Trojan

Trojan.Win64.Donut.ger information

Malware Removal

The Trojan.Win64.Donut.ger is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Donut.ger virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Trojan.Win64.Donut.ger?


File Info:

name: AD55075748DCAE3E59B2.mlw
path: /opt/CAPEv2/storage/binaries/0c863db74e3f3cb9bc7cae241e79b92cff684d808ba4eb78f50fb44069c2bd9f
crc32: 9720BB12
md5: ad55075748dcae3e59b286292db8a324
sha1: 8cef8bb712e8787b002084c82e067ee3d7aa305e
sha256: 0c863db74e3f3cb9bc7cae241e79b92cff684d808ba4eb78f50fb44069c2bd9f
sha512: 7070ed9f70fc538b6de5df21b06bbe785f8657b46d76fc11af149ad0d45d595aaad128a8fcd0fe3bf15764572da8db25ab0be1d88a7076d486cd78d52f7cb419
ssdeep: 196608:wGOOckmuA6A6R+6+7+0uq2XEVOfyQBQlWFGWFmH:Vcb7QU+HH0VgiH
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T175963388FA0CB2A5FF9A07B6D54D3D5889242BF85DF487C0A342A75853A774CC153B8B
sha3_384: 066bd10cebaaadbe390fa987aeb43ad90244ba42fc2c4208b27543a592c1f4e764bd498f2451fa8c66296ca745a4ee7e
ep_bytes: eb0800f0580000000000505152535556
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: Google Inc.
FileTitle: chrome.exe
FileDescription: Google Chrome
FileVersion: 70,0,3538,110
LegalCopyright: Copyright 2017 Google Inc. All rights reserved.
LegalTrademark:
ProductName: Google Chrome
ProductVersion: 70,0,3538,110
Translation: 0x0409 0x04b0

Trojan.Win64.Donut.ger also known as:

LionicTrojan.Win64.Donut.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.ad55075748dcae3e
McAfeeArtemis!AD55075748DC
AlibabaTrojan:Win64/Donut.595abe68
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Packed.Enigma.BV
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win64.Donut.ger
AvastFileRepMalware
TencentWin64.Trojan.Donut.Lohp
DrWebTrojan.Siggen15.64184
McAfee-GW-EditionBehavesLike.Win64.Dropper.rc
SophosMal/Generic-R
SentinelOneStatic AI – Suspicious PE
AviraTR/Redcap.ppjvz
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.Z.Enigma.8749056
GDataWin32.Packed.Kryptik.7GPQ9D
AhnLab-V3Trojan/Win.Trojan-gen.R456599
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R067H07L921
IkarusTrojan.Win64.Enigma
FortinetPossibleThreat.PALLAS.H
AVGFileRepMalware

How to remove Trojan.Win64.Donut.ger?

Trojan.Win64.Donut.ger removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment