AVKillah


· Overview ·
· Origins ·
· Operation ·
· Detection and Removal ·
· Research ·



Overview

Vendor Notes:

From the doc: 'This will kill firewalls and anti viruses. This version is compressed, next version wont be. Starts up with the computer. Uses the active component startup method.' ... 'now kills 124 antivirus'/firewall/misc exes. I also made it undetected by norton anti virus.'

Alias:

destructive program [F-Prot], ProcKill [McAfee], Trojan Horse.LC [Panda], Trojan.Win32.AVKill.a [Kaspersky], Win32.AVKill [Computer Associates], Win32/AVKill!Trojan [Computer Associates], Win32/AVKill.A trojan [Eset]

Category:

Firewall Killer: Any hacker tool intended to disable a user's personal firewall. Some will also disable resident anti-virus software.

AV Killer: Any hacker tool intended to disable a user's anti-virus software to help elude detection. Some will also disable personal firewalls.

Trojan: Any program with a hidden intent. Trojans are one of the leading causes of breaking into machines. If you pull down a program from a chat room, new group, or even from unsolicited e-mail, then the program is likely trojaned with some subversive purpose. The word Trojan can be used as a verb: To trojan a program is to add subversive functionality to an existing program. For example, a trojaned login program might be programmed to accept a certain password for any user's account that the hacker can use to log back into the system at any time. Rootkits often contain a suite of such trojaned programs.

Variants:

  • AVKillah 2
  • Similar Pests:

    Firewall Killer · AV Killer · Trojan

    Origins

    Author:

    Phr0stic

    Group:

    theCorpz

    By This Group:

    AVKillah 2 ·

    Date of Origin:

    Variants from April, 2002 to April, 2002

    Operation

    Storage Required:

  • AVKillah: at least 61 KB
  • AVKillah 2: at least 13 KB
  • Detection and Removal

    Automatic Removal:

    PestPatrol detects this.

    PestPatrol removes this.



    Manual Removal:

    Follow these steps to remove AVKillah from your machine. Begin by backing up your registry and your system, and/or setting a Restore Point, to prevent trouble if you make a mistake.
    Stop Running Processes:

    Kill these running processes with Task Manager:

    Remove Files:

    Remove these files (if present) with Windows Explorer:

    Research

    File Analyses:

    More Info:

  • AllTheWeb, AltaVista, AOL Search, Ask Jeeves, Google, HotBot, Lycos, LookSmart, MSN, Yahoo!
  • Research By:

  • PestPatrol's Pest Research Center
  • Last Revised:

    February 25, 2005