Malware

Doina.70079 information

Malware Removal

The Doina.70079 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.70079 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Doina.70079?


File Info:

name: EFD7B34D914AB10B68A1.mlw
path: /opt/CAPEv2/storage/binaries/36f1c290c8db6caedb6b0c4419c7bb5952ded6b795522342f7372b4b485eef38
crc32: EDA42694
md5: efd7b34d914ab10b68a1ea69584c1d9f
sha1: 78c176ecf72ef5cebe20c94a220b8eb5f46cbde7
sha256: 36f1c290c8db6caedb6b0c4419c7bb5952ded6b795522342f7372b4b485eef38
sha512: 8a8918ae1239c93d7b496c2d0e9249d887e70bb652409af446c1ac0cca045df4ebe37de17c1324fefa41e45602542c0fad164d7034ad95e8a13fa96a64a5e80d
ssdeep: 384:hZQN9Fn1lhYwL+wC+7l06ki2OlBiEw6G54KFKjqfvGBkS+tWI:hZQ/FnhzJB/2+IEw6E4KFKcMkPj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5727E5B5A3D5113EB868DBE90C9E8135C78A7C3DEEE5487B42A87653E083403B8D63D
sha3_384: 99d006c6ffbfa874eb7e75aa9398cbb068799ab47a3accb9ebc91211d101157f66090fd5ac2760597dbf693cb94a7d72
ep_bytes: 60be007040008dbe00a0ffff57eb0b90
timestamp: 2024-03-07 20:37:27

Version Info:

0: [No Data]

Doina.70079 also known as:

LionicTrojan.Win32.ClipBanker.Z!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Doina.70079
FireEyeGen:Variant.Doina.70079
SkyhighArtemis!Trojan
McAfeeArtemis!EFD7B34D914A
Cylanceunsafe
Cybereasonmalicious.d914ab
SymantecDownloader.Upatre
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0XC724
KasperskyTrojan-Banker.Win32.ClipBanker.abbj
BitDefenderGen:Variant.Doina.70079
AvastWin32:MalwareX-gen [Trj]
EmsisoftGen:Variant.Doina.70079 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Doina.70079
TrendMicroTROJ_GEN.R002C0XC724
SophosMal/Generic-S
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Doina.D111BF
GDataWin32.Trojan-Downloader.Generic.4XUT99
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5598593
ALYacGen:Variant.Doina.70079
MAXmalware (ai score=80)
VBA32BScope.Worm.Propriex
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
RisingTrojan.Generic@AI.90 (RDML:jInXNRO7TnSSjdd4Sh+jOw)
FortinetW32/PossibleThreat
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Doina.70079?

Doina.70079 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment