Malware

About “Doina.25760” infection

Malware Removal

The Doina.25760 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.25760 virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself

Related domains:

web.kago.club

How to determine Doina.25760?


File Info:

crc32: DDB8C613
md5: df15c072955879d9ea9fa6f2e6c22a6c
name: DF15C072955879D9EA9FA6F2E6C22A6C.mlw
sha1: 69a74fb2d4887428282710a6525e5de078b5d030
sha256: 8822e94cc17823161c8efd60929bb2988d1ad6624df26608e959aa7484cb8f5b
sha512: d0425acb9b07590d1f4166a0547d98283aa43cf2d76bef744e52bfa839c24aa16511f2e852138b670d92a72df1c64e0f2871f81402277516ebbdfcdd6ea3be88
ssdeep: 49152:Shk1R5GVz4MXtQ48orpGbAQ0dk/OoKXBTB/qp+XvljY23O/DsTDQDvZj+7CV1Xt:ZR5GVz4MXt3dVNdaOoKXBTB/qpWxY23
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: skyx7684x7248x6743x6240x6709
FileVersion: 10.18.1.0
CompanyName: sky
Comments: MySkin LOL
ProductName: MySkin
ProductVersion: 10.18.1.0
FileDescription: MySkin LOL
Translation: 0x0804 0x04b0

Doina.25760 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 0050718d1 )
LionicTrojan.Script.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.StartPage1.60599
CynetMalicious (score: 100)
ALYacGen:Variant.Doina.25760
CylanceUnsafe
K7GWAdware ( 0050718d1 )
Cybereasonmalicious.295587
CyrenW32/Trojan.CLL.gen!Eldorado
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan.Script.Generic
BitDefenderGen:Variant.Doina.25760
MicroWorld-eScanGen:Variant.Doina.25760
Ad-AwareGen:Variant.Doina.25760
SophosMal/Agent-AVP
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34266.1oLfaCGPe0ib
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.df15c072955879d9
EmsisoftGen:Variant.Doina.25760 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Gen3
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Script/Phonzy.C!ml
ArcabitTrojan.Doina.D64A0
ZoneAlarmHEUR:Trojan.Script.Generic
GDataWin32.Trojan.PSE.12FI8JT
AhnLab-V3Malware/Win.Generic.R444729
Acronissuspicious
McAfeeArtemis!DF15C0729558
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.FlyStudio
PandaTrj/Genetic.gen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Doina.25760?

Doina.25760 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment