Malware

How to remove “Doina.38”?

Malware Removal

The Doina.38 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.38 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to modify proxy settings

How to determine Doina.38?


File Info:

name: 07C8A60C9EA1959B143A.mlw
path: /opt/CAPEv2/storage/binaries/ecfbc6328204161bb1dd1add274706ac09d1a74bbf9576f3b9bdbc72a12bc1d3
crc32: 7722E10D
md5: 07c8a60c9ea1959b143a1e1fa7ef56e4
sha1: d3ff05d5b39b134c8670fb993428467cdf29728d
sha256: ecfbc6328204161bb1dd1add274706ac09d1a74bbf9576f3b9bdbc72a12bc1d3
sha512: 25b841f661e2c73e8d7732b8d3497eb909e98350385869e3ec31d740621a6ba1ea4c0d9a0aaf6b67c8961aaa60db4cade61aae82674809c39f78c674754e8eb1
ssdeep: 3072:UsBD6HJfcDDXJ88RF+SKfJkuPutWiOIyZma0Dz7Xfi:UPpKC8RF+SKBkuPutWiOIFai7vi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16894B5201D08C9DAC7508B315BA2F9B4263C6D54BDA8098C3DD73F9B36B649FB51B239
sha3_384: f17f983130571b4f9c81c8d3c0b6be4ebb7265b28c273cdafbe712662289a693af7b5bd99ec932a2796cebce6ed98122
ep_bytes: 81ec8401000053555633db57895c241c
timestamp: 2013-05-19 23:53:02

Version Info:

0: [No Data]

Doina.38 also known as:

MicroWorld-eScanGen:Variant.Doina.38
FireEyeGen:Variant.Doina.38
McAfeeArtemis!07C8A60C9EA1
K7AntiVirusUnwanted-Program ( 004d38111 )
AlibabaTrojanDownloader:Win32/Generic.b6c3364b
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.c9ea19
SymantecTrojan.Gen.2
Elasticmalicious (moderate confidence)
ESET-NOD32NSIS/TrojanDownloader.Agent.NOM
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Doina.38
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Malware-gen
TencentWin32.Trojan-downloader.Genome.Hfk
Ad-AwareGen:Variant.Doina.38
SophosMal/Generic-S
ZillyaDownloader.Genome.Win32.60981
McAfee-GW-EditionBehavesLike.Win32.Dropper.gm
EmsisoftGen:Variant.Doina.38 (B)
GDataGen:Variant.Doina.38
WebrootPua.Adware.Playturtle
Antiy-AVLTrojan/Generic.ASMalwNS.522
KingsoftWin32.TrojDownloader.Genome.fi.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacGen:Variant.Doina.38
VBA32suspected of Trojan.Downloader.gen
FortinetW32/Genome.FIPL!tr.dldr
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Doina.38?

Doina.38 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment