Malware

Doina.7094 (B) removal instruction

Malware Removal

The Doina.7094 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.7094 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Collects and encrypts information about the computer likely to send to C2 server
  • Checks for the presence of known devices from debuggers and forensic tools
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

How to determine Doina.7094 (B)?


File Info:

name: 4041DC6B0517815F407A.mlw
path: /opt/CAPEv2/storage/binaries/8a0c5dc9b6f2dd0b4796c158a08c63ca9c2a2c202439b88ab363b169ce2820c7
crc32: A8D89163
md5: 4041dc6b0517815f407aa964024206ac
sha1: 2b9ed5262d79e78744c0259f56bd39c14fedf09d
sha256: 8a0c5dc9b6f2dd0b4796c158a08c63ca9c2a2c202439b88ab363b169ce2820c7
sha512: 64480ad2b4893f82e342fb166a4f5f5f2415ebbbc44683e1d214b22126d11d1bd1682a8b1d0b16b94d036246e95c1089b7d36197b2210fefe119945a2a2766f6
ssdeep: 12288:LDXCmq00+G46hzoyi+41E83WBBP/hefGILA6+rUTK6h8BnNuWqemtXMmWQV:iz+1IDy1E83WBBP/hef5BFTK6yNgtcH
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T146D48D363882C07AD6B201714DADFBA591BFB8254F3205DB67D42B2F4B216E16F31972
sha3_384: b7fa6616c028dece4281a98434b484c9a3eb2586657c29e633ae331db82e85fd048287c549a470531c6f7ede3bbb20ce
ep_bytes: e8ca070000e974feffff8b4df464890d
timestamp: 2021-02-14 23:14:12

Version Info:

0: [No Data]

Doina.7094 (B) also known as:

LionicTrojan.Win32.Bulz.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.7094
CAT-QuickHealTrojan.Agent
ALYacGen:Variant.Doina.7094
BitDefenderThetaGen:NN.ZexaF.34084.LuW@a8R0KPhi
CyrenW32/Ransom.OZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H0CII21
Paloaltogeneric.ml
BitDefenderGen:Variant.Doina.7094
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Doina.7094
EmsisoftGen:Variant.Doina.7094 (B)
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.4041dc6b0517815f
IkarusTrojan.AvaddonRansom
JiangminTrojan.Agentb.jbh
WebrootW32.Trojan.D8
AviraHEUR/AGEN.1139980
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Doina.D1BB6
GDataGen:Variant.Doina.7094
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Reputation.C4406072
McAfeeArtemis!4041DC6B0517
CylanceUnsafe
APEXMalicious
RisingTrojan.Generic@ML.88 (RDML:h3lKGcysLoW31cZ/1nXENw)
YandexTrojan.AD!fJn4CktwfV8
MAXmalware (ai score=89)
MaxSecureTrojan.Malware.114475974.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.b05178
PandaTrj/GdSda.A

How to remove Doina.7094 (B)?

Doina.7094 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment