Trojan

What is “Trojan:Win32/Killav!pz”?

Malware Removal

The Trojan:Win32/Killav!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Killav!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Killav!pz?


File Info:

name: C2274784D98749479931.mlw
path: /opt/CAPEv2/storage/binaries/bba2e518641509dfb84633879c27ff263e17c3438ec0a5e195fb16941bc99090
crc32: F846DFC4
md5: c2274784d9874947993158ae08cc2ad0
sha1: c23fd6a5bbae48a8e377665ad598bef7712dbbc5
sha256: bba2e518641509dfb84633879c27ff263e17c3438ec0a5e195fb16941bc99090
sha512: db3fb6bef03b3b50a663f56d022f948b12eb19b3dcbc8551626aee751988264bf883907fea3e059510bb6e55f18f7006885500da772217df706165674f21aa8b
ssdeep: 1536:xaKBPMrRyJVy9H4jN9cotLJo0XpAfTaU9v3nXXUr9WuXKrNgHCv8KG2ej+4s:EKNM1yi9YjrtSGpA7JvnXnu4GF6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T134D4D0437CEA97B6E9733571B7FEC7BCE223D24824418E363651C9BD3E226A16C48518
sha3_384: 304fd8c46722bb023c4ab50941ebe9618d35207fe022c721000f565dfeb0161758fc1ebf007d77dee93cbe90182cd08a
ep_bytes: 5589e583ec08c7042402000000ff15fc
timestamp: 2012-09-07 01:45:45

Version Info:

0: [No Data]

Trojan:Win32/Killav!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.b!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Symmi.2478
ClamAVWin.Trojan.Generic-9763885-0
FireEyeGeneric.mg.c2274784d9874947
CAT-QuickHealTrojan.KillAv.DR
SkyhighGenDownloader.qt.a
McAfeeGenDownloader.qt.a
MalwarebytesRansom.FileCryptor
ZillyaDropper.Injector.Win32.38152
SangforDropper.Win32.AutoRun.V5u9
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojanDropper:Win32/AutoRun.089ac05b
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.5bbae4
BitDefenderThetaGen:NN.ZexaF.36744.MyZ@aOcKwOb
VirITTrojan.Win32.Generic.BOXX
SymantecW32.Rontokbro@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.XW
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Injector.fsfc
BitDefenderGen:Variant.Symmi.2478
NANO-AntivirusTrojan.Win32.Inject.bbujfb
AvastWin32:DangerousSig [Trj]
TencentMalware.Win32.Gencirc.10b7270b
EmsisoftGen:Variant.Symmi.2478 (B)
F-SecureTrojan.TR/Jorik.EB.3
DrWebWin32.HLLW.Autoruner1.24454
VIPREGen:Variant.Symmi.2478
TrendMicroTSPY_INJECTOR_BK0842B8.TOMC
Trapminesuspicious.low.ml.score
SophosMal/Inject-CEE
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.2478
JiangminTrojanDropper.Injector.agsz
WebrootW32.Trojan.Gen
VaristW32/Jorik.H.gen!Eldorado
AviraTR/Jorik.EB.3
Antiy-AVLTrojan[Dropper]/Win32.Injector
KingsoftWin32.Troj.Undef.a
XcitiumTrojWare.Win32.Injector.FSFC@4roe8t
ArcabitTrojan.Symmi.D9AE
ZoneAlarmTrojan-Dropper.Win32.Injector.fsfc
MicrosoftTrojan:Win32/Killav!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R34121
ALYacGen:Variant.Symmi.2478
MAXmalware (ai score=100)
VBA32BScope.Worm.VBNA
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_INJECTOR_BK0842B8.TOMC
RisingTrojan.KillAV!8.98 (TFE:5:jbeUF0iXOnC)
YandexTrojan.GenAsa!Z3+eExpa8dY
IkarusTrojan.Win32.KillAV
MaxSecureTrojan.Malware.4496151.susgen
FortinetW32/Injector.VZP!tr
AVGWin32:DangerousSig [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Killav!pz?

Trojan:Win32/Killav!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment