Trojan

What is “Trojan.Generic.20889086”?

Malware Removal

The Trojan.Generic.20889086 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.20889086 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • EternalBlue behavior
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Appends a known Sage ransomware file extension to files that have been encrypted
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
mbfce24rgn65bx3g.jktew0.com
mbfce24rgn65bx3g.jpo2z1.net
a.tomx.xyz

How to determine Trojan.Generic.20889086?


File Info:

crc32: D6808F28
md5: 2e65c098fa05efe51f46b9e897140c75
name: 2E65C098FA05EFE51F46B9E897140C75.mlw
sha1: 7c1d25c0309af7f88aeebf052f9e40b1adbd03b9
sha256: 2c677c767ef3c8100183ab7291185160bcc0292cc041ccda787c8af10924c91c
sha512: 775b52cd5ef2e63fd1a664a5c3be2ab5c5654d5d6cc7a47dc5c2bd28595781634c9787b897a448af00e346f5e186c2429a4bbae35d72b3007f3287bfe251ae54
ssdeep: 12288:oElbPrJKmkO6TSuIInYjCfFFrDGxIeKOPIdR:oElLkO6TTHfFFfBebPIb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9. All rights reserved. Foxit Corporation
InternalName: Certreqpage
CompanyName: Foxit Corporation
ProductName: Certreqpage
ProductVersion: 2.9.8.7
FileDescription: Relocatable Missin
Translation: 0x0409 0x04b0

Trojan.Generic.20889086 also known as:

K7AntiVirusTrojan ( 0051d3ea1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10433
CynetMalicious (score: 100)
ALYacTrojan.Generic.20889086
CylanceUnsafe
ZillyaTrojan.Generic.Win32.346526
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Milicry.13e6b98b
K7GWTrojan ( 0051d3ea1 )
Cybereasonmalicious.8fa05e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FQZW
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.20889086
NANO-AntivirusTrojan.Win32.Encoder.frcvhc
MicroWorld-eScanTrojan.Generic.20889086
TencentMalware.Win32.Gencirc.114aefd4
Ad-AwareTrojan.Generic.20889086
SophosMal/Generic-S
ComodoMalware@#9kte4i45hjh9
BitDefenderThetaGen:NN.ZexaF.34170.HC1@aS@52Cki
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_MiliCry-2t
McAfee-GW-EditionBehavesLike.Win32.Dropper.hh
FireEyeGeneric.mg.2e65c098fa05efe5
EmsisoftTrojan.Generic.20889086 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1102807
Antiy-AVLTrojan/Generic.ASMalwS.1F11E31
MicrosoftRansom:Win32/Milicry!bit
ArcabitTrojan.Generic.D13EBDFE
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Generic.20889086
AhnLab-V3Trojan/Win32.SageCrypt.C1864042
McAfeeArtemis!2E65C098FA05
MAXmalware (ai score=100)
PandaTrj/CI.A
TrendMicro-HouseCallMal_MiliCry-2t
RisingTrojan.Generic@ML.97 (RDML:DIXwWyPawfWSQzqMkrPlfQ)
IkarusTrojan-Ransom.GandCrab
FortinetW32/SageCrypt.BEC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Generic.20889086?

Trojan.Generic.20889086 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment