Malware

Doina.27345 information

Malware Removal

The Doina.27345 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.27345 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Doina.27345?


File Info:

name: 638AB27BC572FB511B24.mlw
path: /opt/CAPEv2/storage/binaries/c9b4b14e0ed516cb626da1d42e6d2c7273b357d94da8d9e1cd7623fcf9dd273e
crc32: 7467F6E5
md5: 638ab27bc572fb511b24f5d2cbc5b908
sha1: a712c901669b428b2ebdbe68441fcdcdb42137de
sha256: c9b4b14e0ed516cb626da1d42e6d2c7273b357d94da8d9e1cd7623fcf9dd273e
sha512: 1850112c842983982f409d091ba0459b0164d4f43f8cb28f8f6a97a6fd473c2558d198ca1ac0444e3aa269505b382e730e2259550558ceab609636b6e181f708
ssdeep: 1536:MZbVpOGtri2jOitri2jOitr+Zb/pOGtri2jOitri2jOitrN:MZhPr1r1iZLPr1r15
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13FA34B079A807E73CB57467A0D7B4635E6A3C3008738C9CBAF6468256B267D1BE3634D
sha3_384: 7f0aa5eebbce15448d167871112aba3fe03b63b9ef714033ed161073abdf08d45f45d1158a1f303b5c60910031cfe3fb
ep_bytes: 60be158040008dbeeb8fffff5783cdff
timestamp: 2016-03-01 22:44:44

Version Info:

0: [No Data]

Doina.27345 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agentb.trWi
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.27345
FireEyeGeneric.mg.638ab27bc572fb51
ALYacGen:Variant.Doina.27345
MalwarebytesTrojan.Dropper
ZillyaTrojan.Agent.Win32.2431372
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058876d1 )
BitDefenderGen:Variant.Doina.27345
K7GWTrojan ( 0058876d1 )
Cybereasonmalicious.bc572f
CyrenW32/Agent.DOR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.ADMM
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agentb.kntn
AlibabaTrojan:Win32/MalwareX.77abe71d
NANO-AntivirusTrojan.Win32.Agent.epwdel
RisingTrojan.Agent!1.D9AC (C64:YzY0OiyAATn80LKm)
Ad-AwareGen:Variant.Doina.27345
SophosMal/Generic-S
DrWebTrojan.Siggen15.22576
TrendMicroTROJ_GEN.R002C0PAU22
McAfee-GW-EditionBehavesLike.Win32.Sivis.nm
EmsisoftGen:Variant.Doina.27345 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.dlnq
AviraTR/Dropper.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.3516521
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.1YNUJ22
McAfeeArtemis!638AB27BC572
VBA32Trojan.Agentb
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PAU22
TencentTrojan.Win32.Agent.wb
YandexTrojan.Agent!wggADWGtfmw
MAXmalware (ai score=83)
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.ADMM!tr
BitDefenderThetaGen:NN.ZexaF.34182.gmJfaix7qjpi
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Doina.27345?

Doina.27345 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment