Trojan

Should I remove “Trojan:Win32/Doina!pz”?

Malware Removal

The Trojan:Win32/Doina!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Doina!pz virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Doina!pz?


File Info:

name: 5645079B623FF49A4148.mlw
path: /opt/CAPEv2/storage/binaries/677fda78d9d45d28a2799565b4c3af8eacfb472f0648b19ff8b0e1c7f2b31826
crc32: 79E341E1
md5: 5645079b623ff49a41482b3ed6da8c23
sha1: 4b0464ac1f6d1b4d89cf841755560ae3e8477dc5
sha256: 677fda78d9d45d28a2799565b4c3af8eacfb472f0648b19ff8b0e1c7f2b31826
sha512: 09b8f1f8097bee0cc589d1175cf31d5d1461a98f80f594365c86fd2c85243a40c9c2c86743ff47b94665019fcb35c569d3b27b0731d4b7c2a6faa6ca5735e270
ssdeep: 3072:mYUb5QoJ4g+eClQifQEBa9Wj5hJG2+lzwRpl2ntchvZj6Iz1ZdW4SUF/ft1:mYkClQ6QE+W/7ofnyhvh6SZI4ZF/n
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1466461562F8CE230DE70067F2CA916F9AED14BE9A22279C1D794D02F08DFB1415EF1A5
sha3_384: 061286e47ed59e04d9d831992b2687d98209e48690f128c06af46830146af861e52085878f61c14ef208de0135117afb
ep_bytes: 6a00e821010100a3bc514100e81d0101
timestamp: 2004-02-24 23:04:52

Version Info:

0: [No Data]

Trojan:Win32/Doina!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Small.tpRp
Elasticmalicious (high confidence)
DrWebTrojan.Click.2603
MicroWorld-eScanGeneric.Dacic.304514EE.A.EF667890
CAT-QuickHealBackdoor.SmallPMF.S30169989
SkyhighBehavesLike.Win32.Generic.fm
McAfeeGenericRXVQ-ZN!5645079B623F
MalwarebytesGeneric.Malware.AI.DDS
ZillyaBackdoor.Small.Win32.11061
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 000002c61 )
BitDefenderGeneric.Dacic.304514EE.A.EF667890
K7GWTrojan ( 000002c61 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.0DC7BCDF1D
VirITTrojan.Win32.Click.DWD
SymantecDownloader
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent.UY
APEXMalicious
ClamAVWin.Trojan.Fugrafa-9733007-0
KasperskyBackdoor.Win32.Small.ml
NANO-AntivirusTrojan.Win32.Click.gacxgj
ViRobotBackdoor.Win32.A.Small.80896
RisingBackdoor.Small.hol (CLASSIC)
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
VIPREGeneric.Dacic.304514EE.A.EF667890
TrendMicroTROJ_GEN.R002C0CK923
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.5645079b623ff49a
EmsisoftGeneric.Dacic.304514EE.A.EF667890 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
JiangminBackdoor.Small.ix
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Agent.IRHR-2426
Antiy-AVLTrojan[Backdoor]/Win32.Small
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Doina!pz
GridinsoftTrojan.Win32.Agent.oa!s1
XcitiumTrojWare.Win32.Agent.ve@4yoq0p
ArcabitGeneric.Dacic.304514EE.A.EF667890
ZoneAlarmBackdoor.Win32.Small.ml
GDataWin32.Trojan.PSE.1620HTT
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.Small.C5521751
VBA32BScope.Backdoor.Small
ALYacGeneric.Dacic.304514EE.A.EF667890
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0CK923
TencentBackdoor.Win32.Small.kc
YandexBackdoor.Small!99FHPvIIWrA
IkarusBackdoor.Small
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.U!tr
AVGWin32:Downloader-TH [Trj]
Cybereasonmalicious.c1f6d1
AvastWin32:Downloader-TH [Trj]

How to remove Trojan:Win32/Doina!pz?

Trojan:Win32/Doina!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment