Trojan

Trojan.Win64.Donut.fwk removal guide

Malware Removal

The Trojan.Win64.Donut.fwk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Donut.fwk virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Trojan.Win64.Donut.fwk?


File Info:

name: 5895E63A7BCA8CC08B3A.mlw
path: /opt/CAPEv2/storage/binaries/f8e512cd8999ab9a3b83ca080647262389cdd72ee22b4afcecf5100fc3abded5
crc32: 41FBA139
md5: 5895e63a7bca8cc08b3a0b624342678d
sha1: 88cfaf2f8d1051092e467e12de987bf717164d60
sha256: f8e512cd8999ab9a3b83ca080647262389cdd72ee22b4afcecf5100fc3abded5
sha512: 27945fcb03a486eb6b2adfe977b8711abcdbb5098539e03274ddae08a421efe2aaa793f333823b38a26b59a7acaa3509f524ea9e1a643b126f1b95b4a6aff001
ssdeep: 196608:rBKyvuzV4lgEHF2cC+xHmptrUnwYmr3LnK:rnumlfgF+tG/YY3D
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1326623FD6284336CC41EC974C433F984F276561E4ADAE4BAB2DB36D067A7424D842F4A
sha3_384: 575996d250cc8a84f14f4690ad8758240634a730c0bddbc21b1b054aec23f0c4548b206cb60cd98f17a8330c994852fb
ep_bytes: 6800ef4011e836341800d4e564cc1564
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: VideoLAN
FileTitle: vlc
FileDescription: VLC media player
FileVersion: 3,0,3,0
LegalCopyright: Copyright В© 1996-2018 VideoLAN and VLC Authors
LegalTrademark: VLC media player, VideoLAN and x264 are registered trademarks from VideoLAN
ProductName: VLC media player
ProductVersion: 3,0,3,0
Translation: 0x0409 0x04b0

Trojan.Win64.Donut.fwk also known as:

LionicTrojan.MSIL.Inject.4!c
DrWebTrojan.Inject4.21377
MicroWorld-eScanGen:Variant.Bulz.931113
McAfeeArtemis!5895E63A7BCA
K7AntiVirusTrojan ( 0058a78f1 )
AlibabaTrojan:Win64/Donut.81251fe8
K7GWTrojan ( 0058a78f1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Packed.VMProtect.NM
TrendMicro-HouseCallTROJ_GEN.R002C0RL221
AvastWin64:MdeClass
KasperskyTrojan.Win64.Donut.fwk
BitDefenderGen:Variant.Bulz.931113
TencentWin64.Trojan.Donut.Sxer
Ad-AwareGen:Variant.Bulz.931113
EmsisoftGen:Variant.Bulz.931113 (B)
F-SecureTrojan.TR/Redcap.febkl
TrendMicroTROJ_GEN.R002C0RL221
McAfee-GW-EditionBehavesLike.Win64.Drixed.vc
FireEyeGeneric.mg.5895e63a7bca8cc0
SophosMal/Generic-R + Mal/VMProtBad-A
IkarusTrojan.Win64.Vmprotect
GDataGen:Variant.Bulz.931113
WebrootW32.Trojan.Gen
AviraTR/Redcap.febkl
Antiy-AVLTrojan/Generic.ASMalwS.34DB176
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftTrojan.Win64.Packed.vb
ArcabitTrojan.Bulz.DE3529
MicrosoftTrojan:Win64/Donut.CIK!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R453708
VBA32Trojan.MSIL.Inject
ALYacGen:Variant.Bulz.931113
MAXmalware (ai score=81)
CylanceUnsafe
APEXMalicious
eGambitUnsafe.AI_Score_99%
FortinetW32/PossibleThreat
AVGWin64:MdeClass
Cybereasonmalicious.f8d105
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win64.Donut.fwk?

Trojan.Win64.Donut.fwk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment