Trojan

About “Trojan:Win32/Doina!pz” infection

Malware Removal

The Trojan:Win32/Doina!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Doina!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Doina!pz?


File Info:

name: 78C2DCD937DD90E4FF4C.mlw
path: /opt/CAPEv2/storage/binaries/c086bffeb42eb427f0483a770d5ac81d0a318152a1d13ae9093fd751a2390c2e
crc32: 7D59C60B
md5: 78c2dcd937dd90e4ff4c0f5fec09a44e
sha1: 2234ab4657ed0db3285cb9cb3e35ae736b7d8ef4
sha256: c086bffeb42eb427f0483a770d5ac81d0a318152a1d13ae9093fd751a2390c2e
sha512: 0b9387c9b42c826915db0c28264e09f8f85d5c6578bd0bb1d8c4fc7dd2f1becd0c4e2644214a9143eddf178537255e954c9888f690c1eeac2008fa9a77fa36fd
ssdeep: 49152:GzhqDI4LZujDTR9/hUspUQdAgTFCyaHcDtwTrfwmQqjJLEdReY52ECy2nPMRxhZA:KvnjDJXpXAgxPaHe+QqjJtlnPSK
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T170E59F227A0BC071E9CE11B065796FF7C5ACAA6E4B3104C766D42F7969311D33A31E2B
sha3_384: 2dcd55dca8b2066abddb9d945364f3e63a58e321c060bfa75be6e5ddf5c45c743e88fac0bab4ffe12be47c2033d6792f
ep_bytes: 558bec837d0c017505e82e0b0000ff75
timestamp: 2022-08-17 06:19:09

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: LogSession
FileVersion: 8.8.0.5
InternalName: LogSession
LegalCopyright: Copyright © 2022 Adobe. All rights reserved.
OriginalFilename: LogSession.dll
PrivateBuild: 8.8.0.5
ProductName: LogSession
ProductVersion: 8.8.0.5
Translation: 0x0409 0x04b0

Trojan:Win32/Doina!pz also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Senoval.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mint.Zard.5
FireEyeGen:Variant.Mint.Zard.5
SkyhighBehavesLike.Win32.Generic.wc
AlibabaTrojan:Win32/Senoval.ac7064a7
K7GWTrojan ( 005ab4bf1 )
K7AntiVirusTrojan ( 005ab4bf1 )
SymantecTrojan.Gen.6
ESET-NOD32a variant of Win32/Patched.NKM
CynetMalicious (score: 100)
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Mint.Zard.5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Patched-AWW [Trj]
TencentTrojan.Win32.Pathced_ya.16001052
EmsisoftGen:Variant.Mint.Zard.5 (B)
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.Beetle.2
VIPREGen:Variant.Mint.Zard.5
SophosW32/Patched-CD
GDataGen:Variant.Mint.Zard.5
VaristW32/Doina.AR.gen!Eldorado
AviraTR/Patched.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Patched
ArcabitTrojan.Mint.Zard.5
ZoneAlarmVirus.Win32.Senoval.a
MicrosoftTrojan:Win32/Doina!pz
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5485362
ALYacGen:Variant.Mint.Zard.5
VBA32BScope.TrojanDownloader.Emotet
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.100 (RDML:MrsvoNWB2wTm0Tak4dBIYg)
IkarusTrojan.Win32.Krypt
FortinetW32/Patched.IP!tr
AVGWin32:Patched-AWW [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Doina!pz?

Trojan:Win32/Doina!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment