Malware

Doina.68904 removal tips

Malware Removal

The Doina.68904 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.68904 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Doina.68904?


File Info:

name: 7127DC292C7FD7E4BFEA.mlw
path: /opt/CAPEv2/storage/binaries/d11a7efd3be1063f7edf3ef5ab8c2478e579cfe149184a9b08fd4baa41d65e4e
crc32: E24BBAC8
md5: 7127dc292c7fd7e4bfea3eb859914230
sha1: be1d58b78e2f1877f002020eed95d5816fc201ce
sha256: d11a7efd3be1063f7edf3ef5ab8c2478e579cfe149184a9b08fd4baa41d65e4e
sha512: 38ae8275d8ce9818d55e8c9b5229ef1bab5c975a1e0cecc03edb7c9d2a46d7d03be041ccda4363448ffbd6e1378aee9dce63566f684d8f7e8a471dde1beb10f5
ssdeep: 196608:ctp6bqgtk/BmzpUTMIV++6gXzhJLMkh3IL2/H:c/RV+g9JbBISH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F876E012C641843AE49304B5947D476AA628BE311364A0C7F7CCBD6EA7F66E33D32B47
sha3_384: 1e1591fcd902d9ac444b4839b1a0d6aa3b9ab213ea595006e8e211fd81eb47b971756155d4e2956cec0cc360dc0d0ecd
ep_bytes: e814f00000e9000000006a1468b8146a
timestamp: 2024-02-19 07:08:56

Version Info:

Comments: https://warzsiam.in.th/
CompanyName: Codex Development Group
FileDescription: WarZ Siam MMO | Launcher
FileVersion: 0.0.1
InternalName: WarZ Siam MMO | Launcher.exe
LegalCopyright: (c) Codex Development Group. All rights reserved.
OriginalFilename: WarZ Siam MMO | Launcher.exe
ProductName: WarZ Siam MMO | Launcher
ProductVersion: 0.0.1
Translation: 0x0409 0x04e4

Doina.68904 also known as:

MicroWorld-eScanGen:Variant.Doina.68904
FireEyeGen:Variant.Doina.68904
SkyhighBehavesLike.Win32.Dropper.wc
McAfeeArtemis!7127DC292C7F
Cylanceunsafe
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
BitDefenderGen:Variant.Doina.68904
EmsisoftGen:Variant.Doina.68904 (B)
VIPREGen:Variant.Doina.68904
Trapminesuspicious.low.ml.score
Antiy-AVLGrayWare/Win32.Wacapew
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Doina.D10D28
GDataGen:Variant.Doina.68904
CynetMalicious (score: 100)
ALYacGen:Variant.Doina.68904
MAXmalware (ai score=86)
TrendMicro-HouseCallTROJ_GEN.R002H09BJ24
RisingTrojan.Generic@AI.90 (RDML:U75m/QAWJhJtiaUtCVw9NQ)
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove Doina.68904?

Doina.68904 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment