Malware

About “Doina.60895” infection

Malware Removal

The Doina.60895 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.60895 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Doina.60895?


File Info:

name: 3032DD3D0406EEF97362.mlw
path: /opt/CAPEv2/storage/binaries/434df1c3f3e3802aba78cb559483a22edc9d8c1704446f35a3504cb2d079aff4
crc32: 494E35AD
md5: 3032dd3d0406eef9736275fc60c566c6
sha1: cfae443852389b77781b7c07c68b92184a9ed739
sha256: 434df1c3f3e3802aba78cb559483a22edc9d8c1704446f35a3504cb2d079aff4
sha512: a776c3ccfdc1ca77dfc035c0bfbf45f480a79b8b25f2d215f3c23b836292e3929b228c93bbd2e64dac9db8a7852b872964d2d90cbce851fa37d90f51b153be40
ssdeep: 24576:/eM1I6k8cgr3rTtIKYCH4WBexKvHBsU/goPo9K:/L1I6kNgr3ntPYCHJHB7o8+K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T105754C01B7914118FDF316FA8AFE606C952CBDE00B68A0D761C86AEE5A25BF17C31717
sha3_384: 9b24ac31dc2cb97e7f3199777953c2b5ac702cc0a18ab008a9e9c7cd5c589abe12b2b781fcd35568db5aa7c7927aa3fa
ep_bytes: e9030f0600e9ae3e0300e9e96d0300e9
timestamp: 2023-07-15 19:09:04

Version Info:

FileDescription: Windows Service
FileVersion: 1.0.0.1
InternalName: svhostc
LegalCopyright: Copyright (C) 2023
OriginalFilename: svhostc
ProductName: svhostc
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04b0

Doina.60895 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Doina.60895
FireEyeGen:Variant.Doina.60895
ALYacGen:Variant.Doina.60895
MalwarebytesGeneric.Malware/Suspicious
K7AntiVirusTrojan ( 005a96931 )
BitDefenderGen:Variant.Doina.60895
K7GWTrojan ( 005a96931 )
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.WTBWVR
APEXMalicious
CynetMalicious (score: 100)
RisingTrojan.Generic@AI.97 (RDML:eR+BIdHLpNV+aXZJMpTDpQ)
F-SecureTrojan.TR/CoinMiner.czpwe
VIPREGen:Variant.Doina.60895
TrendMicroTROJ_GEN.R002C0DGU23
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/CoinMiner.czpwe
Antiy-AVLTrojan/Win32.Wacatac
Kingsoftmalware.kb.a.959
ArcabitTrojan.Doina.DEDDF
GDataGen:Variant.Doina.60895
BitDefenderThetaAI:Packer.1151B89D20
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DGU23
TencentWin32.Trojan.Coinminer.Xmhl
YandexTrojan.Agent!3Nwd07VdNFg
MaxSecureTrojan.Malware.214771848.susgen
FortinetW32/PossibleThreat
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]

How to remove Doina.60895?

Doina.60895 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment