Malware

Should I remove “Doris.7309”?

Malware Removal

The Doris.7309 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doris.7309 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Doris.7309?


File Info:

name: D90DA1607BD8C7C51840.mlw
path: /opt/CAPEv2/storage/binaries/69587ff82ba982d4d16b03e182107c21ca3f3e7b9732b959ccef981aac95ca8c
crc32: DFC4CE2C
md5: d90da1607bd8c7c51840193b13d1eb71
sha1: 103a2d57f0643ff075740987e9db5ad77a8e3678
sha256: 69587ff82ba982d4d16b03e182107c21ca3f3e7b9732b959ccef981aac95ca8c
sha512: 6e1560ee17b0d8cf8e7ace374f7e692d431b059680fbe5e6430cab398405aa1872c6deb702ed4ac6e10c0d0a6fc2cae928c8af83b65eb4d8b01bb80bc64f169f
ssdeep: 3072:00c0Gd9r/9ydS69WV09ThL7SfhEDvM8zhAT7SgfiQtP:01tilu7SgKQl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5440FF37AF15EC8DEC214FF731482B7585A30390A86817965BBAEF03C9D225D1885E6
sha3_384: 3d13caf6574f6a4fa710ee07dec516199776814b843493221e43db57ef1ba1b890b78c37d47ad568cc0e402cb06217ad
ep_bytes: 6800124000e8eeffffff000040000000
timestamp: 2003-08-10 03:29:26

Version Info:

Translation: 0x0409 0x04b0
ProductName: eRmvHa1
FileVersion: 7.86
ProductVersion: 7.86
InternalName: eRmvH1
OriginalFilename: eRmvH1.exe

Doris.7309 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.li7E
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doris.7309
FireEyeGeneric.mg.d90da1607bd8c7c5
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeDownloader-CJX.gen.au
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.WBNA.Win32.876639
SangforSuspicious.Win32.Save.a
K7AntiVirusP2PWorm ( 001ce8dd1 )
AlibabaWorm:Win32/vobfus.1030
K7GWP2PWorm ( 001ce8dd1 )
Cybereasonmalicious.7f0643
ArcabitTrojan.Doris.D1C8D
BitDefenderThetaAI:Packer.DF21DAD91F
VirITWorm.Win32.VBNA.B
SymantecW32.Changeup!gen20
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.WR
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-1322
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.Doris.7309
NANO-AntivirusTrojan.Win32.VB.coonjh
AvastWin32:AutoRun-BSB [Wrm]
TencentWorm.Win32.Wbna.wa
EmsisoftGen:Variant.Doris.7309 (B)
BaiduWin32.Worm.Autorun.am
F-SecureWorm.WORM/CodeT.A
DrWebWin32.HLLW.Autoruner.35286
VIPREGen:Variant.Doris.7309
TrendMicroWORM_VOBFUS.SMIB
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
VaristW32/S-c83aef09!Eldorado
AviraWORM/CodeT.A
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.VB.ww@2ajsup
MicrosoftWorm:Win32/Vobfus!pz
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGen:Variant.Doris.7309
GoogleDetected
AhnLab-V3Worm/Win32.VBNA.R50288
Acronissuspicious
VBA32SScope.Trojan.VBRA.8804
ALYacGen:Variant.Doris.7309
MAXmalware (ai score=85)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_VOBFUS.SMIB
RisingWorm.Autorun!1.99ED (CLASSIC)
YandexTrojan.GenAsa!erL4VW5KLKg
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoRun.XM!worm
AVGWin32:AutoRun-BSB [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Doris.7309?

Doris.7309 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment