GSLC · Question #399
You work as a Network Administrator for Infosec Inc. The company has a Windows 2003-based server. You have installed McAfee antivirus as well as anti-spyware software on the server. One day, you…
The correct answer is B. FireKiller 2000. FireKiller 2000 is a malware tool specifically engineered to locate and terminate active security processes such as firewalls, antivirus engines, and anti-spyware, and to delete their definition databases.
Question
You work as a Network Administrator for Infosec Inc. The company has a Windows 2003-based server. You have installed McAfee antivirus as well as anti-spyware software on the server. One day, you come to know that not only have the security applications running on the server (including software firewalls, anti-virus, and anti-spyware) been disabled, but the anti-virus and anti-spyware definitions have also been deleted. You suspect that this is due to malware infection. Which of the following types of malware is the most likely cause of the issue?
Options
- AWhack-A-Mole
- BFireKiller 2000
- CBeast
- DSubSeven
How the community answered
(48 responses)- A6% (3)
- B77% (37)
- C2% (1)
- D15% (7)
Why each option
FireKiller 2000 is a malware tool specifically engineered to locate and terminate active security processes such as firewalls, antivirus engines, and anti-spyware, and to delete their definition databases.
Whack-A-Mole is a malware variant known for replicating itself to evade removal attempts, not for systematically targeting and disabling security software or deleting definition files.
FireKiller 2000 is classified as a security-disabling malware whose primary purpose is to kill running security application processes and erase virus and spyware definition files, directly matching the scenario where all security tools were disabled and definitions deleted simultaneously.
Beast is a Remote Access Trojan (RAT) designed to provide an attacker with covert remote control over a victim machine; it is not primarily designed to kill security applications or erase their definitions.
SubSeven (Sub7) is also a Remote Access Trojan used for covert remote control and data theft, not for systematically disabling antivirus software or deleting security definitions.
Concept tested: Security-disabling malware identification
Topics
Community Discussion
No community discussion yet for this question.