Malware

Doina.16126 (file analysis)

Malware Removal

The Doina.16126 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.16126 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

cdn-file-ssl-wan.ludashi.com
s.ludashi.com

How to determine Doina.16126?


File Info:

crc32: CB3F2D3C
md5: 048ec3a35503f53f26bba3c4fb831e75
name: 048EC3A35503F53F26BBA3C4FB831E75.mlw
sha1: eb4692556ed78e31b5746700c351e3b20873bfb3
sha256: 535fdd4724b370968a01af628cd726a1f96bee606c30843ec48591b5fc0fa23f
sha512: d8d9908b83f173f0e3b4d0cddaa378c7d7ee8dd53d9d54080e563d9ef8645f16b918943277f5dc17804c6a058c2919fc95590bac8e9db3ec83fd4315b744f212
ssdeep: 98304:K1wpL+MIIwn5P3dipbX9DZhshMK0L7iOQzjumyCzEpqD:qw4Sc5P3KblZhY4ZQuZQzD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x5e94x7528x7a0bx5e8f
ProductVersion: 7.3.122.441
ProductName: x51b0x96eax738bx8005
FileVersion: 7.3.122.441
FileDescription: x51b0x96eax738bx8005
Translation: 0x0804 0x04b0

Doina.16126 also known as:

ClamAVWin.Malware.Fsysna-9760418-0
SangforTrojan.Win32.Agent.aa
BitDefenderGen:Variant.Doina.16126
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
MicroWorld-eScanGen:Variant.Doina.16126
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.048ec3a35503f53f
EmsisoftGen:Variant.Doina.16126 (B)
ArcabitTrojan.Doina.D3EFE
AegisLabTrojan.Win32.Generic.4!c
GDataWin32.Trojan.PSE.1K4L0HE
McAfeeArtemis!048EC3A35503
MAXmalware (ai score=80)
PandaTrj/Genetic.gen
RisingAdware.Agent!1.CFEB (CLASSIC)
FortinetW32/Johnnie.3159!tr
Paloaltogeneric.ml

How to remove Doina.16126?

Doina.16126 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment