Malware

Doina.63347 (B) (file analysis)

Malware Removal

The Doina.63347 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.63347 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Doina.63347 (B)?


File Info:

name: 98F30759C5E90BD52CA8.mlw
path: /opt/CAPEv2/storage/binaries/a02e9414410feac656d43c653631a4b9e4642dc319387461665a13ecdae49883
crc32: 81086453
md5: 98f30759c5e90bd52ca87f4c29da9553
sha1: 9bdf78f8c27f681f09f1b3832d463a256e35a284
sha256: a02e9414410feac656d43c653631a4b9e4642dc319387461665a13ecdae49883
sha512: 617e9f31701bb6641b3fee666fe37bdf697255d83dfe78bfbefeb4a507fbb881b58e8d3c2b817eb0cf90fc671ea3e8776f60e8808d5d60979407a7fa0b276d15
ssdeep: 6144:g4F1BI2fLzPz/0Z7e0ZSCvnUdukXIY27XkgRYGhZ+WCzY/f:g8VTz/0Ne6Dvn0v5y2GB
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15554E137B791F076C38C607C6548CEB75AA2E83062689802BB875F31DFB0751AB1D765
sha3_384: 699d27d065cb224daf6835d3b3c499363bed915510628d5c03072dbeaa7236e17c7c324b34d146adbc90aa6a573b3631
ep_bytes: e8f4690000e9a4feffff8bff558bec56
timestamp: 2013-05-09 02:00:09

Version Info:

0: [No Data]

Doina.63347 (B) also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.63347
FireEyeGeneric.mg.98f30759c5e90bd5
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ab4bf1 )
K7GWTrojan ( 005ab4bf1 )
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW32/Kryptik.KPD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Patched.NKM
APEXMalicious
KasperskyHEUR:Trojan.Win32.Patched.gen
BitDefenderGen:Variant.Doina.63347
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.11b67bea
EmsisoftGen:Variant.Doina.63347 (B)
DrWebWin32.Beetle.2
VIPREGen:Variant.Doina.63347
McAfee-GW-EditionBehavesLike.Win32.Sality.dc
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Doina.63347
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Wacatac
Kingsoftmalware.kb.a.995
ArcabitTrojan.Doina.DF773
ZoneAlarmHEUR:Trojan.Win32.Patched.gen
MicrosoftTrojan:Script/Phonzy.B!ml
GoogleDetected
AhnLab-V3Worm/Win.Sdbot.R604500
ALYacGen:Variant.Doina.63347
VBA32BScope.TrojanDownloader.Emotet
MalwarebytesMalware.AI.1660388333
RisingTrojan.Generic@AI.100 (RDML:YX3Qhlv7YDN0rlc0vMu7Qg)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Patched.IP!tr

How to remove Doina.63347 (B)?

Doina.63347 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment