Malware

Doris.3417 information

Malware Removal

The Doris.3417 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doris.3417 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to remove evidence of file being downloaded from the Internet
  • Behavioural detection: Injection (inter-process)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Doris.3417?


File Info:

name: 4AEF358A39DBBD6EE397.mlw
path: /opt/CAPEv2/storage/binaries/2b145aa8e2d89e48c6839dc3ce6cbb69a18920ce12458717efc0d290329f7bf2
crc32: 980774DB
md5: 4aef358a39dbbd6ee3976556e229f8d3
sha1: be368dbfa826265ff64c40812dbe88cb567ee705
sha256: 2b145aa8e2d89e48c6839dc3ce6cbb69a18920ce12458717efc0d290329f7bf2
sha512: 71bdde968ee9e861c795836672270b92c38fe12254a661fbaadabbe488b00f382e79e7a31dd974cbac191266197ae22e5023d73e252e1b112a8f97d9add50db0
ssdeep: 6144:A/r4R7F99KnPbZDO1fyzCmBS/3mW3XENJH5Um+JdmT6uRkTmGJP3cJEv1AO:kr4b99KP9DO1fym9/3pXEzZU0T6mCmCz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T143841224DF685977D5A860F0A2E31E08AB4DC156785807C34627AF0EBE38777EE83B15
sha3_384: 7c6e60e4a1f3259e8e6ca42ac34261e6df051c842738ebffc3d53c8b3fc69f22e344b54fc89e300c5da84bac7b11c3df
ep_bytes: 60be00d049008dbe0040f6ff5783cdff
timestamp: 1999-09-10 13:24:35

Version Info:

CompanyName: Google Inc.
FileDescription: Google Chrome
FileVersion: 33.0.1750.146
InternalName: chrome_exe
LegalCopyright: Copyright 2012 Google Inc. All rights reserved.
OriginalFilename: chrome.exe
ProductName: Google Chrome
ProductVersion: 33.0.1750.146
CompanyShortName: Google
ProductShortName: Chrome
LastChange: 254388
Official Build: 1
Translation: 0x0409 0x04b0

Doris.3417 also known as:

LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Doris.3417
CAT-QuickHealWorm.Phorpiex.B8
ALYacGen:Variant.Doris.3417
CylanceUnsafe
SangforTrojan.Win32.ATRAPS.Gen
K7AntiVirusTrojan ( 00496a731 )
K7GWTrojan ( 00496a731 )
Cybereasonmalicious.a39dbb
BaiduWin32.Virus.Virut.gen
CyrenW32/Trojan.TJKE-6237
SymantecInfostealer.Napolar!g1
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Virut.NBP
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Doris.3417
NANO-AntivirusTrojan.Win32.Sdbot.cunrnl
AvastWin32:Patched-AFR [Trj]
TencentWin32.Virus.Virut.Pgxj
Ad-AwareGen:Variant.Doris.3417
SophosML/PE-A + Troj/Zbot-HVK
ComodoMalware@#2vk54zoom0xz6
DrWebTrojan.Siggen6.12173
ZillyaTrojan.Scarsi.Win32.1215
McAfee-GW-EditionPWSZbot-FVP!93D543348A7C
FireEyeGeneric.mg.4aef358a39dbbd6e
EmsisoftGen:Variant.Doris.3417 (B)
GDataGen:Variant.Doris.3417
JiangminWin32/Virut.bv
AviraTR/ATRAPS.Gen
MAXmalware (ai score=87)
KingsoftWin32.Infected.Virut.sr.(kcloud)
ArcabitTrojan.Doris.DD59
MicrosoftWorm:Win32/Phorpiex.B
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!4AEF358A39DB
VBA32TScope.Trojan.Delf
MalwarebytesNimnul.Virus.FileInfector.DDS
IkarusTrojan.Patched2_c
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.1FBCC9!tr
BitDefenderThetaAI:Packer.4F5F4B5521
AVGWin32:Patched-AFR [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Doris.3417?

Doris.3417 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment