Trojan

Trojan.Win64.Reincarnation removal

Malware Removal

The Trojan.Win64.Reincarnation is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64.Reincarnation virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win64.Reincarnation?


File Info:

crc32: 48D76422
md5: f457a5f0472e309c574795ca339ab566
name: SQL.exe
sha1: 155066309beddc77984e1d65bac06b2bd15ef055
sha256: f7e6d12821ffba29e2dcb7dca2d77f247711aaef41923d394e959e3ba2849d1c
sha512: 35c729f93fe6162fd0536f7e70c3d85b230f8f42df7e904cd5196165442963292f4f04694184aee1bee95fe8e2ea2d69e891da4d942e6cea74f1dff6c602062a
ssdeep: 24576:tiIfEcwnHimWTIXDMZCQB6eeQqq3rVGpz5QQsmvQSeegJ7ysp:X+JBXDMZCQB6TQX3rMpzPsATgJ7Tp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win64.Reincarnation also known as:

DrWebTool.InstSrv.10
MicroWorld-eScanTrojan.GenericKD.34188985
FireEyeGeneric.mg.f457a5f0472e309c
CAT-QuickHealTrojan.Miner
Qihoo-360Win64/Trojan.c81
McAfeeArtemis!F457A5F0472E
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderTrojan.GenericKD.34188985
K7GWAdware ( 0055f7d61 )
K7AntiVirusAdware ( 0055f7d61 )
Invinceaheuristic
F-ProtW32/Rasftuby.A
SymantecTrojan.Gen.2
ZonerTrojan.Win64.84488
TrendMicro-HouseCallTROJ_GEN.R002H07GJ20
Paloaltogeneric.ml
ClamAVWin.Coinminer.Generic-7151250-0
GDataTrojan.GenericKD.34188985
KasperskyHEUR:Trojan.Win64.Reincarnation.gen
AlibabaTrojan:Win32/Coinminer.2cc
NANO-AntivirusTrojan.Win32.Miner.hnwpco
ViRobotTrojan.Win32.Z.Coinminer.918290
AegisLabTrojan.Win64.Reincarnation.4!c
TencentWin32.Trojan.Miner.Wlha
SophosXMRig Miner (PUA)
F-SecureHeuristic.HEUR/AGEN.1134782
TrendMicroTROJ_GEN.R002C0WGJ20
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.34188985 (B)
CyrenW32/Trojan.WNJU-7839
JiangminTrojan.Miner.mff
Avirasqlwriters.exe
MAXmalware (ai score=82)
Antiy-AVLRiskWare[RiskTool]/Win64.NSSM
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D209AEB9
ZoneAlarmHEUR:Trojan.Win64.Reincarnation.gen
MicrosoftPUA:Win64/CoinMiner
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C1140396
VBA32TrojanRansom.Wanna
ALYacTrojan.Agent.Miner
MalwarebytesTrojan.BitCoinMiner.Generic
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of Win64/CoinMiner.QG potentially unwanted
RisingTrojan.CoinMiner!8.30A (TFE:dGZlOgFVlCqXHs/xOg)
IkarusTrojan-Ransom.WannaCrypt
FortinetRiskware/Miner
AVGWin64:Malware-gen
AvastWin64:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win64.Reincarnation?

Trojan.Win64.Reincarnation removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment