Malware

Doina.25672 removal guide

Malware Removal

The Doina.25672 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.25672 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Doina.25672?


File Info:

name: 5946B63878D964C6F511.mlw
path: /opt/CAPEv2/storage/binaries/1ebeac9e129b743f88b3593168a47d98d6180ec90c219ef121366c24952b31c9
crc32: 312B3CE0
md5: 5946b63878d964c6f51129b3e6a2470c
sha1: 27588e4d4425420f12006986f08ee950a2b8c3e9
sha256: 1ebeac9e129b743f88b3593168a47d98d6180ec90c219ef121366c24952b31c9
sha512: f5b5a6f2e2d73550b5d574a656a07532a3c728763f04014512de1b0feb0fef195f65223c690d076cbabeafdb0c36bde2ba17869b1ae05bcb57fe910eb1d6605b
ssdeep: 6144:iJV10cTrk/mWVqwvzJR6QLW4/ih5IDyL+FUcEOkCybEaQRXr9HNdvOa:qt+aQa4/cIDyJOkx2LIa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188947C25BAA08076C5678579C4E257ABFBB1752137208ACFA390075A5F237E3BD3630D
sha3_384: 17243a4b3be5ef06526332140cc1ca701154f944beb0befe1f3922fcc1c9159073550c829661c8180b097f1d9dae2e4c
ep_bytes: e8ab370000e979feffff8bff558bec5d
timestamp: 2023-07-10 10:05:50

Version Info:

FileVersion: 23, 7, 10, 1805
ProductVersion: 23, 7, 10, 1805
Translation: 0x0804 0x04b0

Doina.25672 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.25672
FireEyeGeneric.mg.5946b63878d964c6
CAT-QuickHealTrojan.IGENERIC
ALYacGen:Variant.Doina.25672
Cylanceunsafe
ZillyaTrojan.Sfuzuan.Win32.824
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Convagent.5e7d1173
K7GWTrojan ( 0054e9cc1 )
K7AntiVirusTrojan ( 0054e9cc1 )
BitDefenderThetaGen:NN.ZexaF.36318.yu0@a4k4l2nj
CyrenW32/Gulpix.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Sfuzuan.AB
APEXMalicious
ClamAVWin.Malware.Barys-10002593-0
KasperskyBackdoor.Win32.Convagent.r
BitDefenderGen:Variant.Doina.25672
NANO-AntivirusTrojan.Win32.Gulpix.jxexcz
AvastWin32:BackdoorX-gen [Trj]
TencentMalware.Win32.Gencirc.10bf08a8
EmsisoftGen:Variant.Doina.25672 (B)
F-SecureTrojan.TR/Sfuzuan.owaqv
DrWebTrojan.Siggen21.8155
VIPREGen:Variant.Doina.25672
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1XKCGNB
AviraTR/Sfuzuan.owaqv
Antiy-AVLTrojan/Win32.Sfuzuan
ArcabitTrojan.Doina.D6448
ViRobotTrojan.Win.Z.Sfuzuan.408064.G
ZoneAlarmBackdoor.Win32.Convagent.r
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R355135
Acronissuspicious
McAfeeGenericRXAA-FA!5946B63878D9
MAXmalware (ai score=83)
VBA32BScope.Trojan.Tiggre
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CGJ23
RisingBackdoor.Gulpix!8.3DA (TFE:5:D5c93dakOJL)
IkarusTrojan.Win32.Sfuzuan
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Sfuzuan.AB!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.878d96
DeepInstinctMALICIOUS

How to remove Doina.25672?

Doina.25672 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment