Published Jan 17, 2011|Updated Sep 15, 2017


Alert level: Severe Detected with Windows Defender Antivirus

Also detected as: Win-Trojan/Rootkit.6280.H (AhnLab) Rootkit.Win32.Agent.bipu (Kaspersky) Rootkit.Agent2!cpMP978OkXs (VirusBuster) Rkit/Agent.bipu (Avira) Trojan.KillProc.KP (BitDefender) Trojan.NtRootKit.9781 (Dr.Web) Win32/KillAV.NKC (ESET) Rootkit.Win32.Agent (Ikarus) RootKit.Win32.Undef.cuo (Rising AV) Mal/Efic-A (Sophos) Hacktool.Rootkit (Symantec)

Trojan:WinNT/KillAV.E is a kernel mode rootkit, which is used to terminate processes related to antivirus and security software. It may also perform other functions, such as deleting files, overwriting registry entry data, and others.


Latest news