214 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.48214 virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Authenticode signature is invalid

How to determine Doina.48214?


File Info:

name: CAFA8E2E5510E74C5E4D.mlw
path: /opt/CAPEv2/storage/binaries/bcff3f65afa47729ed591f9eed8d5aefedf5a2521c077829ffe3436bb798d1ed
crc32: 24E23C68
md5: cafa8e2e5510e74c5e4d8fa78ee2d5cf
sha1: 7fc762d17fa8f35068a5d45faf3ad51a86f839fa
sha256: bcff3f65afa47729ed591f9eed8d5aefedf5a2521c077829ffe3436bb798d1ed
sha512: 6e865f3db5d0870a5b814c912a197a3410fb6fe23ddbf259ce0f3ad9ed1919e0d73ba68e3c0cfd12f63f82697428aea6fd4f0b8c89b5139bb827637472363e43
ssdeep: 6144:SR9eh569+UR6P3zIwkp4p2k/DPaZHwc3eoe6u17MgAOIMs8Bq:Sfm5BB7kpi2k/ae6u17pa8Bq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F6439417952C072D960A1721AB5BFF2C59D68249BB049DB7BC00F76DB212E77A30F3A
sha3_384: 13e718affda36a08c4358c3f388bbb8c3c6dd50e0128adbfae7e856cf1a144ae7e538c80d3d102964812f79a4cebabc0
ep_bytes: e82f060000e974feffff8b4df464890d
timestamp: 2023-08-11 05:05:24

Version Info:

0: [No Data]

Doina.48214 also known as:

BkavW32.AIDetectMalware
AVGWin32:Dh-A [Heur]
MicroWorld-eScanGen:Variant.Doina.48214
McAfeeDownloader-FCND!CAFA8E2E5510
MalwarebytesTrojan.Downloader
VIPREGen:Variant.Doina.48214
SangforTrojan.Win32.Save.a
Cybereasonmalicious.e5510e
BitDefenderThetaAI:Packer.57A85DC61F
CyrenW32/Amadey.C1.gen!Eldorado
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Amadey
ESET-NOD32a variant of Win32/TrojanDownloader.Amadey.A
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan-Banker.Win32.ClipBanker.gen
BitDefenderGen:Variant.Doina.48214
AvastWin32:Dh-A [Heur]
EmsisoftGen:Variant.Doina.48214 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.cafa8e2e5510e74c
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Amadey.D
JiangminTrojan.Generic.ekdes
MAXmalware (ai score=87)
ArcabitTrojan.Doina.DBC56
ZoneAlarmHEUR:Trojan-Banker.Win32.ClipBanker.gen
MicrosoftTrojan:Win32/Amadey.A!MTB
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5466218
ALYacGen:Variant.Doina.48214
Cylanceunsafe
PandaTrj/GdSda.A
RisingDownloader.Amadey!8.125AC (TFE:5:5THvZBcKOfP)
IkarusTrojan-Downloader.Win32.Amadey
FortinetW32/Amadey.A!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Doina.48214?

Doina.48214 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment