Malware

What is “Doina.27057”?

Malware Removal

The Doina.27057 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.27057 virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Doina.27057?


File Info:

name: DFBF20BF5B59527CECB0.mlw
path: /opt/CAPEv2/storage/binaries/0891117dc130a5c9c1a94524e0728e3b8202fa905480586a7461ef0f5e5610a2
crc32: 760D811E
md5: dfbf20bf5b59527cecb0cda6b3c211f0
sha1: d3b2fb5e5c9979bb0f034b4624c55a7d2020f6fc
sha256: 0891117dc130a5c9c1a94524e0728e3b8202fa905480586a7461ef0f5e5610a2
sha512: f15f99710b9dc137faa0e2ec91b43500aa347a00c35e4acdc17dfaaf37dc4fbfbca77a439107055b6fda67c33c97eb42dbca8236714d615b13d20e180e7b5663
ssdeep: 3072:0lOtuGx2iB/qxmY33JjXjMQpsQOSiLEO53KH5JLy:z2m/qxJnJjgMt2LEO5Yy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C304F81DE6E2D176C827083204CBD1BE5934BA7063598CDBF2C00E9A9976EF1637539B
sha3_384: 4c33e084327ed6000208958e123b758a0af1e4c7fb3f9ea7f2900d85ab0743b2ffd2ff83226cdcc506720d2d73ad87a6
ep_bytes: e88d050000e91cfdffffff2550964200
timestamp: 2021-03-20 16:07:46

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Consent UI for administrative applications
FileVersion: 6.1.7601.18896
InternalName: consent
LegalCopyright: ? Microsoft Corporation. All rights reserved.
OriginalFilename: consent.exe
ProductName: consent
ProductVersion: 6.1.7601.18896
Translation: 0x0804 0x04b0

Doina.27057 also known as:

MicroWorld-eScanGen:Variant.Doina.27057
FireEyeGeneric.mg.dfbf20bf5b59527c
McAfeeArtemis!DFBF20BF5B59
CylanceUnsafe
ZillyaTrojan.Farfli.Win32.40245
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34062.kC1@a8xDpPoj
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Farfli.CZM
TrendMicro-HouseCallTROJ_GEN.R035C0WL521
KasperskyHEUR:Trojan.Win32.Agentb.gen
BitDefenderGen:Variant.Doina.27057
AvastWin32:Trojan-gen
TencentWin32.Trojan.Falsesign.Wwep
Ad-AwareGen:Variant.Doina.27057
EmsisoftGen:Variant.Doina.27057 (B)
TrendMicroTROJ_GEN.R035C0WL521
McAfee-GW-EditionArtemis
SophosMal/Generic-S
IkarusTrojan.Win32.Farfli
GDataGen:Variant.Doina.27057
eGambitPE.Heur.InvalidSig
AviraTR/Farfli.jwpsh
Antiy-AVLTrojan/Generic.ASMalwS.34E5ABC
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32BScope.Trojan.Agent
ALYacGen:Variant.Doina.27057
MAXmalware (ai score=86)
FortinetW32/Farfli.CZM!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Doina.27057?

Doina.27057 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment