Categories: Malware

Doris.5025 malicious file

The Doris.5025 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doris.5025 virus can do?

  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

propellero.com
googlestats.ru
alexastats.ru
profeller.com
google-ana1itics.com
searchmachiner.com
edgedl.me.gvt1.com

How to determine Doris.5025?


File Info:

crc32: D0AB8A70md5: 10c306a3511c823ffeec95d83d330711name: 10C306A3511C823FFEEC95D83D330711.mlwsha1: c750fb506a8761df3794afdb8ae7e904d9c7ddb6sha256: 4be67b79db06cfec129797fceb16c8bcc32c03f47de0391630b518522b24a5b4sha512: 65b88accb93a52f453cfc1b5b5ffb0b6d62c8a126e2e74f72132bcd2398ec4aa9befef3f043a2d6e8871321c42b23f9b662c577d15d54cfdc456347c621aa400ssdeep: 1536:9+e4nYIZH53AAGY+4fN+rDcF4jPQddIYode1L91:9+e4HAAGYDfYr4yjPQQQxtype: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Doris.5025 also known as:

K7AntiVirus Trojan ( 0006051b1 )
Lionic Trojan.Win32.Agent.a!c
Elastic malicious (high confidence)
DrWeb Trojan.Suslik
Cynet Malicious (score: 100)
CAT-QuickHeal Trojan.MauvaiseRI.S5265240
ALYac Trojan.VXGame
Cylance Unsafe
Zillya Backdoor.Bandok.Win32.77
Sangfor Trojan.Win32.Heur.RP
Alibaba TrojanDownloader:Win32/Qhost.70d8668b
K7GW Trojan ( 0006051b1 )
Cybereason malicious.3511c8
Cyren W32/Backdoor.CXIN-8599
Symantec Trojan.Adclicker
ESET-NOD32 a variant of Win32/Qhost.OAQ
APEX Malicious
Avast FileRepMalware
Kaspersky Trojan-Downloader.Win32.Agent.aozb
BitDefender Gen:Variant.Doris.5025
NANO-Antivirus Trojan.Win32.Bandok.qxrf
ViRobot Trojan.Win32.A.Downloader.66048.DR[UPX]
MicroWorld-eScan Gen:Variant.Doris.5025
Tencent Win32.Trojan-Downloader.Agent.gjb
Ad-Aware Gen:Variant.Doris.5025
Sophos Mal/Behav-104
Comodo Backdoor@#19ixuxlo3pzrm
BitDefenderTheta AI:Packer.09AB87D81E
VIPRE Trojan.Vxgame.z
TrendMicro BKDR_BANDOK.SM
McAfee-GW-Edition BehavesLike.Win32.Generic.kc
FireEye Generic.mg.10c306a3511c823f
Emsisoft Gen:Variant.Doris.5025 (B)
SentinelOne Static AI – Suspicious PE
Jiangmin Backdoor/Bandok.ge
Webroot TrojanProxy:Win32/Dosenjo.A
Avira BDS/Backdoor.Gen
Antiy-AVL Trojan/Generic.ASMalwS.10389D8
Microsoft PWS:Win32/Zbot!ml
GData Gen:Variant.Doris.5025
AhnLab-V3 Trojan/Win32.Agent.C129348
McAfee generic!bg.ftt
MAX malware (ai score=100)
VBA32 TrojanDownloader.Agent
Panda Bck/Bandok.AY
TrendMicro-HouseCall BKDR_BANDOK.SM
Rising Trojan.Win32.Undef.rnb (CLASSIC)
Yandex Trojan.GenAsa!jFKJt3lOEnU
Ikarus Backdoor.Win32.Bandok
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Generic.AP.171F650!tr
AVG FileRepMalware
Qihoo-360 Win32/Backdoor.Bandook.HwsBOAMA

How to remove Doris.5025?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Win32/StartPage.OUR information

The Win32/StartPage.OUR is considered dangerous by lots of security experts. When this infection is active,…

16 mins ago

How to remove “Trojan.Generic.33997309”?

The Trojan.Generic.33997309 is considered dangerous by lots of security experts. When this infection is active,…

32 mins ago

Cerbu.190164 (file analysis)

The Cerbu.190164 is considered dangerous by lots of security experts. When this infection is active,…

59 mins ago

Win32/Adware.Adposhel.AR information

The Win32/Adware.Adposhel.AR is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Trojan.Generic.35266640 malicious file

The Trojan.Generic.35266640 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Should I remove “TrojanDownloader:Win32/Beebone.AC”?

The TrojanDownloader:Win32/Beebone.AC is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago