Content

PRocKill-CR

Type
Program
SubType
ProcKill
Discovery Date
05/02/2005
Minimum DAT
4481 (05/02/2005)
Updated DAT
4573 (09/02/2005)
Minimum Engine
5.1.00
Description Added
05/02/2005
Description Modified
05/24/2005 3:55 AM (PT)

Tab Navigation

Characteristics

This detection is not for a trojan/virus but for a "potentially unwanted program (pup)".  The detection of this type of files is not automatically activated.
Users who would like to check for the presence of this kind of files on their system should run the command line scanner with the /PROGRAM switch.
Please note that VirusScan 7 has also an option, which enables users to detect this kind of program automatically (see below).
This type of detection also exists within e250/e500 Webshield filtering devices.

Detection was added to cover for an arguable 32 bit PE file originally called "svcproc.exe " , having a filesize of 5632 bytes. The file is internally compressed with upx.

Upon running the file, it runs silently. No messageboxes nor a graphical user interface appears.

The file can be used to open sc manager, open a service for Deletion. A silent delete of a service is arguable.

It doesn't drop/modify files nor change the registry.

Files such as this can be used regularly by system admins but they can also be misused by hackers hence the pup detection.

Aliases

Aliases

    N/A