Trojan

Trojan:Win32/Dodinede.A removal instruction

Malware Removal

The Trojan:Win32/Dodinede.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dodinede.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Dodinede.A?


File Info:

name: D6A8612F2CF303D8D8C2.mlw
path: /opt/CAPEv2/storage/binaries/1aeaade8915900d7309e113f556abb21a00cf0ce534a5c9763c0d2b5c996d0d9
crc32: AC80123F
md5: d6a8612f2cf303d8d8c27105529dc13f
sha1: deff0dd53c0c025cbcb529875ff8dcf97376c4a9
sha256: 1aeaade8915900d7309e113f556abb21a00cf0ce534a5c9763c0d2b5c996d0d9
sha512: d0a570d67b76e652f79409b7399e3d0518ba9b912b95bbd50eaa5439b6e74764d91016cfcf818b5a11e491793f8a0979af9204964b47f27acd2dd7347325deca
ssdeep: 1536:wi1TEU51CjlAXWXbL4xGWQfH4+i204iNzfNDD0g+wahWnr/:wi1wU51S+mQMfH4Z20fNblD0g+L0nr/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121C31913B5B46422E22385F04CB1A7BE741B7CB11491DD0B3589EB0E1A73B93ADA631F
sha3_384: 247dc28e63925062e33fd80e8c028439b830404385947b39692d108b04b8d9a7d3337ee4b8db48806be8e168bee25735
ep_bytes: 6878354000e8eeffffff000000000000
timestamp: 2012-06-19 16:18:28

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Muriates Developement
ProductName: muriates
FileVersion: 1.00
ProductVersion: 1.00
InternalName: smtpdoidi
OriginalFilename: smtpdoidi.exe

Trojan:Win32/Dodinede.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VB.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen4.7095
MicroWorld-eScanBackdoor.VB.Agent.KF
ClamAVWin.Trojan.Agent-532586
FireEyeGeneric.mg.d6a8612f2cf303d8
SkyhighGeneric.lb
McAfeeGeneric.lb
Cylanceunsafe
ZillyaTrojan.VB.Win32.90225
SangforTrojan.Win32.VB.QNP
K7AntiVirusTrojan-Downloader ( 001656ed1 )
AlibabaTrojan:Win32/Dodinede.715c68dd
K7GWTrojan-Downloader ( 001656ed1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitBackdoor.VB.Agent.KF
BitDefenderThetaAI:Packer.B0C53BF321
VirITTrojan.Win32.Generic.BWGM
SymantecBackdoor.Trojan
ESET-NOD32Win32/VB.QNP
ZonerTrojan.Win32.7966
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.VB.auks
BitDefenderBackdoor.VB.Agent.KF
NANO-AntivirusTrojan.Win32.VB.ebyqqu
TencentWin32.Trojan.Vb.Vmhl
SophosMal/Generic-R
F-SecureTrojan.TR/Spy.122880.359
VIPREBackdoor.VB.Agent.KF
TrendMicroTROJ_AGENTB.ITW
Trapminemalicious.moderate.ml.score
EmsisoftBackdoor.VB.Agent.KF (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/VB.cwpd
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Spy.122880.359
Antiy-AVLTrojan/Win32.VB
XcitiumMalware@#2b0h3hbd7u7r0
MicrosoftTrojan:Win32/Dodinede.A
ViRobotTrojan.Win32.A.VB.122880.S
ZoneAlarmTrojan.Win32.VB.auks
GDataWin32.Trojan.Agent.2NQ9HU
VaristW32/Trojan.EBIY-0112
VBA32Trojan.VB
ALYacBackdoor.VB.Agent.KF
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_AGENTB.ITW
RisingTrojan.VB!8.B20 (TFE:5:kd9xLt3soPP)
IkarusTrojan.Win32.VB
MaxSecureTrojan.Malware.2718768.susgen
FortinetW32/VB.AUKS!tr
PandaGeneric Malware

How to remove Trojan:Win32/Dodinede.A?

Trojan:Win32/Dodinede.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment