Malware

About “Doina.72” infection

Malware Removal

The Doina.72 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.72 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Doina.72?


File Info:

crc32: E4F16943
md5: 7c4c3a12f367dcd154accce5948ebaeb
name: 7C4C3A12F367DCD154ACCCE5948EBAEB.mlw
sha1: b0a7b80ddd9b86a20d3a41e3423cedb341b6220c
sha256: 1a1e74fbe89bed37913351432c163e204018655e51811aabb9e5fc6a06cf5887
sha512: 3309ff4fa38aca1d791683f80de67ed2ab720dab034dcb997e9985623eb57f350959ea2ae5bd542f118b703793630a6002b38356716819ef9c28b0ce704dc5a4
ssdeep: 12288:cqOdWKrdSUiJruF2ahX/gjTCSxJMbAbYTqLqPqxG9sCQPb45Yxsy:cZYA2W2QX/cTfw0sTOq/9sPbLxsy
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Doina.72 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.AutoIt.1000
Qihoo-360Win32/Trojan.Injuke.HyoD4yoA
McAfeeRDN/Generic.cf
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Doina.72
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ddd9b8
ArcabitTrojan.Doina.72
CyrenW32/Trojan.XUKQ-5504
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Injuke.dnhw
MicroWorld-eScanGen:Variant.Doina.72
Ad-AwareGen:Variant.Doina.72
SophosML/PE-A
ComodoMalware@#1bg6ggchungos
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.bc
FireEyeGeneric.mg.7c4c3a12f367dcd1
EmsisoftGen:Variant.Doina.72 (B)
IkarusTrojan.Autoit
WebrootW32.Trojan.Gen
KingsoftWin32.Troj.Injuke.dn.(kcloud)
GridinsoftAdware.Win32.Adload.oa!s1
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Injuke.dnhw
GDataWin32.Malware.CredStealer.YEU5PP@gen
MAXmalware (ai score=86)
APEXMalicious
ESET-NOD32a variant of Generik.FGOCVKK
SentinelOneStatic AI – Suspicious PE
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Doina.72?

Doina.72 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment