hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Starskiller ;-)
starsky32
Hello :-)

I was a bit tired of using my old batch file to kill AV/FW, so I wrote this little tool.
It's faster and smaller than a batch file and not yet detected as other similar tools.

It's the Starsky-Killer=Starskiller (what an inventive name lol), here's the readme file:

CODE

                             = Starskiller v1.0 =

*Description:
-------------

Starskiller is a tool to kill processes / stop services of Antivirus/Firewalls
(able to shutdown more than 500 AV/FW killed - 533 processes killed and 373 services stopped)

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
> Fast killing/stopping. Small Exe file.

> Good Base list included.

> Not yet detected (23/04/2004)

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

This tool was coded for educationnal & testing purposes, don't do illegal things with it, I'm not responsible of the usage you *can* make of this tool.

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

__Starsky32__

...


+(internal database of processes/services killed/stopped listed in the readme)


Note:I intend to update the AV/FW database (and add other functionnalities to the program) regulary, but I need your help to do this. In order to have a better and better AV/FW database, you can help me and contribute if you want.
If board admins are ok,maybe you can post in this thread new processes or services names to include (but be precise : I don't want to stop anything else than AV/FW or similar products so don't post useless things and if not obvious indicate the name of the product associated with the service/process to stop), and I will be able to update the tool more often.
Please report bugs if any too ;-)


Starsky32.
manni
thx i will have a look
Janosch
nice tool, great work

i'll test it out
Tyrano
looks good, how about the source code? wink.gif
tweakz20
QUOTE
This tool was coded for educationnal & testing purposes, don't do illegal things with it, I'm not responsible of the usage you *can* make of this tool.


education = source please??

VERY nice and complete internal db.. good job!
nice name lol
qcred11
I was looking for this tool for a long time. Nice work. Thanks man.
Blaster99
thx 4 this great tool !
ZiRo
Very nice tool thanks for sharing.. biggrin.gif
Jellymech
nice tool , thx for sharing wink.gif

btw my mcafee got it.
starsky32
Sorry Jellymech, I haven't notice mcaffe detected my tool. What does he said ?
Well btw it's not a problem, I will provide soon a new version with more than 20 new AV processes/services added to the baselist and I will code it differently, so we will see how much time it will take to mcaffe to got it next time...

(if you want to see new processes/services included in this tool, don't hesitate to pm me...)

Starsky32.
passi
hey nice work starsky biggrin.gif

you're right, a new section with actual FW / AV process and executeable names would be great!

PS: not jet detected by my AVK smile.gif
jimmy
KAV detects it as well
starsky32
QUOTE (jimmy @ May 24 2004, 02:58 AM)
KAV detects it as well

So it's time for a small update wink.gif

Here it is. I checked it, KAV doesn't detect it with the latest definitions. As I have not at this time the possibility to test with other AV, please tell me if it's detected by some AV/antitrojan etc...


Have fun,don't do illegal things with it, I'm not responsible etc...etc...



manu
Very nice dude,

Please add ZLCLIENT.EXE too in your database..

AVG Antivirus is not detecting your tool.. Great work m8.

Manu biggrin.gif
dotcom
I'll run it past a few A/V's to test and give a proper response soon. Thanks for sharing it with the GSO ppl starsky32

Also good to mention maybe once again advising not to use the online scanners to test, use an installed version so no alerting all the A/V companies as to why so many people checked an "undetected" file, so many testing the same file.....
Figo
Really great tool!
Nice work wink.gif
COM
Thanks for that killer rolleyes.gif
nvidia247
thanks man, gonna try this app out...

looks promising..cheers
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.