Malware

Doina.10071 removal guide

Malware Removal

The Doina.10071 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.10071 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Creates known PcClient mutex and/or file changes.
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Doina.10071?


File Info:

name: 60828B0A3AED7FF1459A.mlw
path: /opt/CAPEv2/storage/binaries/4c746db20fe8d91ddd3e1402347b1e43a257d8db7ffa0c9061b891571d632ad2
crc32: 16CA3FB3
md5: 60828b0a3aed7ff1459a1e074b09f0dc
sha1: 1320999d1a87cc79239da25dbaf607e79f06ee8e
sha256: 4c746db20fe8d91ddd3e1402347b1e43a257d8db7ffa0c9061b891571d632ad2
sha512: 9fb481f68b00cb1b5794e9b721a41363df160ccfd248b7b6b68c7704829ff6aea6ad044e085c6f199441b95ca31049218e7eaf2b714e4fdb4ec10e9dc225a8a3
ssdeep: 3072:sX8gvoZhGH8RiRnvth6y47VFRg6rb1Zb/aQfZ6eiPeqovqw:sX8JZhmZ6yShltZbCVheqoi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9047D22F6C041FEE5651530709B7B369D3ABDA48B095A936717FE660D33290FB2234B
sha3_384: c543cc8f196d60b363c045c38c4f80485192f44c9d3f930b49db91fc2ff47d934bfc78155d503822435136d171334ce3
ep_bytes: 558bec6aff68e01040006840ae420064
timestamp: 2011-09-05 00:51:13

Version Info:

Comments:
CompanyName: Sogou.com Inc.
FileDescription: 搜狗拼音输入法 设置程序
FileVersion: 5.0.0.3787
InternalName: SogouPY Config
LegalCopyright: ? 2010 Sogou.com Inc. All rights reserved.
LegalTrademarks:
OriginalFilename: Config.exe
PrivateBuild:
ProductName: 搜狗拼音输入法
ProductVersion: 5.0.0.3787
SpecialBuild:
Translation: 0x0804 0x04b0

Doina.10071 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lLJx
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.10071
ClamAVWin.Dropper.Gh0stRAT-6992317-0
CAT-QuickHealBackdoor.Farfli.K4
SkyhighBehavesLike.Win32.Pate.cm
McAfeeFarfli.h
MalwarebytesFarFli.Backdoor.Bot.DDS
VIPREGen:Variant.Doina.10071
SangforSuspicious.Win32.Save.ins
AlibabaBackdoor:Win32/Farfli.2cfff5fb
Cybereasonmalicious.d1a87c
ArcabitTrojan.Doina.D2757
BaiduWin32.Backdoor.DarkAngle.a
VirITBackdoor.Win32.Generic.WL
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Farfli.DV
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Zegost.unj
BitDefenderGen:Variant.Doina.10071
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Farfli-AX [Trj]
TencentWin32.Backdoor.Zegost.Lqil
TACHYONTrojan/W32.Agent.176128.ARP
EmsisoftGen:Variant.Doina.10071 (B)
F-SecureHeuristic.HEUR/AGEN.1345204
DrWebTrojan.DownLoader4.52099
ZillyaTrojan.Farfli.Win32.1860
TrendMicroBKDR_ZEGOST.SMT
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminHeur:Trojan/Dialer
WebrootW32.Backdoor.Agent
GoogleDetected
AviraHEUR/AGEN.1345204
Kingsoftmalware.kb.a.1000
XcitiumMalware@#up4qyaxom6mu
MicrosoftTrojanDropper:Win32/Farfli.E
ZoneAlarmBackdoor.Win32.Zegost.unj
GDataWin32.Trojan.PSE.CGJLAQ
AhnLab-V3Dropper/Win32.OnlineGameHack.R3269
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.km0@ai2OOBhb
MAXmalware (ai score=100)
Cylanceunsafe
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallBKDR_ZEGOST.SMT
RisingBackdoor.Farfli!1.64A3 (CLASSIC)
YandexTrojan.Farfli!XlXtAZ98Gys
IkarusBackdoor.Win32.FirstInj
MaxSecureTrojan.Malware.7104872.susgen
FortinetW32/Farfli.AIL!tr
AVGWin32:Farfli-AX [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Doina.10071?

Doina.10071 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment