Malware

Doina.7693 removal instruction

Malware Removal

The Doina.7693 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.7693 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Anomalous binary characteristics

How to determine Doina.7693?


File Info:

name: FAFCCF624983635977CB.mlw
path: /opt/CAPEv2/storage/binaries/40f90f146233d0a1764e2f3d10f5e7955aaf371d523d87eb72975bb429a959cf
crc32: CB1C95B9
md5: fafccf624983635977cb1c6ee1a8c980
sha1: 04e02248545f7a6411b4d6174017db83ae7774e4
sha256: 40f90f146233d0a1764e2f3d10f5e7955aaf371d523d87eb72975bb429a959cf
sha512: 1737d1f618c0c03b479b3573753233c469d387c9d868d3e81b982b5e744dc3e1440b021163d33de25a925104e5e9bb0fb16598fe664d19e85120f1f56cf8e54c
ssdeep: 12288:ygUX/3mGwAQepHBGYHXfV9FJjGkjXhC/9wnojY6HJyFK0vSnBk+ICKjjPH6yXtxj:yNPW0rvLFJhg9ZU0JqSO/CayuIi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152258D22F2E18837C5B72A389C5BA794992ABD142E385C4A3FF41D4C4F396417D352EB
sha3_384: 72711d5e416f65c454486eadb8fa4ff4ce272365be29deccb280bfcd2b825babbc2366e9eb3498d83700cc5036eb35a1
ep_bytes: 558bec83c4e053565733c08945e08945
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Doina.7693 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop2.61767
MicroWorld-eScanGen:Variant.Doina.7693
FireEyeGeneric.mg.fafccf6249836359
McAfeeGenericR-DXE!FAFCCF624983
CylanceUnsafe
ZillyaTrojan.Cossta.Win32.3360
AlibabaTrojan:Win32/Runner.69f4fe3b
Cybereasonmalicious.249836
BitDefenderThetaAI:Packer.F7E4FE1425
CyrenW32/A-e27b6041!Eldorado
ESET-NOD32a variant of Win32/Runner.NCG
TrendMicro-HouseCallTROJ_AGENT_042989.TOMB
Paloaltogeneric.ml
ClamAVWin.Trojan.Cossta-16
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Doina.7693
NANO-AntivirusTrojan.Win32.Cossta.dmjwv
AvastWin32:Trojan-gen
RisingTrojan.Win32.Fednu.axx (CLASSIC)
Ad-AwareGen:Variant.Doina.7693
ComodoTrojWare.Win32.Cossta.~AF@38wf23
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_AGENT_042989.TOMB
McAfee-GW-EditionGenericR-DXE!FAFCCF624983
EmsisoftGen:Variant.Doina.7693 (B)
GDataGen:Variant.Doina.7693
JiangminTrojan/Cossta.cmr
AviraDR/Delphi.Gen5
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.5BD8D
ArcabitTrojan.Doina.D1E0D
ViRobotTrojan.Win32.A.Cossta.995456.CX
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Cossta.R5644
ALYacGen:Variant.Doina.7693
VBA32Trojan.Cossta
APEXMalicious
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!m0nPtRnlLrg
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Cossta.NAD!tr
WebrootW32.Malware.Gen
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen

How to remove Doina.7693?

Doina.7693 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment