Malware

Doina.9674 removal guide

Malware Removal

The Doina.9674 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.9674 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Doina.9674?


File Info:

name: 1A1E4D60BC50AFFBCEE6.mlw
path: /opt/CAPEv2/storage/binaries/f617e3d0c058e09566c97078d9411157fcda9392c3bec9bad71e6cef781e804f
crc32: 3AA059F4
md5: 1a1e4d60bc50affbcee63afbf17ddabe
sha1: 5d333ccea7d6459a9c3083251cdf0fea34b58de6
sha256: f617e3d0c058e09566c97078d9411157fcda9392c3bec9bad71e6cef781e804f
sha512: 1b3759ab73c6faa2a5d9fbd422e9991f92ddde776b5d1a7181f0417f9cba045b732f5ff1b2986feb6974e49f1f6faab8920ec4c0022428608af29550a612c827
ssdeep: 6144:BAzMDuL6wVQ+jex2envjZMqLNC95Cw8PEPHV0eX8:W5HjS2KlfLNo5CwKcc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10694925163F94608F6F77F7CAA792E7C4A76FC9EEC38C65C0252405F59B1A5088A0B23
sha3_384: 5c74ebdc77ff216149ce4a2cc0e9020743ab014928f705ddbde72f71ca8c1ce044fdba38c6d6386ec9a8e6ba63119419
ep_bytes: 558bec6aff68804a4000688231400064
timestamp: 2015-10-30 05:09:33

Version Info:

CompanyName: TeamViewer GmbH
FileDescription: TeamViewer 9
FileVersion: 9.0.29947.0
InternalName: TeamViewer
LegalCopyright: TeamViewer GmbH
LegalTrademarks: TeamViewer
OriginalFilename: TeamViewer_Resource.dll
PrivateBuild: TeamViewer Remote Control Application
ProductName: TeamViewer
ProductVersion: 9.0
Translation: 0x0809 0x04b0

Doina.9674 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Palevo.o!c
tehtrisGeneric.Malware
DrWebTrojan.DownLoader17.32279
MicroWorld-eScanGen:Variant.Doina.9674
FireEyeGeneric.mg.1a1e4d60bc50affb
CAT-QuickHealBackdoor.Venik.8262
McAfeeBackDoor-FDAJ!1A1E4D60BC50
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Doina.9674
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004d486b1 )
AlibabaWorm:Win32/Palevo.2a22b4c2
K7GWTrojan ( 004d486b1 )
Cybereasonmalicious.0bc50a
BitDefenderThetaGen:NN.ZexaF.36250.Ay1@aOUpk@pP
CyrenW32/Farfli.GH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Farfli.BVW
APEXMalicious
ClamAVWin.Trojan.Farfli-9952113-0
KasperskyP2P-Worm.Win32.Palevo.hyao
BitDefenderGen:Variant.Doina.9674
NANO-AntivirusTrojan.Win32.WOW.dygxtd
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Farfli.zj
EmsisoftGen:Variant.Doina.9674 (B)
F-SecureTrojan.TR/Crypt.ASPM.Gen
ZillyaWorm.Palevo.Win32.126161
TrendMicroTROJ_GEN.R002C0DFA23
McAfee-GW-EditionBehavesLike.Win32.Kudj.gh
Trapminemalicious.high.ml.score
SophosTroj/Venik-K
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Palevo.E
JiangminWorm.Palevo.fg
GoogleDetected
AviraTR/Crypt.ASPM.Gen
Antiy-AVLWorm[P2P]/Win32.Palevo
ArcabitTrojan.Doina.D25CA
ZoneAlarmP2P-Worm.Win32.Palevo.hyao
MicrosoftBackdoor:Win32/Venik.J
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Banki.R505390
VBA32Worm.Palevo
ALYacGen:Variant.Doina.9674
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DFA23
RisingBackdoor.Farfli!1.A275 (CLASSIC)
YandexTrojan.GenAsa!EK8JG6aINKQ
IkarusBackdoor.Win32.Venik
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Farfli.BVW!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Doina.9674?

Doina.9674 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment