Malware

Doina.9768 removal instruction

Malware Removal

The Doina.9768 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.9768 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Doina.9768?


File Info:

name: 0CFA124A5FF7454C316B.mlw
path: /opt/CAPEv2/storage/binaries/aa82761b6ce0fa2ca8d4af53981bc0bba2b73a63bd80c064d203a9a21ffacea5
crc32: A2537DDF
md5: 0cfa124a5ff7454c316baf5d62221710
sha1: ff5218999ac984567551637e98d75c342c8aceb1
sha256: aa82761b6ce0fa2ca8d4af53981bc0bba2b73a63bd80c064d203a9a21ffacea5
sha512: 3d27c27214caaa35381543c19e37b70bcdf8a8cf7c4c81a3a6c169b91ed1e1ccda290effba8420cab58ae7ca7c65b6a0f15e79d42490d847adb74ab7e5add138
ssdeep: 3072:QEGbeS0hj8xtTRhM+J/ME2QFgBuxp/dQQR3tG888FAPXXS:QEGbo8xpME/2QAq/FR48EPXXS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19794F20653AF18E5C9EBCB30FBBB03C62113C06542BAC51B265F5C2C8EA577449BD5AB
sha3_384: 352a8c736a91ddd63470721dca7762b4b2953357469c906d7e5868e00aa0a24f4e95a11b88eb172d42fc2b1fc347bf97
ep_bytes: b83cd24400ffe0ffadf56eb8fe3aaad9
timestamp: 2012-01-14 14:12:20

Version Info:

Comments:
CompanyName: Shenzhen QVOD Technology Co.,Ltd
FileDescription: QvodInstall Module
FileVersion: 4, 0, 4, 6
InternalName: QvodInstall.exe
LegalCopyright: Copyright(C) 2006-2012 QVOD
LegalTrademarks:
OriginalFilename: QvodInstall.exe
PrivateBuild:
ProductName: QvodInstall Module
ProductVersion: 4, 0, 4, 6
SpecialBuild:
Translation: 0x0409 0x0000

Doina.9768 also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.DownLoader5.35840
MicroWorld-eScanGen:Variant.Doina.9768
FireEyeGeneric.mg.0cfa124a5ff7454c
CAT-QuickHealTrojan.Rimod.A.mue
ALYacGen:Variant.Doina.9768
CylanceUnsafe
ZillyaDropper.Agent.Win32.103552
K7AntiVirusTrojan ( 005203381 )
K7GWTrojan ( 005203381 )
Cybereasonmalicious.a5ff74
BitDefenderThetaGen:NN.ZexaF.34646.zi3fa4A20Zfb
VirITTrojan.Win32.Generic.BPJS
CyrenW32/KillAV.BC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDropper.Agent.PRE
APEXMalicious
ClamAVWin.Trojan.Agent-441594
KasperskyTrojan-Dropper.Win32.Agent.bjtpya
BitDefenderGen:Variant.Doina.9768
NANO-AntivirusTrojan.Win32.Rimod.crgjki
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Qvod.kal
Ad-AwareGen:Variant.Doina.9768
EmsisoftGen:Variant.Doina.9768 (B)
ComodoTrojWare.Win32.Rimod.aj@4tvs05
BaiduWin32.Trojan-Dropper.Agent.s
VIPREGen:Variant.Doina.9768
TrendMicroTROJ_AGENT_029534.TOMB
McAfee-GW-EditionBehavesLike.Win32.Generic.gz
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Doina.9768
JiangminTrojan/Generic.acmsr
WebrootW32.Downloader.Gen
GoogleDetected
AviraTR/Rimod.AJ.1
MAXmalware (ai score=81)
ArcabitTrojan.Doina.D2628
ViRobotTrojan.Win32.A.Downloader.620832.C
ZoneAlarmTrojan-Dropper.Win32.Agent.bjtpya
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Downloader.R20670
Acronissuspicious
McAfeeGenDownloader.oj
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTROJ_AGENT_029534.TOMB
RisingTrojan.DL.Win32.AVPlayer.a (CLASSIC)
YandexTrojan.DR.Agent!6qCEAingtPk
IkarusTrojan-PWS.Banker6
FortinetW32/TrojanDownloader.PRE!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Doina.9768?

Doina.9768 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment