Malware

How to remove “Doina.50524”?

Malware Removal

The Doina.50524 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.50524 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Doina.50524?


File Info:

name: 09B8DAFE7AB18F7F7EEE.mlw
path: /opt/CAPEv2/storage/binaries/e785fc36c20e5ac2902960576e837d6897cc6049a304915ff47e83dcf3e4bfde
crc32: E0D102B5
md5: 09b8dafe7ab18f7f7eee58bb30ded672
sha1: aee3f01504557c2ce47901c72daa2250922c14a8
sha256: e785fc36c20e5ac2902960576e837d6897cc6049a304915ff47e83dcf3e4bfde
sha512: a68f3dec9bf24a830f18430eace1ba48a49fca085cd903ae08272007d26438fce4aad3200f4564018324accdecc421f2d58f1e399e2f9b2ae88790e64ef21fdc
ssdeep: 24576:6/X47YFGRZ2DN7GerxGiX5nn/BRYnfs3FMOIaX:6fVFGwfnn/BKnUF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142259D91E7891CB5C8647C3C955BD17FEE734F802941CB8A81AA7F07B8D66C86872E30
sha3_384: 72977ff1c9c47f6fcb801906e71ad2504a505abb910d11d97dfc09ac37f3ce09957b6b770fc5a2c0fe9c6ee43024acb6
ep_bytes: e802040000e974feffff558bec8b4508
timestamp: 2023-02-10 18:01:43

Version Info:

0: [No Data]

Doina.50524 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Crysan.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.50524
FireEyeGeneric.mg.09b8dafe7ab18f7f
McAfeeArtemis!09B8DAFE7AB1
MalwarebytesTrojan.Dropper
ZillyaTrojan.Small.Win32.92311
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056e5201 )
AlibabaBackdoor:Win32/Crysan.c1035353
K7GWTrojan ( 0056e5201 )
Cybereasonmalicious.504557
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent_AGen.AIR
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Crysan.gen
BitDefenderGen:Variant.Doina.50524
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.117b12c7
SophosMal/Generic-R
F-SecureTrojan.TR/Small.kbbwf
VIPREGen:Variant.Doina.50524
TrendMicroTROJ_GEN.R023C0RBD23
McAfee-GW-EditionRDN/Generic BackDoor
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Doina.50524 (B)
GDataGen:Variant.Doina.50524
JiangminTrojan.Generic.gwtef
AviraTR/Small.kbbwf
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Small
ArcabitTrojan.Doina.DC55C
ZoneAlarmHEUR:Backdoor.Win32.Crysan.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacGen:Variant.Doina.50524
VBA32Trojan.Agent
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R023C0RBD23
RisingBackdoor.Crysan!8.10ECA (TFE:5:RlUNbz8okGG)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74669239.susgen
FortinetW32/NDAoF
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Doina.50524?

Doina.50524 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment