Trojan

Trojan:Win32/Doina!pz information

Malware Removal

The Trojan:Win32/Doina!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Doina!pz virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Doina!pz?


File Info:

name: 61130D225309A20F525D.mlw
path: /opt/CAPEv2/storage/binaries/4306893efa66b518eb6573e48d5ef85497c7772c735d3853bd6adc221a92021e
crc32: 77142E2B
md5: 61130d225309a20f525dd5838d0868af
sha1: 71f2660bc190f5e35da1675dc3b348ecc207f366
sha256: 4306893efa66b518eb6573e48d5ef85497c7772c735d3853bd6adc221a92021e
sha512: 46d3d9214328cf2efb61daa560f56820bb34db4a958bcd35ea0ebdbed80fcaff7663468ee93dd84268ee3a64cf710d7a5ea7a93417683ee99cf2f8ecec46bf4d
ssdeep: 3072:mYUb5QoJ4g+eClQifQEBa9Wj5hJG2+lzwRpl2ntchvZj6Iz1ZdW4SUF/ftA:mYkClQ6QE+W/7ofnyhvh6SZI4ZF/K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1986461562F8CE230DE70067F2CA916F9AED14BE9A22279C1D794D02F08DFB1415EF1A5
sha3_384: 1a1b24e170dbd4956a16e0aaf3fa0621626a13c332ee6084cd1c2e62fa41337ae4327852789cb1c4e3f4625aa1cf08f9
ep_bytes: 6a00e821010100a3bc514100e81d0101
timestamp: 2004-02-24 23:04:52

Version Info:

0: [No Data]

Trojan:Win32/Doina!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.304514EE.A.EF667890
CAT-QuickHealBackdoor.SmallPMF.S30169989
SkyhighBehavesLike.Win32.Generic.fm
McAfeeGenericRXVQ-ZN!61130D225309
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Dacic.304514EE.A.EF667890
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 000002c61 )
BitDefenderGeneric.Dacic.304514EE.A.EF667890
K7GWTrojan ( 000002c61 )
Cybereasonmalicious.bc190f
VirITTrojan.Win32.Click.DWD
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent.UY
APEXMalicious
ClamAVWin.Trojan.Fugrafa-9733007-0
KasperskyBackdoor.Win32.Small.ml
NANO-AntivirusTrojan.Win32.Click.gacxgj
ViRobotBackdoor.Win32.A.Small.80896
RisingBackdoor.Small.hol (CLASSIC)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Click.2603
ZillyaBackdoor.Small.Win32.11061
TrendMicroTROJ_GEN.R03BC0CK823
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.61130d225309a20f
EmsisoftGeneric.Dacic.304514EE.A.EF667890 (B)
IkarusBackdoor.Small
JiangminBackdoor.Small.ix
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Agent.IRHR-2426
Antiy-AVLTrojan[Backdoor]/Win32.Small
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Doina!pz
XcitiumTrojWare.Win32.Agent.ve@4yoq0p
ArcabitGeneric.Dacic.304514EE.A.EF667890
ZoneAlarmBackdoor.Win32.Small.ml
GDataWin32.Trojan.PSE.1620HTT
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.Small.C5521751
BitDefenderThetaAI:Packer.0DC7BCDF1D
ALYacGeneric.Dacic.304514EE.A.EF667890
MAXmalware (ai score=81)
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.Small
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0CK823
TencentBackdoor.Win32.Small.kc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.U!tr
AVGWin32:Downloader-TH [Trj]
AvastWin32:Downloader-TH [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Doina!pz?

Trojan:Win32/Doina!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment