Malware

About “Doina.11610” infection

Malware Removal

The Doina.11610 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.11610 virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
edgedl.me.gvt1.com
update.googleapis.com
ic-b0696600-1475e2-windowsupdate61.s.loris.llnwd.net

How to determine Doina.11610?


File Info:

crc32: 17D38D6A
md5: de7c934886783529efab7789664de1fd
name: DE7C934886783529EFAB7789664DE1FD.mlw
sha1: e1082896850a3c2388352781785e63adf398568f
sha256: 41be89418aa464c33dbe641506a23fa1e0a4ae9e1dce21172ed742c60df2b8c5
sha512: c4e08b1cbfe3dee39d649cc3ba9d0988f2f4e1aa90677fc47e9e6654731be45165ef46a287473db62535893382a5964821e38735092550ce98e7e92a663c4370
ssdeep: 768:l/Dn5PVJWinyJVU7to6UlBh1g07bxMeukEGwbDszNAY1XKoJc4P1:ppbnCVMo5lLP7bx0DDUt
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Doina.11610 also known as:

BkavW32.RansomTO.Fam.Trojan
K7AntiVirusTrojan ( 0055e3df1 )
LionicTrojan.Win32.HmBlocker.lwU0
Elasticmalicious (high confidence)
DrWebTrojan.Packed.317
CynetMalicious (score: 100)
CAT-QuickHealTrojanDropper.Wlock.AA6
ALYacGen:Variant.Doina.11610
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/HmBlocker.f6e63a57
K7GWTrojan ( 0055e3df1 )
Cybereasonmalicious.886783
CyrenW32/Ransom.E.gen!Eldorado
SymantecTrojan.Ransomlock
ESET-NOD32a variant of Win32/LockScreen.AAV
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.HmBlocker.anh
BitDefenderGen:Variant.Doina.11610
NANO-AntivirusTrojan.Win32.Winlock.bsinq
MicroWorld-eScanGen:Variant.Doina.11610
TencentWin32.Trojan.Hmblocker.Wuhg
Ad-AwareGen:Variant.Doina.11610
SophosML/PE-A + Mal/Agent-IE
ComodoTrojWare.Win32.Trojan.Ransom.~B@465pcw
BitDefenderThetaAI:Packer.EED5C5221F
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.BrowseFox.pc
FireEyeGeneric.mg.de7c934886783529
EmsisoftGen:Variant.Doina.11610 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Ransom.ace
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Genasom.FF
ArcabitTrojan.Doina.D2D5A
GDataGen:Variant.Doina.11610
AhnLab-V3Trojan/Win32.HmBlocker.R2314
McAfeeGenericRXAA-AA!DE7C93488678
MAXmalware (ai score=86)
VBA32OScope.Trojan.PornoBlocker.Restarter
PandaTrj/CI.A
YandexTrojan.HmBlocker!ZfgvALbSk5Q
IkarusTrojan-Ransom.HmBlocker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.19500!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Doina.11610?

Doina.11610 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment