Trojan

How to remove “Trojan.Win64.Donut.euy”?

Malware Removal

The Trojan.Win64.Donut.euy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Donut.euy virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win64.Donut.euy?


File Info:

name: B836F3F180AD9262B8C5.mlw
path: /opt/CAPEv2/storage/binaries/274c8513e1e05f0b81ec8a77fc5a93d72ede7b1dbb3f576ceb610515c78c6e6b
crc32: CBC4D09D
md5: b836f3f180ad9262b8c5fa73caa86ae5
sha1: 16ccb63eab31f7e0d2a199019a2b25c84bfc4dbf
sha256: 274c8513e1e05f0b81ec8a77fc5a93d72ede7b1dbb3f576ceb610515c78c6e6b
sha512: 1a0b8afa9ab4235988675bcdb72258d7180dc28391edfada5808aeba643428e15077294d5f68f061bdaa8a88bcb90b71514230b6373a6447a889e16b130b8655
ssdeep: 49152:O1xNI23jqgbnBJrnUj2y6tY0WmGJfYTHspzHx/h/D38Un:O1s2T9LrgmY0aATMt5tj
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T17C9533B41A8480A4C56A98BD1FC5AB9BD77495A7C03023ECF4F849F9E4A4D9F6250F0B
sha3_384: 7c430e58767edc09c9338e6aca8ac16a047e5dc825efa52dec9dd8d37bbc073cf0f40d5b52d18b7bcc9acf897a5269d2
ep_bytes: 554889e54881ec4000000048b8040000
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: Google Inc.
FileTitle: chrome.exe
FileDescription: Google Chrome
FileVersion: 70,0,3538,110
LegalCopyright: Copyright 2017 Google Inc. All rights reserved.
LegalTrademark:
ProductName: Google Chrome
ProductVersion: 70,0,3538,110
Translation: 0x0409 0x04b0

Trojan.Win64.Donut.euy also known as:

LionicTrojan.Win64.Donut.4!c
Elasticmalicious (high confidence)
DrWebTrojan.InjectNET.14
MicroWorld-eScanTrojan.GenericKDZ.78844
FireEyeGeneric.mg.b836f3f180ad9262
CAT-QuickHealTrojan.Inject
ALYacTrojan.GenericKDZ.78844
CylanceUnsafe
SangforTrojan.Win64.Donut.euy
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win64/Donut.f50d36cd
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.eab31f
CyrenW64/Agent.DMU.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Agent.AVO
Paloaltogeneric.ml
KasperskyTrojan.Win64.Donut.euy
BitDefenderTrojan.GenericKDZ.78844
AvastFileRepMalware
TencentMalware.Win32.Gencirc.10cf73a4
Ad-AwareTrojan.GenericKDZ.78844
EmsisoftTrojan.Agent (A)
Comodo.UnclassifiedMalware@0
TrendMicroTROJ_GEN.R002C0DKF21
McAfee-GW-EditionBehavesLike.Win64.Generic.tc
SophosMal/Generic-S
IkarusTrojan.Win64.Agent
JiangminTrojan.Donut.jq
WebrootW32.Trojan.Gen
AviraTR/Agent.yimmx
Antiy-AVLTrojan/Generic.ASMalwS.34C0FDD
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftTrojan.Win64.Agent.vb
MicrosoftTrojan:Win64/Donut.CIK!MTB
GDataTrojan.GenericKDZ.78844
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R444976
McAfeeTrojan-FUCP!B836F3F180AD
MAXmalware (ai score=80)
VBA32Trojan.Inject
MalwarebytesTrojan.Agent
TrendMicro-HouseCallTROJ_GEN.R002C0DKF21
YandexTrojan.Agent!jkzoEePQd8A
FortinetW64/Agent.AVO!tr
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Trojan.Win64.Donut.euy?

Trojan.Win64.Donut.euy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment