Malware

BAT/KillFiles.NQU (file analysis)

Malware Removal

The BAT/KillFiles.NQU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/KillFiles.NQU virus can do?

  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine BAT/KillFiles.NQU?


File Info:

crc32: 4F225A9C
md5: 3c065a13a229dd0ebb1f79521022473f
name: 3C065A13A229DD0EBB1F79521022473F.mlw
sha1: ba9a45b19d6ab74be492a59bdb8d73f666eb7620
sha256: 31f11d0b6bbf34d2b87990dc6d38a1bfcba98193b6539738e9e25c25d6f0f423
sha512: a3bda90e5762074534ad157fbb8909b439e7bc27f2e77186b791a6feccdae10955c90421b035171e4c6621030ba819ed38aa312184156cc910b4b25ca4944980
ssdeep: 1536:bH7ftfkS5g9YOms+gZcQipICdXkNDqLLZX9lItVGL++eIOlnToIfCwNR:bbFfHgTWmCRkGbKGLeNTBfCcR
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BAT/KillFiles.NQU also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0057b6411 )
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:BAT/KillFiles.96e54b73
K7GWTrojan ( 0057b6411 )
Cybereasonmalicious.19d6ab
CyrenW32/Nitol.AB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/KillFiles.NQU
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Encoder.mee
BitDefenderTrojan.GenericKD.36805123
NANO-AntivirusTrojan.Win32.Encoder.iumphc
MicroWorld-eScanTrojan.GenericKD.36805123
Ad-AwareTrojan.GenericKD.36805123
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
FireEyeGeneric.mg.3c065a13a229dd0e
EmsisoftTrojan.GenericKD.36805123 (B)
eGambitUnsafe.AI_Score_92%
MicrosoftProgram:Win32/Wacapew.C!ml
AegisLabTrojan.Win32.Encoder.j!c
GDataTrojan.GenericKD.36805123
TACHYONTrojan/W32.Agent.91136.ACQ
McAfeeArtemis!3C065A13A229
MAXmalware (ai score=87)
VBA32TrojanRansom.Encoder
TrendMicro-HouseCallTROJ_GEN.R002H07DO21
RisingRansom.Encoder!8.FFD4 (CLOUD)
IkarusTrojan.BAT.KillFiles
MaxSecureTrojan.Malware.300983.susgen
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove BAT/KillFiles.NQU?

BAT/KillFiles.NQU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment