Malware

What is “Doina.69854”?

Malware Removal

The Doina.69854 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.69854 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Doina.69854?


File Info:

name: 75EC2DE8DD3D1BBCF2A9.mlw
path: /opt/CAPEv2/storage/binaries/7dfd58f219db1585804e23e066b1b840e6078ad7419c4c17058c53c4b84e8287
crc32: 5902B5E9
md5: 75ec2de8dd3d1bbcf2a96d6b1e11b202
sha1: 47161a0dca6e8716f71f29fe0bf3c6270d910065
sha256: 7dfd58f219db1585804e23e066b1b840e6078ad7419c4c17058c53c4b84e8287
sha512: 0680d3f6846054f90ca5eee1e4fd263e5ecc6872387ced400f6e646956fb85a113260a7a67b695a222a7497009c99220235bf42b8276b0350f63e35550b57cb3
ssdeep: 768:W0WswN3KO2omI7PP3lLuzZPKqocjIgapoRZ:U5N3KqmI7PP3lLuBZocFaK
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1FAE2B6597E444CFBDA10173994E6C77A2A7CF091C6234B62F650B7308B337E1219B26E
sha3_384: b923291d0e20b11cb780bde3c25d8ffd9c01c27f19b21c0f81b08bebccde547130eeb400851ff1a2c33909ab00957bc5
ep_bytes: 57565383ec108b5c24248b7424208b7c
timestamp: 2024-02-09 07:33:07

Version Info:

0: [No Data]

Doina.69854 also known as:

LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.69854
FireEyeGen:Variant.Doina.69854
SkyhighBehavesLike.Win32.Injector.nm
McAfeeRDN/Generic Dropper
SangforTrojan.Win32.Agent.Vbo7
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Generic.01e48b46
K7GWTrojan ( 005b1a3b1 )
K7AntiVirusTrojan ( 005b1a3b1 )
BitDefenderThetaAI:Packer.A271CAAA1E
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.DDZ
CynetMalicious (score: 99)
KasperskyTrojan-Dropper.Win32.Agent.tfscnn
BitDefenderGen:Variant.Doina.69854
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan-Dropper.Agent.Aujl
EmsisoftGen:Variant.Doina.69854 (B)
F-SecureTrojan.TR/Agent_AGen.htobb
VIPREGen:Variant.Doina.69854
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
GDataGen:Variant.Doina.69854
AviraTR/Agent_AGen.htobb
Antiy-AVLTrojan/Win32.Wacatac
KingsoftWin32.Troj.Undef.a
ArcabitTrojan.Doina.D110DE
ZoneAlarmTrojan-Dropper.Win32.Agent.tfscnn
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R634577
ALYacGen:Trojan.Heur.PT.c46@aGtnm1e
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H09BA24
RisingTrojan.Agent!8.B1E (TFE:5:m6lX4ciup7G)
FortinetW32/Agent_AGen.DDZ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Doina.69854?

Doina.69854 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment