Donkeyhot Ransomware ๐Ÿ” (. Donkeyhot File) โ€” Removal Guide

What is Donkeyhot virus?

The renaming will be done according to the following scheme: [victimID].[ICQ_contact].DONKEYHOT. In the process of encryption, a file entitled, for example, โ€œreport.docxโ€ will be turned into โ€œreport.docx.[5deecd3145].[ICQ_DONKEYHOT].DONKEYHOTโ€.

In each folder with the encoded files, a #HOW_TO_DECRYPT#.txt file will be created. It is a ransom money note. Therein you can find information about the ways of paying the ransom and some other remarks. The ransom note most probably contains a description of how to buy the decryption tool from the Donkeyhot developers. You can obtain this decoding tool after contacting ICQ contact via email. That is pretty much the scheme of the crime.

NameDonkeyhot Virus
Extension.DONKEYHOT
Ransomware note#HOW_TO_DECRYPT#.txt
ContactICQ contact
Detection1Win32/Injector.EJDH, MSIL/Shutdowner.CA, Trojan:Win32/Anomaly!C
SymptomsYour files (photos, videos, documents) get a .DONKEYHOT extension and you canโ€™t open them.
Fix ToolSee If Your System Has Been Affected by Donkeyhot virus

The #HOW_TO_DECRYPT#.txt file accompanying the Donkeyhot ransomware provides the following dispiriting information:

Hello my dear friend!

Unfortunately for you, a major IT security weakness left you open to attack, your files have been encrypted
If you want to restore them, write to our mail: 
Best option is to write us via ICQ live chat which works 24/7: @DONKEYHOT
Install ICQ software on your PC  or on your smartphone search for \"ICQ\" in Appstore / Google market
Write to our ICQ @DONKEYHOT hxxps://

Attention!
* Do not rename encrypted files.
* Do not try to decrypt your data using third party software, it may cause permanent data loss.
* We are always ready to cooperate and find the best way to solve your problem.
* The faster you write, the more favorable the conditions will be for you.
* Our company values its reputation. We give all guarantees of your files decryption, such as test decryption some of them.
We respect your time and waiting for respond from your side.

Tell your MachineID: - and LaunchID: -

SENSITIVE DATA ON YOUR SYSTEM WAS DOWNLOADED.
IF YOU DON\'T WANT YOUR SENSITIVE DATA TO BE PUBLISHED YOU HAVE TO ACT QUICKLY.

Data includes:
- Employees personal data, CVs, DL, SSN.
- Complete network map including credentials for local and remote services.
- Private financial information including: clients data, bills, budgets, annual reports, bank statements.
- Manufacturing documents including: datagrams, schemas, drawings in solidworks format
- And more...

In the picture below, you can see what a directory with files encrypted by the Donkeyhot looks like. Each filename has the โ€œ.DONKEYHOTโ€ extension added to it.

An example of encrypted .DONKEYHOT files.

How did Donkeyhot ransomware end up on my PC?

Nowadays, there are three most exploited methods for criminals to have ransomware working in your digital environment. These are email spam, Trojan introduction and peer networks.

If you access your mailbox and see letters that look like familiar notifications from utility services providers, delivery agencies like FedEx, web-access providers, and whatnot, but whose mailer is unknown to you, beware of opening those emails. They are most likely to have a malicious item enclosed in them. So it is even more dangerous to open any attachments that come with emails like these.

Another option for ransom hunters is a Trojan virus model2. A Trojan is a program that gets into your computer disguised as something legal. Imagine, you download an installer of some program you want or an update for some service. But what is unboxed turns out to be a harmful agent that compromises your data. Since the installation file can have any name and any icon, youโ€™d better be sure that you can trust the resource of the stuff youโ€™re downloading. The optimal way is to trust the software developersโ€™ official websites.

As for the peer networks like torrent trackers or eMule, the danger is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. So youโ€™d better be using trustworthy websites. Also, it is reasonable to scan the directory containing the downloaded objects with the antivirus as soon as the downloading is done.

Elena Rostova

Elena Rostova

Lead Health, Wellness & Medical Journalist

Elena Rostova holds a Master's degree in Public Health Journalism. She covers groundbreaking medical research, holistic wellness trends, mental health awareness, and nutritional science.

Share this article
Twitter Facebook Pinterest