Malware

What is “Doina.48214 (B)”?

Malware Removal

The Doina.48214 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.48214 (B) virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Authenticode signature is invalid

How to determine Doina.48214 (B)?


File Info:

name: 5E80C7648EBA07AE3D6D.mlw
path: /opt/CAPEv2/storage/binaries/cedc650a9228f3301ef58478f5c1ba743a21f0c94968ade505fd8144111c8a73
crc32: 246D37CC
md5: 5e80c7648eba07ae3d6d21274e30c48a
sha1: b249a91e3cb9160bacf1f7db23a44022bf8f880c
sha256: cedc650a9228f3301ef58478f5c1ba743a21f0c94968ade505fd8144111c8a73
sha512: 3d2f895f68633dfda0b2326a8cd2d9263839b45b4f28bfc60441b84d735ab637e1a5f027e51b310ff572545c03f730477f2b487c539fef4754c2cf2fa7ca0d48
ssdeep: 6144:V7Vj3uVUn27+6qQx41QPF2nnugMeS2SpY:xwYfQx9FOnugMeS2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10F24F7653916C032D660A1B619F4BFF2C19DA819ABB149DF2B800F77DA112F73970E39
sha3_384: fb9944769fc74b7ba32055966b84a6a726cec7870b9dee3994df0e3eda23bf84febec45ec735b36754f56aba1f9c8f4e
ep_bytes: e882040000e974feffffe9ea42000055
timestamp: 2023-09-06 08:56:36

Version Info:

0: [No Data]

Doina.48214 (B) also known as:

BkavW32.AIDetectMalware
ElasticWindows.Trojan.Amadey
MicroWorld-eScanGen:Variant.Doina.48214
ClamAVWin.Malware.Doina-10001799-0
ALYacGen:Variant.Doina.48214
VIPREGen:Variant.Doina.48214
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a7a4a1 )
K7GWTrojan ( 005a7a4a1 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Amadey.C1.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Amadey.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Deyma.gen
BitDefenderGen:Variant.Doina.48214
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Doina.48214 (B)
F-SecureHeuristic.HEUR/AGEN.1317762
McAfee-GW-EditionBehavesLike.Win32.Downloader.dh
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.5e80c7648eba07ae
SophosMal/Amadey-C
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Amadey.D
AviraHEUR/AGEN.1317762
MAXmalware (ai score=88)
ArcabitTrojan.Doina.DBC56
ZoneAlarmHEUR:Trojan-Downloader.Win32.Deyma.gen
MicrosoftTrojan:Win32/Amadey.AY!MTB
GoogleDetected
McAfeeDownloader-FCND!5E80C7648EBA
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.100 (RDML:xp1honk5afyg1U/F2QKUHQ)
IkarusTrojan-Downloader.Win32.Amadey
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Amadey.A!tr
BitDefenderThetaAI:Packer.92097B291F
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Doina.48214 (B)?

Doina.48214 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment