Malware

How to remove “MSIL/KillFiles.AU”?

Malware Removal

The MSIL/KillFiles.AU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/KillFiles.AU virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine MSIL/KillFiles.AU?


File Info:

crc32: 91A31AB9
md5: 3c934527dce686605db3a230008c207a
name: 3C934527DCE686605DB3A230008C207A.mlw
sha1: 4acd4ae1e6c9479ec5f0e7408eaebd14fe9b506d
sha256: d005ac9eb08706d0c22f6fdee6adbad6cd2222cd56f0a6dfe397ad0916ef6697
sha512: f1bb5158d288cb811ba5cd2b10d213f361cdf84d9f519512844881e56e21f24ea29356ae9432c361345ffee8436b11e0192963e68123afa6ecc39ec52dda2bd1
ssdeep: 96:fx610AlfGyIru0Avy5UHiOIcFX379tnCL4ZPAwRueuXCB:o0Qery0cyOHiOIw79tnRZPANxXo
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.1
InternalName: Ebast21sa.exe
FileVersion: 1.0.0.1
CompanyName:
LegalTrademarks:
Comments:
ProductName: Ebast21sa
ProductVersion: 1.0.0.1
FileDescription: Ebast21sa
OriginalFilename: Ebast21sa.exe

MSIL/KillFiles.AU also known as:

K7AntiVirusTrojan ( 00532e8f1 )
LionicTrojan.Win32.Generic.j!c
DrWebTrojan.DelShadows.6
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.30889864
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7GWTrojan ( 00532e8f1 )
Cybereasonmalicious.7dce68
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/KillFiles.AU
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderTrojan.GenericKD.30889864
NANO-AntivirusTrojan.Win32.DelShadows.fctdzk
MicroWorld-eScanTrojan.GenericKD.30889864
TencentWin32.Trojan.Generic.Lmut
Ad-AwareTrojan.GenericKD.30889864
SophosMal/Generic-S
ComodoMalware@#1kj1ygzr1dey7
BitDefenderThetaGen:NN.ZemsilF.34126.am0@aSCOW3c
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXEE-GQ!3C934527DCE6
FireEyeTrojan.GenericKD.30889864
EmsisoftTrojan.GenericKD.30889864 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1115167
Antiy-AVLTrojan/Generic.ASMalwS.2637461
MicrosoftTrojan:Win32/Dynamer!rfn
GDataTrojan.GenericKD.30889864
McAfeeGenericRXEE-GQ!3C934527DCE6
MAXmalware (ai score=94)
PandaTrj/GdSda.A
YandexTrojan.Agent!bIPUfIVXo1A
IkarusTrojan.Ransom
FortinetMSIL/Generic.AP.CEBB4B2!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/KillFiles.AU?

MSIL/KillFiles.AU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment