Malware

Should I remove “BAT/KillWin.NIV”?

Malware Removal

The BAT/KillWin.NIV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/KillWin.NIV virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Clears Windows events or logs
  • Uses suspicious command line tools or Windows utilities

How to determine BAT/KillWin.NIV?


File Info:

name: EFACDCEF58914B28A010.mlw
path: /opt/CAPEv2/storage/binaries/21b80eabda821d81c9203ebc5c589991d42306ee7f7aebe23c56e51f5538bc1c
crc32: B983855B
md5: efacdcef58914b28a01075b9b226f118
sha1: 914bd6ec7189eea574d1dded3beeb6e06fbb14fa
sha256: 21b80eabda821d81c9203ebc5c589991d42306ee7f7aebe23c56e51f5538bc1c
sha512: cf1c42d81c4dd3c523cd344f2b0c452e4191ab546dd31f82e3f67272f50be770839b33f1a079383dd1610651e97012a6b431b912029ce7997b3d53b0f5283fbb
ssdeep: 1536:K7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfKxZgKAd:oq6+ouCpk2mpcWJ0r+QNTBfKTgDd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173C3F661B2F241E6F9E10D720CA2A02ABBE65D148F1494DFC35839E155337D4DA392FE
sha3_384: dc22677f7084fcb034d491e7d2b9ddf301fa8f837ba3f646ec1306a6d1ce48a46550b151d7d437c6815d5130003d2d87
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

ProductName: Tabla excel.xls
OriginalFilename: Tabla excel.xls
InternalName: Tabla excel.xls
FileDescription: Tabla excel.xls
Comments: Tabla excel.xls
Translation: 0x0000 0x04e4

BAT/KillWin.NIV also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Tiny.trFe
MicroWorld-eScanTrojan.GenericKD.35803859
FireEyeGeneric.mg.efacdcef58914b28
ALYacTrojan.GenericKD.35803859
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/SchoolGirl.741f7904
Cybereasonmalicious.f58914
VirITTrojan.Win32.Genus.IHW
CyrenW32/Trojan.VFBA-8001
Elasticmalicious (high confidence)
ESET-NOD32BAT/KillWin.NIV
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.SchoolGirl.fei
BitDefenderTrojan.GenericKD.35803859
AvastFileRepMalware [Trj]
TencentWin32.Trojan.Schoolgirl.Aotg
Ad-AwareTrojan.GenericKD.35803859
EmsisoftTrojan.GenericKD.35803859 (B)
ZillyaTool.Lazagne.Win32.102
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.35803859
ArcabitTrojan.Generic.D22252D3
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C4268368
McAfeeArtemis!EFACDCEF5891
MAXmalware (ai score=89)
VBA32Trojan.SchoolGirl
MalwarebytesMalware.AI.392946571
RisingTrojan.Generic@AI.95 (RDML:mGVl+71XyBMHwfeJBlvQBw)
YandexTrojan.SchoolGirl!zGk5iCSV7ZU
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/SchoolGirl.FEI!tr
AVGFileRepMalware [Trj]

How to remove BAT/KillWin.NIV?

BAT/KillWin.NIV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment