Malware

Doina.25190 removal

Malware Removal

The Doina.25190 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.25190 virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Doina.25190?


File Info:

name: AD95CFD111744FF48256.mlw
path: /opt/CAPEv2/storage/binaries/220074643ff2d7031f8a45cc13b6d8ab88d98f1022287faa4475de7aa05b7ae6
crc32: 338FF487
md5: ad95cfd111744ff48256c139e739f948
sha1: afdcd0c4384f7480ffe0d9094fad2c838fca19eb
sha256: 220074643ff2d7031f8a45cc13b6d8ab88d98f1022287faa4475de7aa05b7ae6
sha512: c373780ee17c8c97df7d58cdaf17ee5fda5a763c1e447b2485dbc669bfb0130e678492efdcede26ef7bfad0e209b0f09f0d4702f5a1ff06f851c5f05e73fd15e
ssdeep: 3072:q7lWcSzoFrJltLwmZGNcx+rAdvUXu3ER4+UUMVgwUUt2M4uxewcDVE9jEXb4+gTt:kOKtUEx6ovUXu3ER4+UUMVgwUUt2M4uD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T134E37D167682C4DAC76340F1828B6B5F4F567E210E6270E757C47F0EAEF50B56A3B086
sha3_384: 6cfa1140ed7be701b5772a761b6b95e60ec0dc58a447f177d656aca45c7f71feeaae3800a637d514f8e8ee39d5ba0967
ep_bytes: 558bec6aff68b890400068506c400064
timestamp: 2014-09-14 07:20:22

Version Info:

0: [No Data]

Doina.25190 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader16.16954
MicroWorld-eScanGen:Variant.Doina.25190
FireEyeGeneric.mg.ad95cfd111744ff4
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXAN-DG!AD95CFD11174
CylanceUnsafe
ZillyaBackdoor.Finfish.Win32.18
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/DropperX.56f39300
K7GWTrojan-Downloader ( 005412be1 )
K7AntiVirusTrojan-Downloader ( 005412be1 )
BitDefenderThetaGen:NN.ZexaF.34062.iqZ@aSTT2bcb
CyrenW32/Agent.DQN.gen!Eldorado
SymantecDownloader
ESET-NOD32Win32/TrojanDownloader.Agent.CWI
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Malware.Broskod-6804161-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Doina.25190
NANO-AntivirusTrojan.Win32.Dwn.dwrwuh
TencentMalware.Win32.Gencirc.10b0f069
Ad-AwareGen:Variant.Doina.25190
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Broskod.SA@6vorj1
TrendMicroTROJ_GEN.R002C0OKR21
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftGen:Variant.Doina.25190 (B)
Paloaltogeneric.ml
JiangminBackdoor/Finfish.d
AviraHEUR/AGEN.1121102
Antiy-AVLTrojan/Generic.ASMalwS.E5F25C
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftRansom.Win32.Sabsik.sa
GDataWin32.Trojan.PSE.13RMOHK
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Broskod.R190001
VBA32Trojan.Broskod
ALYacGen:Variant.Doina.25190
MAXmalware (ai score=82)
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_GEN.R002C0OKR21
RisingMalware.FakeXLS/ICON!1.9C3D (CLASSIC)
YandexTrojan.Broskod!EnkeBxbqRbM
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.CWI!tr
AVGWin32:DropperX-gen [Drp]

How to remove Doina.25190?

Doina.25190 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment