Malware

Win32/KillMBR.NCO removal instruction

Malware Removal

The Win32/KillMBR.NCO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/KillMBR.NCO virus can do?

  • Uses Windows utilities for basic functionality
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Writes a potential ransom message to disk
  • Anomalous binary characteristics

How to determine Win32/KillMBR.NCO?


File Info:

crc32: F63C43D9
md5: fab05c128b683d1e2d4ef981b4f1905a
name: FAB05C128B683D1E2D4EF981B4F1905A.mlw
sha1: 9374501e77dc72c515d6a5c8f4ffe5656c70d896
sha256: a0ed70e10cde5f96cd36166a235c3ca13007181d83636a971e992467c9cfc272
sha512: 75addc6745c27d2c494e1de22082257c7f725dcd668243e5bcf1a652d1e1cb1c7ce09db385eb71b9b6e58feeaa7d15b6454b19ef2b478a72ad73113d8174afb7
ssdeep: 1536:wNx32nZ7n9Ji4+IrLFAAi524020CVdDATOwt77X0goavwiw:w/2nR9Ji4+IrLW240FCVBATEgoavQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/KillMBR.NCO also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052b6931 )
Elasticmalicious (high confidence)
DrWebTrojan.MBRlock.281
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.30462464
CylanceUnsafe
ZillyaTrojan.Carbanak.Win32.7
SangforTrojan.Win32.Atosev.rfn
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojanSpy:Win32/KillMBR.8f9c0d08
K7GWTrojan ( 0052b6931 )
Cybereasonmalicious.28b683
CyrenW32/Carbanak.TVJG-0788
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/KillMBR.NCO
ZonerTrojan.Win32.66962
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Ransomware.UselessDisk-6492359-0
KasperskyHEUR:Trojan-Spy.Win32.Carbanak.gen
BitDefenderTrojan.GenericKD.30462464
NANO-AntivirusTrojan.Win32.Carbanak.ezedbo
MicroWorld-eScanTrojan.GenericKD.30462464
TencentMalware.Win32.Gencirc.11492840
Ad-AwareTrojan.GenericKD.30462464
SophosMal/Generic-S
ComodoMalware@#1abdtv71ryukq
BitDefenderThetaGen:NN.ZexaF.34670.luX@aO9tpwk
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_MBRLOCKER.SMALY
McAfee-GW-EditionRansom-KillMBR!FAB05C128B68
FireEyeTrojan.GenericKD.30462464
EmsisoftTrojan.GenericKD.30462464 (B)
JiangminTrojanSpy.Carbanak.a
AviraTR/KillMBR.wsjln
Antiy-AVLTrojan[Spy]/Win32.Carbanak
MicrosoftRansom:Win32/Pitroxin.A
ArcabitTrojan.Generic.D1D0D200
AegisLabTrojan.Win32.Carbanak.tpmX
GDataTrojan.GenericKD.30462464
AhnLab-V3Trojan/Win32.RL_DiskWriter.R355055
McAfeeRansom-KillMBR!FAB05C128B68
MAXmalware (ai score=83)
VBA32BScope.TrojanSpy.Carbanak
MalwarebytesRansom.Petya
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_MBRLOCKER.SMALY
RisingRansom.Pitroxin!1.B225 (CLOUD)
YandexTrojan.GenAsa!4sneWOrtzb8
IkarusTrojan.Win32.KillMBR
FortinetW32/KillMBR.NCO!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.KillMBR.HwIApQsA

How to remove Win32/KillMBR.NCO?

Win32/KillMBR.NCO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment