Malware

How to remove “Doina.17992”?

Malware Removal

The Doina.17992 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.17992 virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Anomalous binary characteristics

How to determine Doina.17992?


File Info:

crc32: 0DAF5FCC
md5: 0c6d85dd911cef67e8d696b194965a4b
name: 0C6D85DD911CEF67E8D696B194965A4B.mlw
sha1: baad6de398aa1fc72b8f14d25637a55944ccac69
sha256: 3b83cbf0cebeee10fcd6497eb28cf2933a65a2983bc42b4b3350fa65d72b7496
sha512: db40b650a977c1069fd7d994b54c0d2a7906a5b083b918169ca0d8b85e127be990310bfa661c5f0e1132441d4b69255c6797746ab2a2edc98e8219a1a56e58a3
ssdeep: 24576:GDv3hyBx11K8hU8KsCAx5ampOGt8SYiWdCMJ5Qxzr2C/hR:GDJ01sN2ampipiW0MbQxP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2010
InternalName: LoginTools.exe
FileVersion: 1,0,0,0
CompanyName: 178x7f51x6e38x5de5x4f5cx5ba4
ProductName: x5546x4e1ax7a0bx5e8f
ProductVersion: 1, 0, 0, 0
FileDescription: x5546x4e1ax7a0bx5e8f
OriginalFilename: LoginTools.exe
Translation: 0x0804 0x03a8

Doina.17992 also known as:

K7AntiVirusRiskware ( 005439d61 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader40.12935
CynetMalicious (score: 100)
ALYacGen:Variant.Doina.17992
CylanceUnsafe
ZillyaTool.GameTool.Win32.1172
CrowdStrikewin/malicious_confidence_60% (D)
K7GWRiskware ( 005439d61 )
Cybereasonmalicious.d911ce
CyrenW32/Legendmir.S.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.GameTool.S
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Doina.17992
NANO-AntivirusTrojan.Win32.GameTool.ixmtuz
MicroWorld-eScanGen:Variant.Doina.17992
TencentMalware.Win32.Gencirc.10cf07c4
Ad-AwareGen:Variant.Doina.17992
SophosGeneric ML PUA (PUA)
BitDefenderThetaAI:Packer.C6B1A80219
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUPXFU.tm
FireEyeGeneric.mg.0c6d85dd911cef67
EmsisoftGen:Variant.Doina.17992 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1103850
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.3343357
ArcabitTrojan.Doina.D4648
GDataGen:Variant.Doina.17992
AhnLab-V3Unwanted/Win32.GameHack.R355518
McAfeeGenericRXGA-BH!0C6D85DD911C
MAXmalware (ai score=85)
VBA32Trojan.SDP.27105
MalwarebytesRiskWare.GameTool
PandaTrj/Genetic.gen
YandexRiskWare.GameTool!dHta8m/b0EE
IkarusTrojan-Spy.Lmir
MaxSecureTrojan.Malware.73613737.susgen
FortinetW32/Lmir.BQT!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Doina.17992?

Doina.17992 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment