Malware

Doina.57995 malicious file

Malware Removal

The Doina.57995 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.57995 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Doina.57995?


File Info:

name: 786E9DDF7C72C8AAF6ED.mlw
path: /opt/CAPEv2/storage/binaries/e2bb12bd029c30f1a214eaabf4b265ad564927448e8864cc83c3be25f65fe9fd
crc32: 96F06111
md5: 786e9ddf7c72c8aaf6ed8ac8b321c262
sha1: 303b893002a553a16fa9a25bed86c01fd0bb1f96
sha256: e2bb12bd029c30f1a214eaabf4b265ad564927448e8864cc83c3be25f65fe9fd
sha512: fa0932dc2ef28d27be6e48164f94e00f1b213dad3ecf6f31cd8af5442a23cd5b67e64b577e6f3fa1c06a77965f1426f4f78e08026f62952e77c474eb456654d8
ssdeep: 6144:5nxrhVEz5CHWhtk4w6ezxdMK8g3A7PFo4/3U4:5nxrhWz5CHWhtbwhMKX3AZb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F844A23D511E0F2D025067B76B9033D79B99732642681A7EBC4CF746EA63F18BA670C
sha3_384: d72d12d6d47282a08329a696891b3e89a694cfb80d940bccbec3035ec359a40b2bea2df6fd7322573516aeac64765003
ep_bytes: 558bec6aff68c081440068085f430064
timestamp: 2023-02-28 04:29:47

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Doina.57995 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.57995
ClamAVWin.Dropper.Tiggre-9845940-0
FireEyeGeneric.mg.786e9ddf7c72c8aa
McAfeeRDN/Generic.dx
MalwarebytesPUP.Optional.ChinAd
ZillyaTrojan.GenCBL.Win32.12405
SangforTrojan.Win32.Save.BlackMoon
K7AntiVirusTrojan ( 0058fc4f1 )
K7GWTrojan ( 0058fc4f1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/ABRisk.FKCW-3592
SymantecTrojan Horse
ESET-NOD32a variant of Win32/GenCBL.BUN
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Blamon.gen
BitDefenderGen:Variant.Doina.57995
AvastWin64:RATX-gen [Trj]
TencentWin32.Trojan.FalseSign.Osmw
F-SecureHeuristic.HEUR/AGEN.1342531
DrWebTrojan.MulDrop21.53320
VIPREGen:Variant.Doina.57995
TrendMicroTROJ_GEN.R002C0PC323
McAfee-GW-EditionRDN/Generic.dx
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Doina.57995 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan-Stealer.BlackMoon.D
AviraHEUR/AGEN.1342531
Antiy-AVLTrojan/Win32.Blamon.a
ArcabitTrojan.Doina.DE28B
ZoneAlarmHEUR:Trojan.Win32.Blamon.gen
MicrosoftPUA:Win32/Fox
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2627103
ALYacGen:Variant.Doina.57995
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PC323
RisingRootkit.Agent!1.E3AE (CLASSIC)
IkarusTrojan.Win32.Generic
MaxSecureDropper.Dinwod.frindll
FortinetRiskware/Blackmoon
AVGWin64:RATX-gen [Trj]
Cybereasonmalicious.f7c72c
DeepInstinctMALICIOUS

How to remove Doina.57995?

Doina.57995 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment