Trojan

Trojan:Win32/Doplik removal guide

Malware Removal

The Trojan:Win32/Doplik is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Doplik virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Attempted to write directly to a physical drive
  • Collects information to fingerprint the system

How to determine Trojan:Win32/Doplik?


File Info:

name: 138267DAFB14B46D7935.mlw
path: /opt/CAPEv2/storage/binaries/c95c4a1e939baf4bd1d7c4a6e236dc0d673fd5f48e4d1a410e69929d7cca8273
crc32: B877842A
md5: 138267dafb14b46d79356d9c548e21ac
sha1: ff9dfb976efa254c9e4f0ab96ba7dd30b1a22859
sha256: c95c4a1e939baf4bd1d7c4a6e236dc0d673fd5f48e4d1a410e69929d7cca8273
sha512: 3cc1c585dea68d39f8559b9a5edf32a7894b709d6bcaf0f3a01ac3a5a951164e5aa62dc43a03a5020e016dc50d590994ea8bb21aa1737f93a2cedd29e31a0a57
ssdeep: 24576:PFGQ7I2W0sdMKPAOhJPAOhXnebe+/Apd2BEbFn++4dYD:029sdMtZSnebe+/AXbFn++b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127356B066BA4DA16D1EEEF31DCBA0B0427B7E487B267DB4B608409A81C5274C1EF1777
sha3_384: 1fd42c9bcf105f9f82b0a5e7c7c0a7831b28f3949d8a039d97c94b17b98d60c98283747fb3547bcfa620dc5c1081b7bb
ep_bytes: ff2560c44f00000000000000000034c4
timestamp: 2023-02-27 06:17:39

Version Info:

Translation: 0x0000 0x04b0
Comments: PDFConverty
CompanyName:
FileDescription: PDFConverty
FileVersion: 1.0.6
InternalName: PDFConvertyexe.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: PDFConvertyexe.exe
ProductName: PDFConverty
ProductVersion: 1.0.6
Assembly Version: 1.0.6.0

Trojan:Win32/Doplik also known as:

BkavW32.Common.9D4EFC46
LionicTrojan.Win32.Doplik.4!c
SkyhighArtemis!Trojan
McAfeeArtemis!138267DAFB14
MalwarebytesPUP.Optional.MediaArena
SangforTrojan.Win32.Doplik.Vm2q
AlibabaTrojan:Win32/Doplik.a709584c
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 00584baa1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/MediaArena.C potentially unwanted
BitDefenderGen:Variant.Marsilia.89853
SUPERAntiSpywareTrojan.Agent/Gen-Doina
MicroWorld-eScanGen:Variant.Marsilia.89853
AvastWin32:MalwareX-gen [Trj]
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.fxvxx
DrWebAdware.Linkury.143
VIPREGen:Variant.Marsilia.89853
TrendMicroTROJ_GEN.R002C0DL623
EmsisoftGen:Variant.Marsilia.89853 (B)
IkarusTrojan.Win32.Doplik
GDataGen:Variant.Marsilia.89853
VaristW32/Doplik.A.gen!Eldorado
AviraTR/Redcap.fxvxx
Antiy-AVLTrojan/Win32.Doplik
ArcabitTrojan.Marsilia.D15EFD
MicrosoftTrojan:Win32/Doplik
GoogleDetected
VBA32TScope.Trojan.MSIL
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DL623
RisingTrojan.Doplik!8.12141 (CLOUD)
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/MediaArena
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Doplik?

Trojan:Win32/Doplik removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment