Malware

Doina.7905 removal instruction

Malware Removal

The Doina.7905 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.7905 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
data-link.s3.amazonaws.com

How to determine Doina.7905?


File Info:

crc32: 992DED9C
md5: 85017759285c4149c23b36860a18e0c2
name: 85017759285C4149C23B36860A18E0C2.mlw
sha1: 956d9ad5ea3db70dfac6d8ab4f2b5cd5957c79bc
sha256: 271b2f32ecc17dd19d1cef1a2184aa9d19763a229f9d1f59e3938bd89e98fc7e
sha512: 1d940595e121e7545fb22c2ff11d6d54c2645cc78eca0d229e2864c2c92735e0ae0fa54115d70fe1caaae9911ea2092caa82ae337061e796c6c11702429e59d5
ssdeep: 98304:qO/SVXejhfCiA4Iex1V6276eY8XT7rkjq:DQXeFfHA54V62FdXKq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Doina.7905 also known as:

CAT-QuickHealDownloader.Agent.20168
ALYacGen:Variant.Doina.7905
MalwarebytesTrojan.Downloader
ZillyaDownloader.Agent.Win32.301195
SangforTrojan.Win32.DropperX.gen
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Snojan.039a6f60
Cybereasonmalicious.9285c4
APEXMalicious
AvastWin32:DropperX-gen [Drp]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Snojan.bwyv
BitDefenderGen:Variant.Doina.7905
NANO-AntivirusTrojan.Win32.Agent.dtilwx
MicroWorld-eScanGen:Variant.Doina.7905
TencentWin32.Trojan.Snojan.Dxmf
ComodoMalware@#3c9e435ht3mtz
BitDefenderThetaGen:NN.ZexaF.34266.yuW@amUJayoi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PGL21
McAfee-GW-EditionBehavesLike.Win32.Injector.wc
FireEyeGen:Variant.Doina.7905
EmsisoftGen:Variant.Doina.7905 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Agent.eqlq
WebrootPua.Gen
AviraHEUR/AGEN.1129603
Antiy-AVLTrojan/Generic.ASMalwS.1181E7E
MicrosoftTrojan:Win32/Skeeyah.A!bit
GDataGen:Variant.Doina.7905
McAfeeArtemis!85017759285C
MAXmalware (ai score=100)
TrendMicro-HouseCallTROJ_GEN.R002C0PGL21
RisingTrojan.Generic@ML.84 (RDMK:jt4Un8hAazDU/fxcs9zkrA)
FortinetW32/Agent.WTLQ!tr
AVGWin32:DropperX-gen [Drp]

How to remove Doina.7905?

Doina.7905 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment