Trojan

Trojan:Win32/Avkill.E removal instruction

Malware Removal

The Trojan:Win32/Avkill.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Avkill.E virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Avkill.E?


File Info:

crc32: 7BD741BD
md5: 682199f0958dbe1eae9b0505eeaa2789
name: root.exe
sha1: a4cc2745fd2e495a924f50456be93050671d2242
sha256: f8c29875b35abaf3f292d1687c3ddc5a74f5502ab61518cc33ba435525679322
sha512: 6d695cfc698871e56336973b39c0230c66c19571a4b8ab5e8c3babd5a1c239034847e020370c71bc4f2500c8203a1699dedaf7d4a34cfa0366ddcc3b7a8f3131
ssdeep: 12288:Q2BZaVSRfgUmUAWRHkRxj+9nKmPEx3oV8q2:VBZaV4NmvyHkfj+RKUExYVG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x948ax6da3x56e2x961f
FileVersion: 1.0.0.0
CompanyName: x948ax6da3x56e2x961f
Comments: x8179x6c34x96bex6536
ProductName: x948ax6da3x79d2x6740x673a
ProductVersion: 1.0.0.0
FileDescription: x8179x6c34x96bex6536
Translation: 0x0804 0x04b0

Trojan:Win32/Avkill.E also known as:

MicroWorld-eScanTrojan.GenericKD.42355769
FireEyeGeneric.mg.682199f0958dbe1e
Qihoo-360Trojan.Win32.Made.J
ALYacTrojan.GenericKD.42355769
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.lvQ7
K7AntiVirusTrojan ( 005246d51 )
BitDefenderTrojan.GenericKD.42355769
K7GWTrojan ( 00013a151 )
Cybereasonmalicious.5fd2e4
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34084.Uq0@a4hznrhb
F-ProtW32/Agent.EW.gen!Eldorado
TotalDefenseWin32/ASuspect.HHFAM
APEXMalicious
AvastWin32:AutoRun-BRF [Wrm]
ClamAVWin.Malware.Zusy-6840460-0
GDataTrojan.GenericKD.42355769
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Disabler.77cda910
TencentWin32.Trojan.Killav.Wnmf
Ad-AwareTrojan.GenericKD.42355769
EmsisoftTrojan.GenericKD.42355769 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
F-SecureTrojan.TR/AvKill.rjonu
BaiduWin32.Trojan.KillAV.f
TrendMicroTROJ_KILLAV.SMIE
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Daws
CyrenW32/Agent.EW.gen!Eldorado
JiangminTrojan/Generic.bcpfy
AviraTR/AvKill.rjonu
Antiy-AVLGrayWare/Win32.FlyStudio.a
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2864C39
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Avkill.E
AhnLab-V3Trojan/Win32.Vilsel.C48033
Acronissuspicious
McAfeeArtemis!682199F0958D
MAXmalware (ai score=80)
MalwarebytesTrojan.FlyStudio
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Disabler.NBL
TrendMicro-HouseCallTROJ_KILLAV.SMIE
RisingTrojan.Killav!1.9D3A (CLOUD)
YandexTrojan.Pasta.Gen.1
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Disabler.NAT!tr
AVGWin32:AutoRun-BRF [Wrm]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Trojan:Win32/Avkill.E?

Trojan:Win32/Avkill.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment