Trojan

How to remove “Trojan:Win32/Kilim.U”?

Malware Removal

The Trojan:Win32/Kilim.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Kilim.U virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs an hook procedure to monitor for mouse events
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable UAC

Related domains:

www.filmverme.com
www.filmver.com
www.pornokan.com

How to determine Trojan:Win32/Kilim.U?


File Info:

crc32: A0138628
md5: 24911b842678b4d575dd8103c8bdd7a6
name: 24911B842678B4D575DD8103C8BDD7A6.mlw
sha1: fb82ce6e00e7ee83a7af4b7dbaad79ccc02f1bf4
sha256: f1a786693e9b6b182b8ddaa5836ac27f5080094df4390f6880796a2b3a1ca722
sha512: 1010c841be6c8ebe207d03cf4111d30089b7dc0c19d975dd76806be20d75ae2390e9827d44784983bebc4837239cda63a8d6d52e3ab5e4254fb44294adfc6b90
ssdeep: 12288:aNIQAPGsAqY9IMVYd38sJdpQHlGlY8KfTc0FfGIjQb/l9TXQCI:HPGSY91VwNJcFMqTc0FRjQbdVXlI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Apple Inc.
FileDescription: Apple Inc. 9.1.2 Installation
FileVersion: 9.1.2
Comments:
CompanyName: Apple Inc.
Translation: 0x0409 0x04e4

Trojan:Win32/Kilim.U also known as:

BkavW32.SapidosLTG.Trojan
Elasticmalicious (high confidence)
DrWebTrojan.Siggen1.63828
MicroWorld-eScanGen:Variant.Ransom.1994
FireEyeGeneric.mg.24911b842678b4d5
CAT-QuickHealTrojan.IGENERIC
ALYacGen:Variant.Ransom.1994
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Ransom.1994
K7GWTrojan ( 004c2c031 )
K7AntiVirusTrojan ( 004c2c031 )
BitDefenderThetaGen:NN.ZexaF.34590.Rq3@aeAQwami
CyrenW32/Dapato.G.gen!Eldorado
SymantecTrojan.Gen
TrendMicro-HouseCallTROJ_BPUSH.SM
AvastWin32:Malware-gen
ClamAVWin.Malware.Dapato-6959214-0
KasperskyTrojan.Win32.VB.ctxv
NANO-AntivirusTrojan.Win32.VB.dqbdxe
AegisLabTrojan.Win32.VB.mgqM
Ad-AwareGen:Variant.Ransom.1994
SophosMal/Generic-S
ComodoMalware@#6mqkehfqykgx
F-SecureTrojan:W32/Bepush.B
ZillyaTrojan.VB.Win32.131371
TrendMicroTROJ_BPUSH.SM
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
EmsisoftGen:Variant.Ransom.1994 (B)
IkarusTrojan.Win32.VB
JiangminTrojan/VB.cxlm
MaxSecureTrojan.Malware.121218.susgen
AviraTR/Crypt.CFI.besd
MAXmalware (ai score=85)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Kilim.U
ArcabitTrojan.Ransom.D7CA
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmTrojan.Win32.VB.ctxv
GDataGen:Variant.Ransom.1994
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Blocker.C742060
McAfeeArtemis!24911B842678
VBA32BScope.TrojanRansom.Blocker
MalwarebytesTrojan.KBayi.FLA
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of JS/ExtenBro.FBook.FW
RisingTrojan.Kilim!8.64 (TFE:3:hX9y46hkMzV)
YandexTrojan.VB!AHAK1+o69cc
FortinetW32/ExtenBro.AK!tr
WebrootW32.Rogue.Gen
AVGWin32:Malware-gen
Cybereasonmalicious.42678b
Qihoo-360Win32/Worm.VB.HgIASOUA

How to remove Trojan:Win32/Kilim.U?

Trojan:Win32/Kilim.U removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment