Trojan

Should I remove “Trojan.Win64RI.S20908814”?

Malware Removal

The Trojan.Win64RI.S20908814 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win64RI.S20908814 virus can do?

  • Unconventionial language used in binary resources: Hebrew
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan.Win64RI.S20908814?


File Info:

crc32: 8785CD1F
md5: 0f73d1809a0474d5cf68b93b2d6c4a2f
name: 0F73D1809A0474D5CF68B93B2D6C4A2F.mlw
sha1: 44aa3d3fa45c53675af648a60c5797f9a4f514d0
sha256: 0628aaf627ce84b832a81812cd56f30c5fea3c703e764fc7b70994f692c780ac
sha512: e61430e99bdd626235e5c6e93cc492f2bee0b31ab0a08eb91fa1a49bc5e99545b52a5ba7b0dec01e4158f727476142389b23bb015ff0ba3365696b5403f3fc3f
ssdeep: 12288:TdMIwS97wJs6tSKDXEabXaC+jhc1S8XXk7CZzHsZH9dq0T:hMIJxSDX3bqjhcfHk7MzH6z
type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005 - 2009 Nir Sofer
InternalName: TeltwFoo
FileVersion: 9.74
CompanyName: NirSoft
ProductName: TeltwFoo
ProductVersion: 9.74
FileDescription: ProduKey
OriginalFilename: TeltwFoo.exe
Translation: 0x0409 0x04b0

Trojan.Win64RI.S20908814 also known as:

Elasticmalicious (high confidence)
ClamAVWin.Dropper.Dridex-9875456-0
CAT-QuickHealTrojan.Win64RI.S20908814
ALYacTrojan.GenericKDZ.75562
MalwarebytesMalware.AI.1884556628
ZillyaTrojan.Injexa.Win64.129
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW64/MSIL_Kryptik.ELJ.gen!Eldorado
ESET-NOD32a variant of Win64/Kryptik.CJV
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin64:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win64.Injexa.gen
BitDefenderTrojan.GenericKDZ.75562
MicroWorld-eScanTrojan.GenericKDZ.75562
TencentMalware.Win32.Gencirc.10ce569e
Ad-AwareTrojan.GenericKDZ.75562
SophosML/PE-A + Troj/Dridex-ABY
F-SecureTrojan.TR/Crypt.ZPACK.Gen
McAfee-GW-EditionDrixed-FJX!0F73D1809A04
FireEyeGeneric.mg.0f73d1809a0474d5
EmsisoftTrojan.GenericKDZ.75562 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Injexa.hs
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win64.Injexa
GridinsoftTrojan.Win64.Kryptik.oa!s1
GDataTrojan.GenericKDZ.75562
AhnLab-V3Trojan/Win.Generic.R426521
Acronissuspicious
McAfeeDrixed-FJX!0F73D1809A04
MAXmalware (ai score=89)
VBA32Trojan.Win64.Dridex
IkarusTrojan.Win64.Dridex
FortinetW64/Kryptik.CJV!tr
AVGWin64:BankerX-gen [Trj]

How to remove Trojan.Win64RI.S20908814?

Trojan.Win64RI.S20908814 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment