Malware

Doris.8345 malicious file

Malware Removal

The Doris.8345 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doris.8345 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

How to determine Doris.8345?


File Info:

crc32: 4AD4EE73
md5: af4771e6987e4d938b952446a9c24a6b
name: AF4771E6987E4D938B952446A9C24A6B.mlw
sha1: 2601df2e46943ddc3688c3bbc1cf4931529ff68f
sha256: 5a7c41398b7baf7b760ab26a588d0bced8ba9e6acea4dbb6aeb12c6ff39b5a29
sha512: b2b278a49b65eae5400b2595ddd707fa56111ae1792681a6e2f1a95733f9ffb30afd57e356a19322f27d5cb456a57c3ef9fd16ed06909714de06175081af9ffa
ssdeep: 768:4ov7SmVoXZ0tAYkW49wWW6tJSyIFb8RQvWgiMK74Ly/8AsJLiA6S1vdT3L6TrSo:4ov7op8AP9wWtTSyIt8RoXIWL+mlTVP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: 2006-1991 Hister conservativist
InternalName: Sandp
FileVersion: 6.04.0004
CompanyName: Telerik
ProductName: Skullful
ProductVersion: 6.04.0004
FileDescription: Unjustif
OriginalFilename: Sandp.exe

Doris.8345 also known as:

BkavW32.AIDetect.malware1
CynetMalicious (score: 99)
ALYacGen:Variant.Doris.8345
CylanceUnsafe
Cybereasonmalicious.6987e4
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Blocker.bamk
BitDefenderGen:Variant.Doris.8345
NANO-AntivirusTrojan.Win32.Blocker.daanhm
MicroWorld-eScanGen:Variant.Doris.8345
TencentWin32.Trojan.Blocker.Lorn
Ad-AwareGen:Variant.Doris.8345
SophosML/PE-A + Troj/VBInj-MJ
ComodoTrojWare.Win32.VB.KLM@4xatot
BitDefenderThetaGen:NN.ZevbaF.34142.dmKfa4FV@tfi
VIPREVirtool.Win32.VBInject.abs (v)
McAfee-GW-EditionBehavesLike.Win32.Trojan.kc
FireEyeGen:Variant.Doris.8345
EmsisoftGen:Variant.Doris.8345 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.VB.Gen8
eGambitUnsafe.AI_Score_93%
Antiy-AVLTrojan/Generic.ASMalwS.291D9F
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Doris.8345
AhnLab-V3Trojan/Win32.MDA.R115026
McAfeeArtemis!AF4771E6987E
MAXmalware (ai score=98)
VBA32TrojanRansom.Blocker
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!4qbl99uDg7g
IkarusVirus.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.AFCD!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Doris.8345?

Doris.8345 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment