Malware

How to remove “Doina.15925”?

Malware Removal

The Doina.15925 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.15925 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

cdn-file-ssl-wan.ludashi.com
s.ludashi.com

How to determine Doina.15925?


File Info:

crc32: 38675458
md5: 043662a4b5e44eb83cec615f2a519906
name: 043662A4B5E44EB83CEC615F2A519906.mlw
sha1: a3445fe53782b10e5903e41ca8af89faac192df4
sha256: 1cded2a6ad0ce1864580e179b9ddd2a5eec787e96236bc8eb0cdb61ce47a137c
sha512: c12c0c0d356d81e085df20cf6bbcb9abe44f99051b235b249c3596a4ad9e18fd415cc506afd452c82f4603b8940c3f61dca82841c79918e7a883f0a64ff9fa3b
ssdeep: 98304:e1wpL+yII5n5PIdtsnZ3BxtBQzjumyCzEpq/:Ow4g95PIP2PQuZQz/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x6563x4ebax6253x91d1
ProductVersion: 3.2.124.1372
ProductName: x6563x4ebax6253x91d1
FileVersion: 3.2.124.1372
FileDescription: x6563x4ebax6253x91d1
Translation: 0x0804 0x04b0

Doina.15925 also known as:

CynetMalicious (score: 100)
SangforTrojan.Win32.PSE.1K4L0HE
BitDefenderGen:Variant.Doina.15925
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Fsysna-9760418-0
MicroWorld-eScanGen:Variant.Doina.15925
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.043662a4b5e44eb8
EmsisoftGen:Variant.Doina.15925 (B)
WebrootW32.Malware.Gen
AegisLabTrojan.Win32.Generic.4!c
GDataWin32.Trojan.PSE.1K4L0HE
McAfeeArtemis!043662A4B5E4
MAXmalware (ai score=85)
PandaTrj/Genetic.gen
RisingAdware.Agent!1.CFEB (CLASSIC)
FortinetW32/Johnnie.3159!tr

How to remove Doina.15925?

Doina.15925 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment