Malware

Doina.8776 (B) removal

Malware Removal

The Doina.8776 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.8776 (B) virus can do?

  • At least one process apparently crashed during execution
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Doina.8776 (B)?


File Info:

name: ED970744FB54B24E04B0.mlw
path: /opt/CAPEv2/storage/binaries/5c352e80e1ec69dc7aa112847848006aa2bcea9849c7bc9788605aa7861928df
crc32: BD9B33D5
md5: ed970744fb54b24e04b04b380c4403b8
sha1: 212294af47b6de13f9227d8bd20e137490dc44db
sha256: 5c352e80e1ec69dc7aa112847848006aa2bcea9849c7bc9788605aa7861928df
sha512: 05f49ca49b6cdb3ffb5968cba87bddf75958d5f845237666097638719ada83223f0d4b94bf5193b17d485a738f299427cc9379879d61281e1476234d42c24440
ssdeep: 24576:OjIeXuJE4+v4/Nq0Cl0N00MOvhPTCFb62E9JosLo:OjI0uJEll0N0SvhPeFb62Qmc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12F2523026AE98277D0B82B30ABFA475B37347C6A1C789B3E27C076560D376566137327
sha3_384: a332cb865b42bf62d1b733196862dd8ebf8d8d20245e30d1585fc1ecc3414c8e149e203644455be62973f77eb3a22f93
ep_bytes: 558bec83ec4456ff155c1100018bf08a
timestamp: 2003-03-25 07:08:18

Version Info:

CompanyName: eToro
FileDescription: Empty.exe
FileVersion: 1.0
InternalName: Empty.exe
LegalCopyright: Copyright © eToro
OriginalFilename: Empty.exe
ProductName: Empty.exe
ProductVersion: 1.0
Translation: 0x0409 0x04b0

Doina.8776 (B) also known as:

LionicTrojan.Win32.Generic.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.8776
FireEyeGeneric.mg.ed970744fb54b24e
McAfeeGeneric.bmm
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4fb54b
VirITBackdoor.Win32.Generic16.AQSQ
CyrenW32/Trojan.PJOG-1384
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Doina.8776
AvastWin32:Agent-AUNA [Trj]
TencentMalware.Win32.Gencirc.114c3a02
TACHYONTrojan/W32.Agent.1042944.B
EmsisoftGen:Variant.Doina.8776 (B)
ComodoTrojWare.Win32.TrojanClicker.AutoIt.~d002@1p6tm4
VIPRETrojan.Win32.Vundo
McAfee-GW-EditionGeneric.bmm
SophosGeneric ML PUA (PUA)
JiangminTrojan/Vundo.cxr
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2BAB92A
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Doina.8776
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34182.5uW@aylpLWli
ALYacGen:Variant.Doina.8776
MAXmalware (ai score=81)
VBA32TrojanDownloader.Genome
MalwarebytesMalware.AI.525136363
RisingDownloader.Genome!8.142 (RDMK:cmRtazpeh5xQa7F85nCJ7k2666ya)
YandexTrojan.GenAsa!c5zmQyDUo74
FortinetAdware/AutoIt
AVGWin32:Agent-AUNA [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Doina.8776 (B)?

Doina.8776 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment