Trojan

Trojan:Win32/Killav.DR malicious file

Malware Removal

The Trojan:Win32/Killav.DR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Killav.DR virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Anomalous binary characteristics

Related domains:

whatismyipaddress.com
whatismyip.everdot.org
www.whatismyip.com
www.showmyipaddress.com
www.whatismyip.ca

How to determine Trojan:Win32/Killav.DR?


File Info:

crc32: 46A1AE21
md5: 85715aa52cf7dada1f4a7a3177698eaf
name: nraalk.exe
sha1: 7961035d4584605949f000466f4f9f7b39964718
sha256: 035be54a6162a4a8871bfb13cc608618f978ab3910437a256d83f09935e7713b
sha512: a3ff0ea82bf4ae28a1a08fde2084e1a4b83e29a17a1ea10b1f56e931f6196769475f9b43f1167e8b319969c5bcbb1cb61a5fd3a99efe304817cdcc2f41f9e1b7
ssdeep: 12288:ugkDxdkL+6JNgKVcRa+fpHyWs3OBH4pU8vAx:YxsKXa+hHyWseBge
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Killav.DR also known as:

BkavW32.YoyasvC.Trojan
MicroWorld-eScanGen:Variant.Ulise.3192
FireEyeGeneric.mg.85715aa52cf7dada
CAT-QuickHealTrojan.KillAv.DR
Qihoo-360Backdoor.Win32.Agent.GF
McAfeeBackDoor-EJG
CylanceUnsafe
ZillyaTrojan.Chydo.Win32.10
SangforMalware
K7AntiVirusTrojan ( 003b31ad1 )
BitDefenderGen:Variant.Ulise.3192
K7GWTrojan ( 003b31ad1 )
Cybereasonmalicious.52cf7d
Invinceaheuristic
BitDefenderThetaAI:Packer.44A4C33920
F-ProtW32/KillAV.M.gen!Eldorado
SymantecTrojan.Dropper
ESET-NOD32Win32/AutoRun.Agent.TV
BaiduWin32.Worm.Agent.ht
APEXMalicious
AvastWin32:AutoRun-BDI [Wrm]
ClamAVWin.Malware.Pykspa-6723765-0
GDataGen:Variant.Ulise.3192
KasperskyIM-Worm.Win32.Chydo.axa
AlibabaWorm:Win32/Chydo.b05b5fa3
NANO-AntivirusTrojan.Win32.Chydo.eaicht
ViRobotTrojan.Win32.Chydo.516096
TencentWorm.Win32.Pykspa.b
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ulise.3192 (B)
ComodoTrojWare.Win32.Autorun.KTV@4q6joa
F-SecureTrojan:W32/Chydo.gen!A
DrWebTrojan.MulDrop4.60762
VIPRETrojan.Win32.Pykspa.a (v)
TrendMicroWORM_MESSEN.SMF
McAfee-GW-EditionBehavesLike.Win32.Backdoor.gc
Trapminemalicious.high.ml.score
CMCTrojan.Win32.Chydo!O
SophosTroj/Bckdr-RAK
IkarusTrojan.Dropper.Agen
CyrenW32/KillAV.M.gen!Eldorado
JiangminTrojan/Generic.azgqm
WebrootW32.Trojan.Chydo.Gen
AviraTR/Chydo.TF
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Chydo
MicrosoftTrojan:Win32/Killav.DR
ArcabitTrojan.Ulise.DC78
SUPERAntiSpywareTrojan.Agent/Gen-Pykspa
AhnLab-V3Trojan/Win32.Chydo.R4045
ZoneAlarmIM-Worm.Win32.Chydo.axa
TotalDefenseWin32/Pykspa.A!genus
Acronissuspicious
VBA32BScope.Dropper.gen
ALYacGen:Variant.Ulise.3192
TACHYONTrojan/W32.Chydo.503808.F
Ad-AwareGen:Variant.Ulise.3192
MalwarebytesTrojan.Chydo
PandaTrj/Chydo.A
TrendMicro-HouseCallWORM_MESSEN.SMF
RisingTrojan.DL.Dwonk!1.662D (CLOUD)
YandexWorm.Chydo!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.LGB!tr
AVGWin32:AutoRun-BDI [Wrm]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Chydo.axa

How to remove Trojan:Win32/Killav.DR?

Trojan:Win32/Killav.DR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment