Malware

Doina.16972 removal tips

Malware Removal

The Doina.16972 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.16972 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Doina.16972?


File Info:

name: E8C417568CF2BBCDBD65.mlw
path: /opt/CAPEv2/storage/binaries/4501ffd23e74c4130720e965586f6606e01b144d97b420d16abaebc93782d1e8
crc32: A553EDC5
md5: e8c417568cf2bbcdbd65e53366d92b89
sha1: ae696d6df31c81e1342abb7266011034fd9ab8be
sha256: 4501ffd23e74c4130720e965586f6606e01b144d97b420d16abaebc93782d1e8
sha512: 00742082a6e99961483c0f6681da2cd552a80b7378456b1b60df0139b2d0195e998998e0965ac1e074fb99bff4bcf857a550eb0ed110f25b63554305100ba7a8
ssdeep: 48:Zvtyb0xItX+PKS+ohVWZKRILePC8GSeJY8JTaIYoB:Z1yIxItA5hWEiR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B51A4C77E1C54BBC297123F13A8C223B27575B10FBE4A81AFF9161378C3498862499A
sha3_384: b6c1226103dbdaf072853cdf52b3ea7ce8dc0c25441c15de0e4702904116c6c76c88239b58b962ec0b91eba0010dc053
ep_bytes: 60be155040008dbeebbfffff5783cdff
timestamp: 2009-08-13 17:09:18

Version Info:

0: [No Data]

Doina.16972 also known as:

LionicTrojan.Win32.Small.l8da
DrWebTrojan.DownLoad.45120
MicroWorld-eScanGen:Variant.Doina.16972
ClamAVWin.Trojan.Agent-36030
FireEyeGeneric.mg.e8c417568cf2bbcd
SkyhighBehavesLike.Win32.Generic.xm
McAfeeArtemis!E8C417568CF2
Cylanceunsafe
ZillyaDownloader.Tintin.Win32.409
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 000d97c11 )
AlibabaTrojanDownloader:Win32/Tintin.dcbc5c73
K7GWTrojan-Downloader ( 000d97c11 )
Cybereasonmalicious.df31c8
BitDefenderThetaGen:NN.ZexaF.36744.amGfau0T6Ki
VirITTrojan.Win32.Agent.I
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/TrojanDownloader.Small.OPY
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Tintin.vjb
BitDefenderGen:Variant.Doina.16972
NANO-AntivirusTrojan.Win32.Small.barzx
AvastWin32:Small-NBP [Trj]
EmsisoftGen:Variant.Doina.16972 (B)
F-SecureTrojan.TR/Downloader.Gen
VIPREGen:Variant.Doina.16972
TrendMicroTROJ_DOWGAV.SMF
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Doina.16972
JiangminTrojanDownloader.Small.aeyl
GoogleDetected
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.HeurC.KVM008.a
XcitiumTrojWare.Win32.TrojanDownloader.Small.CR@1b3t7n
ArcabitTrojan.Doina.D424C
ViRobotTrojan.Win32.Downloader.11264.JY[UPX]
ZoneAlarmTrojan-Downloader.Win32.Tintin.vjb
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/Downloader.JPLS-7407
AhnLab-V3Downloader/Win32.Small.R2698
ALYacGen:Variant.Doina.16972
MAXmalware (ai score=99)
VBA32TrojanDownloader.Small
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
TrendMicro-HouseCallTROJ_DOWGAV.SMF
RisingTrojan.DL.Small!1.65BB (CLOUD)
YandexTrojan.GenAsa!gwcxxiP4LdA
IkarusTrojan-Downloader.Win32.Dowgav
MaxSecureTrojan.Malware.19313.susgen
FortinetW32/Small.OPY!tr.dldr
AVGWin32:Small-NBP [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Doina.16972?

Doina.16972 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment