Malware

What is “BAT/KillFiles.NOB”?

Malware Removal

The BAT/KillFiles.NOB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/KillFiles.NOB virus can do?

  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Clears Windows events or logs
  • Anomalous binary characteristics

How to determine BAT/KillFiles.NOB?


File Info:

crc32: 38B6F5D0
md5: 37ab838dfbd17afe26c93efa5aa678be
name: 37AB838DFBD17AFE26C93EFA5AA678BE.mlw
sha1: 3930efd00aeb2d4de9d6982a0493591ced4f7b55
sha256: 308c8a727098ed5322f4978e92106c0130aa74010428e77504fdb48eb5a5db75
sha512: 769e952779a4a2a7ff0171819d8267152bb24ac047729fc850c5ffb5d0062e496df59bb496d43a6546997c516aa39d161288851b174e75de7e04c9d35de98c20
ssdeep: 6144:E5aWbksiNTB7SMEPRvT1Rjja4su15S2CV:E5atNTxSxPBTrCV
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BAT/KillFiles.NOB also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.KillFiles.4!c
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.00aeb2
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/KillFiles.NOB
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.KillFiles
AlibabaTrojan:Win32/KillFiles.1a13d4d8
SophosMal/Generic-S
ComodoMalware@#1777zt08rempv
BitDefenderThetaGen:NN.ZexaF.34142.CuW@a896Zcf
McAfee-GW-EditionBehavesLike.Win32.Emotet.gm
FireEyeGeneric.mg.37ab838dfbd17afe
SentinelOneStatic AI – Malicious PE
MicrosoftRansom:Win32/Genasom
ZoneAlarmHEUR:Trojan.Win32.KillFiles
AhnLab-V3Malware/Win32.Generic.C2884393
McAfeeArtemis!37AB838DFBD1
MAXmalware (ai score=99)
MalwarebytesMalware.Heuristic.1008
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.93 (RDML:fGAsrERm2EeqvpAPnOeftA)
YandexTrojan.KillFiles!19c6VqGCgKI
IkarusTrojan-Ransom.Rokku
MaxSecureTrojan.Malware.300983.susgen
Paloaltogeneric.ml

How to remove BAT/KillFiles.NOB?

BAT/KillFiles.NOB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment