Remove KillSec. Description and removal instructions

 
Title: KillSec

Type: Trojans
Severity scale:KillSec severity is 68  (68 / 100)
 
KillSec is a trojan that attempts to steal login names, passwords, account details and other confidential information that the victim enters on certain German banking web sites. Gathered data is transferred to a predefined remote host. The parasite can run a hidden FTP server or a proxy. It may also download and run malicious files and block access to popular security-related web resources. KillSec runs on every Windows startup.


KillSec properties:
• Allows remote user connection
• Logs keystrokes
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic KillSec removal:

remover for KillSec

KillSec manual removal:

Kill processes:
smss.exe, winlogon.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Windows Logon Process
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Windows Session Manager Subsystem
HKEY_CLASSES_ROOT\ib1dll6.CBrowserHelper
HKEY_CLASSES_ROOT\CLSID\{1E6CE4CD-161B-4847-B8BF-E2EF72299D69}
HKEY_CLASSES_ROOT\Interface\{8C691F25-C565-4FB7-8BCC-E85169BD7C47}
HKEY_CLASSES_ROOT\TypeLib\{14A5F3E7-B235-4D98-9264-5C67D2657BC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E6CE4CD-161B-4847-B8BF-E2EF72299D69}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E6CE4CD-161B-4847-B8BF-E2EF72299D69}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\InitRegKey
Delete files:
smss.exe, winlogon.exe
Misc:
KillSec files reside in the main system folder C:\Windows or C:\Winnt.

Other programs to remove KillSec:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 28/02/06
Information updated: 18/08/06

Additional resources related to KillSec:

Attention: If you know or you have a website or page about KillSec removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about KillSec parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by Guest. 2006-08-18 09:08:50
Only problem is when you remove 1.com file it also removes your Run32.dll file and no programs will run after reboot of the system. Every removal program I have found says the trojan is gone, but it always comes right back.


Latest spyware news:
Similar parasites:
Related discussions:
 virus