Malware

How to remove “Doina.9154”?

Malware Removal

The Doina.9154 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.9154 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a slightly modified copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

citrix.vipreclod.com

How to determine Doina.9154?


File Info:

crc32: BAB97F16
md5: eb8e2d67cde387d87a3d78a52a477fb4
name: EB8E2D67CDE387D87A3D78A52A477FB4.mlw
sha1: 4138900c2fd72ddfa8fbeedb74bdc460d9a3a42b
sha256: a2e5236b9facabd44e2291c6fe7289a1022f1a461db2894c99e3fc91c51e5c24
sha512: d085267cbfdb096391e5d80353fa08ca9d448e225ce3505f0cd1fb5c45728a7c4495c537d079e8c894baaa94ab07f5e22a2cc7430dc42b870e4da37de0ac32c0
ssdeep: 1536:iZioIoCwbYP4nuEApQK4TQbtY2gA9DX+ytBO8c3G3eTJ/k:iEoIlwIguEA4c5DgA9DOyq0eFs
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Doina.9154 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.19306
ClamAVWin.Malware.Scar-6745903-0
ALYacGen:Variant.Doina.9154
CylanceUnsafe
ZillyaTrojan.Scar.Win32.132835
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0054e5911 )
K7AntiVirusTrojan ( 0054e5911 )
BaiduWin32.Trojan.Shyape.a
CyrenW32/Shyape.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Shyape.G
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.okdf
BitDefenderGen:Variant.Doina.9154
MicroWorld-eScanGen:Variant.Doina.9154
TencentMalware.Win32.Gencirc.10b0cbc6
Ad-AwareGen:Variant.Doina.9154
SophosML/PE-A
ComodoTrojWare.Win32.Shyape.Z@83gos3
BitDefenderThetaAI:Packer.520FA13D1E
TrendMicroBKDR_DIOFOPI.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.eb8e2d67cde387d8
EmsisoftGen:Variant.Doina.9154 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.aregn
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.29197C
MicrosoftTrojan:Win32/Sakurel.B!dha
GridinsoftTrojan.Win32.Agent.oa!s1
ArcabitTrojan.Doina.D23C2
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Doina.9154
TACHYONTrojan/W32.Agent.59392.AIN
AhnLab-V3Trojan/RL.Scar.R257359
Acronissuspicious
McAfeeTrojan-FRKD!29BEDF21EB1A
MAXmalware (ai score=81)
VBA32Trojan.Scar
MalwarebytesMalware.AI.2234501969
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_DIOFOPI.SM
RisingTrojan.Shyape!1.A74F (CLASSIC)
YandexTrojan.GenAsa!+L+LGuwwhOg
IkarusTrojan.Win32.Shyape
MaxSecureTrojan.Malware.11657011.susgen
FortinetW32/Shyape.Z!tr
AVGWin32:Trojan-gen

How to remove Doina.9154?

Doina.9154 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment