Malware

Doina.8580 (file analysis)

Malware Removal

The Doina.8580 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.8580 virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Finnish
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Doina.8580?


File Info:

crc32: 032F85AA
md5: 48e5d48b185c125eed30ca0b57f8621c
name: 48E5D48B185C125EED30CA0B57F8621C.mlw
sha1: edf3e5e1520cdcd260a3e111273faf4e6253ac2e
sha256: 763ed6695c6692bd857d4f712036c7d4fd8c52b20e9de8693760a99cf73329d4
sha512: f0a3c56c0b3be47c571dcb1e7228fd1afb4297f41c0988d0781691fa67996f36e81569575391f4ba6d2f3763358d146c0a17c2cffa7b1e126ef5c89c9521676a
ssdeep: 49152:LC1oz15m7hPJF4IHN+X3RGILeh/rZK24HiI8qJ+KE+dEnnPv/0xC2Dt:Jz15m7h0CNgRHLehAP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright by TypingMaster Finland Inc.
InternalName:
FileVersion: 6.2.0.393
CompanyName: TypingMaster Inc
LegalTrademarks:
Comments:
ProductName: TypingMaster 2002
ProductVersion: 6.2
FileDescription: TypingMaster Tutor
OriginalFilename:
Translation: 0x0409 0x04e4

Doina.8580 also known as:

DrWebWin32.WowSub.4
CAT-QuickHealTrojanDropper.Jadtre.B7
ALYacGen:Variant.Doina.8580
CylanceUnsafe
K7GWP2PWorm ( 004c69cd1 )
Cybereasonmalicious.b185c1
BaiduWin32.Virus.Wapomi.a
CyrenW32/Risk.MODP-1101
SymantecW32.Fujacks.CE!inf
ESET-NOD32Win32/AutoRun.AntiAV.T
APEXMalicious
AvastWin32:AutoRun-BFB [Trj]
ClamAVWin.Worm.Allaple-221772
KasperskyTrojan-Dropper.Win32.Bototer.bff
BitDefenderGen:Variant.Doina.8580
MicroWorld-eScanGen:Variant.Doina.8580
TencentTrojan.Win32.Downloader.aav
Ad-AwareGen:Variant.Doina.8580
SophosMal/Jadtre-C
BitDefenderThetaGen:NN.ZexaF.34294.pCW@ayk7XDhb
VIPRETrojan.Win32.Generic!BT
TrendMicroPE_DOWN.A-O
McAfee-GW-EditionW32/Fujacks.cm
FireEyeGeneric.mg.48e5d48b185c125e
EmsisoftGen:Variant.Doina.8580 (B)
SentinelOneStatic AI – Malicious PE
JiangminHeur:TrojanDownloader.Agent
AviraTR/Agent.fyee.8
eGambitTrojan.Generic
KingsoftHeur.SSC.1960518.1216.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Doina.8580 (2x)
McAfeeArtemis!48E5D48B185C
MAXmalware (ai score=89)
VBA32BScope.Trojan.SvcHorse.01643
MalwarebytesMalware.AI.2319565596
TrendMicro-HouseCallPE_DOWN.A-O
YandexTrojan.GenAsa!Ju64OpijAdY
IkarusRootkit.Win32.Agent
MaxSecureVirus.W32.Bototer.A
FortinetW32/Wapomi.AO
AVGWin32:AutoRun-BFB [Trj]

How to remove Doina.8580?

Doina.8580 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment