Home / malwarePDF  

HackTool:Win32/ProcKiller.C


First posted on 23 August 2011.
Source: SecurityHome

Aliases :

HackTool:Win32/ProcKiller.C is also known as W32/SecRisk-ProcessPatcher-Sml-based!Maximus (Authen, RiskTool.Win32.ProcessPatcher.Sml!cobra (Sunbelt Sof.

Explanation :

HackTool:Win32/ProcKiller.C is a tool used to forcefully terminate a running process.


Top

HackTool:Win32/ProcKiller.C is a tool used to forcefully terminate a running process.

When executed, it displays a screen similar to the following:



The user can then choose to forcefully terminate the following antivirus programs:

  • AhnLab V3 Lite
  • Ahnlab SiteGuard
  • ESTSoft ALYac 1.5
  • ESTSoft ALYac 2.0 Beta


The user can also choose to terminate a certain service or process by specifying the service name or process ID.



Analysis by Chun Feng

Last update 23 August 2011

 

TOP