Trojan

Trojan.Win64.Donut.ggf removal

Malware Removal

The Trojan.Win64.Donut.ggf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Donut.ggf virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Trojan.Win64.Donut.ggf?


File Info:

name: 3E1EBBDFE87471AB48CE.mlw
path: /opt/CAPEv2/storage/binaries/0ebf8eceec8a8410502bb285ec236ce9f5e26a20d28398bae5f6af3b588bb14d
crc32: 6586428C
md5: 3e1ebbdfe87471ab48cec60e6dca1d83
sha1: 8bc0c29df3404f6da7b6f98668528c4d1f7aaf45
sha256: 0ebf8eceec8a8410502bb285ec236ce9f5e26a20d28398bae5f6af3b588bb14d
sha512: 8df145f2137553fe2f564482190b743dfda02380dfc943628f528c7a3b71f6e52cf6fbb3b486cf9dd6dec43313a8e57d78086b6377fad4b73de72ecb8c2f77a5
ssdeep: 196608:VtB3u09Zpbs7Ata+fYvcydcKDKl03YxeQ1IBs1+:VtB9XblzwvXcKOWoP1IB
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1729633C5A20D28EDF8269D7685583C48AC7D77F159E2C67AC30C62CC1584749FCABE8E
sha3_384: cc290773b8b691b310fbba2795b7d81520531cc070ab84315f080c7ac77431a482011c937d17c1ae45fc51fd0d1b90d3
ep_bytes: eb0800ea580000000000505152535556
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: Google Inc.
FileTitle: chrome.exe
FileDescription: Google Chrome
FileVersion: 70,0,3538,110
LegalCopyright: Copyright 2017 Google Inc. All rights reserved.
LegalTrademark:
ProductName: Google Chrome
ProductVersion: 70,0,3538,110
Translation: 0x0409 0x04b0

Trojan.Win64.Donut.ggf also known as:

LionicTrojan.Win64.Donut.4!c
DrWebTrojan.Siggen16.2217
MicroWorld-eScanTrojan.GenericKD.38229962
FireEyeGeneric.mg.3e1ebbdfe87471ab
McAfeeArtemis!3E1EBBDFE874
CylanceUnsafe
K7AntiVirusTrojan ( 005823691 )
AlibabaTrojan:Win64/Donut.762c2dbc
K7GWTrojan ( 005823691 )
ArcabitTrojan.Generic.D24757CA
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win64/Packed.Enigma.BV
Paloaltogeneric.ml
KasperskyTrojan.Win64.Donut.ggf
BitDefenderTrojan.GenericKD.38229962
AvastWin64:Trojan-gen
Ad-AwareTrojan.GenericKD.38229962
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win64.Dropper.rc
EmsisoftTrojan.GenericKD.38229962 (B)
MAXmalware (ai score=83)
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKD.38229962
AhnLab-V3Trojan/Win.Generic.C4785021
ALYacTrojan.GenericKD.38229962
APEXMalicious
IkarusTrojan.Win64.Enigma
eGambitUnsafe.AI_Score_99%
FortinetPossibleThreat.PALLAS.H
AVGWin64:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Win64.Donut.ggf?

Trojan.Win64.Donut.ggf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment