Trojan

About “Dropped:Trojan.BAT.KillFiles.GD” infection

Malware Removal

The Dropped:Trojan.BAT.KillFiles.GD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.BAT.KillFiles.GD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

edex114-10.tripod.com
edex114-11.tripod.com
edex114-12.tripod.com
edex114-13.tripod.com
edex114-14.tripod.com
edex114-15.tripod.com
edex114-16.tripod.com
edex114-17.tripod.com
edex114-18.tripod.com
edex114-19.tripod.com
edex114-20.tripod.com
edex114-21.tripod.com
edex114-22.tripod.com
edex114-23.tripod.com
edex114-24.tripod.com
edex114-25.tripod.com
edex114-26.tripod.com
edex114-27.tripod.com
edex114-28.tripod.com
edex114-29.tripod.com
edex114-30.tripod.com
edex114-31.tripod.com
edex114-32.tripod.com
edex114-33.tripod.com
edex114-34.tripod.com
edex114-35.tripod.com
edex114-36.tripod.com
edex114-37.tripod.com
edex114-38.tripod.com
edex114-39.tripod.com
edex114-40.tripod.com
edex114-41.tripod.com
edex114-42.tripod.com
edex114-43.tripod.com
edex114-44.tripod.com

How to determine Dropped:Trojan.BAT.KillFiles.GD?


File Info:

crc32: 16642B13
md5: 33dae70760fe758bcb9a3435d9e9d0f8
name: 33DAE70760FE758BCB9A3435D9E9D0F8.mlw
sha1: ec6f9e3c3d2e261f84aeb3325b0b7d9c31811eae
sha256: 0553b1c050a14001290ef731177a298380588d9b4dfc2a2cb1da5caa2c60ed98
sha512: e382d38a858a16b7496b00494c3459fd5636f31dc463bd9aacc981a07630b40ab854ebd1c0deabb9dd73d8f539300b37e98b7b59734aadc189fe454a7f1765eb
ssdeep: 12288:cj6/3mPjf0w76gEc0q8qO65X6AOe+tv+svU9IrgcRO1jUITEojPnl:E6/3mPjf0w/n0L6J6AObvF+1jUITBz
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Dropped:Trojan.BAT.KillFiles.GD also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 000143381 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Banker.12163
CynetMalicious (score: 100)
ALYacDropped:Trojan.BAT.KillFiles.GD
ZillyaBackdoor.Delf.Win32.4484
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojanSpy:BAT/KillFiles.2f5c972e
K7GWTrojan ( 000143381 )
Cybereasonmalicious.760fe7
CyrenW32/Backdoor.AHVK-4137
SymantecBloodhound.Bancos.1
ESET-NOD32a variant of Win32/Spy.Banker
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Dropper.Killfiles-9844577-0
KasperskyTrojan.BAT.KillFiles.gh
BitDefenderDropped:Trojan.BAT.KillFiles.GD
NANO-AntivirusTrojan.Win32.KillFiles.dezobx
MicroWorld-eScanDropped:Trojan.BAT.KillFiles.GD
Ad-AwareDropped:Trojan.BAT.KillFiles.GD
SophosML/PE-A + Mal/Banspy-K
ComodoTrojWare.Win32.Spy.Banker.Gen@1qlojk
BitDefenderThetaGen:NN.ZelphiF.34738.SiWfa4AQ9AiG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.VirRansom.bc
FireEyeGeneric.mg.33dae70760fe758b
EmsisoftDropped:Trojan.BAT.KillFiles.GD (B)
JiangminTrojan/PSW.GamePass.xby
AviraTR/Spy.Banker.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.63F59A
MicrosoftTrojan:Win32/Sisproc!gmb
AegisLabTrojan.Win32.Delf.m!c
GDataDropped:Trojan.BAT.KillFiles.GD
AhnLab-V3Trojan/Win32.Xema.C119680
McAfeeGeneric PWS.b
VBA32BScope.Trojan.BAT.KillFiles
PandaGeneric Malware
RisingTrojan.PSW.Win32.Mnless.b (CLASSIC)
YandexTrojan.GenAsa!+J+Y63GaVJ4
IkarusTrojan-Spy.Win32.Banker.anv
MaxSecureTrojan.Malware.300983.susgen
FortinetBasine.A!tr
AVGWin32:Evo-gen [Susp]

How to remove Dropped:Trojan.BAT.KillFiles.GD?

Dropped:Trojan.BAT.KillFiles.GD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment