Malware

About “Doina.7082” infection

Malware Removal

The Doina.7082 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.7082 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

Related domains:

hoh.adoptioncla.bid
grill.glyceraceousfive.bid

How to determine Doina.7082?


File Info:

crc32: 9651C632
md5: 65d1598f8b1854233cf3b9faae76b542
name: 65D1598F8B1854233CF3B9FAAE76B542.mlw
sha1: 902d30ab6c2dbb1c441358b36f0180cc053681fe
sha256: 1a58694d24dee5b399841c80f4a5ec21005264c4419f0d959e4abb051fef36af
sha512: 8e4fe717ae2dd2b08f86793bc16b04c6e310626124399cd2058acd6ab51e9cdd21d0ab65e1580501e3f5e5cf44f2042f19c82d38cb5866ffd4ed23fb170781e2
ssdeep: 98304:GzlkbFDVrQMyOr3S3d6cLhs7vy9Jeu6XaiKaxQodm:EeVUKSN6c1sG9JMnnm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Setup Engine Copyright xa9 2004-2015 Indigo Rose Corporation
InternalName: suf_launch
FileVersion: 9.5.0.0
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
Comments: Created with Setup Factory
ProductName: Setup Factory Runtime
ProductVersion: 9.5.0.0
FileDescription: Setup Application
OriginalFilename: suf_launch.exe
Translation: 0x0409 0x04e4

Doina.7082 also known as:

LionicAdware.Win32.StartSurf.2!c
DrWebTrojan.Vittalia.13032
ALYacGen:Variant.Doina.7082
CylanceUnsafe
SangforTrojan.Win32.Indiloadz.8
AlibabaAdWare:Win32/StartSurf.4399bfd4
Cybereasonmalicious.f8b185
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.StartSurf.mor
BitDefenderGen:Variant.Doina.7082
NANO-AntivirusRiskware.Win32.StartSurf.epnbsp
MicroWorld-eScanGen:Variant.Doina.7082
TencentWin32.Trojan.Multiple.Wqmz
Ad-AwareGen:Variant.Doina.7082
SophosGeneric ML PUA (PUA)
VIPREAdware.Win32.StartSurf
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGen:Variant.Doina.7082
EmsisoftGen:Variant.Doina.7082 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.StartSurf.m.(kcloud)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Doina.D1BAA
GDataGen:Variant.Doina.7082
McAfeeArtemis!65D1598F8B18
MAXmalware (ai score=100)
VBA32AdWare.StartSurf
PandaTrj/CI.A
IkarusTrojan-Dropper.LUA.Agent
FortinetAdware/StartSurf
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Doina.7082?

Doina.7082 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment