Malware

About “Doina.66756” infection

Malware Removal

The Doina.66756 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.66756 virus can do?

  • Uses Windows utilities for basic functionality
  • Authenticode signature is invalid
  • Creates known Fynloski/DarkComet mutexes

How to determine Doina.66756?


File Info:

name: BDE008BE6F7741C6C3E5.mlw
path: /opt/CAPEv2/storage/binaries/2d886cf1612ec78952cda46c14a6bfc24b993023763a63cfc5b0824c2974646b
crc32: 21F8C514
md5: bde008be6f7741c6c3e5029d0a8f894f
sha1: 4efff7f2883055d16c4f21f31b15f83cd0d3fb0b
sha256: 2d886cf1612ec78952cda46c14a6bfc24b993023763a63cfc5b0824c2974646b
sha512: 916327ffa608cdcd5ab27b9ba7ed434998f5cc47ef10603e16bc991473ad8f36ff77935e5c3d07151ae2bc9e9b8b3213abfc69d94f2ae440942fb6b8109ac3a7
ssdeep: 6144:pF7wRKlph4l+O7KQ7hBKszYBs1hjuyRpAOESz:pKRKlpKl+PLuPVz
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T147349D1074D1C873D5A2143248B5DBB64ABDB8210F21DAEBB7D41B7EDE302C19A35A7B
sha3_384: d47cf01b04655a28e71469083afdca7b93412f930e83b0c0e4513801571561d6f558c24d4bb5546f60b2eb8cb7cc4738
ep_bytes: e884040000e974feffffe9f445000083
timestamp: 2023-11-09 03:55:41

Version Info:

0: [No Data]

Doina.66756 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Doina.66756
FireEyeGeneric.mg.bde008be6f7741c6
SkyhighBehavesLike.Win32.Generic.dh
ALYacGen:Variant.Jaik.195318
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Variant.Doina.66756
SangforTrojan.Win32.Agent.Vo9r
BitDefenderGen:Variant.Doina.66756
Cybereasonmalicious.288305
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.KeyLogger.RHY
CynetMalicious (score: 100)
APEXMalicious
KasperskyVHO:Trojan-Dropper.Win32.Convagent.gen
AlibabaTrojanSpy:Win32/KeyLogger.57b1237c
RisingTrojan.Generic@AI.100 (RDML:h1+utySYEcArj62NCxvN+g)
EmsisoftGen:Variant.Doina.66756 (B)
F-SecureTrojan.TR/Spy.KeyLogger.vnecm
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Suspicious PE
AviraTR/Spy.KeyLogger.vnecm
Antiy-AVLTrojan[Spy]/Win32.KeyLogger
Kingsoftmalware.kb.a.798
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Doina.D104C4
ZoneAlarmVHO:Trojan-Dropper.Win32.Convagent.gen
GDataGen:Variant.Doina.66756
GoogleDetected
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=87)
DeepInstinctMALICIOUS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H09KA23
IkarusTrojan-Spy.Win32.KeyLogger
BitDefenderThetaGen:NN.ZexaF.36792.oqW@aiKGY9f
AVGWin32:Dh-A [Heur]
AvastWin32:Dh-A [Heur]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Doina.66756?

Doina.66756 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment