Killapps.exe - reported by a2

I just started scann process with a2, and at the end of scan, I’ve got report that one file is classified as malware. The name of the file is KILLAPPS.EXE and it’s located in Windows/System32 subfolder (WindXP Pro SP2). I’ve searched all over the net and found this thread at Wilders forum:
http://www.google.ca/search?q=cache:g8LVPWp3MwsJ:www.wilderssecurity.com/showthread.php%3Ft%3D13039%26goto%3Dnextnewest+what+is+killapps.exe&hl=en

Some of them are saying that file belongs to some specific SoundBlaster cards (Audigy etc.), but I don’t have Audigy, my SoundBlaster model is SB Live! Value. I’ve also found out that some antiviruses are recognizing that file as malware, but after double checking by developers, they all agreed that it’s just a false positive.

I would really like to hear Alwil’s opinion, as we all know, to whome to trust if not to our host, hehe… is there any chance I can send that file to someone for further checking ?

Note: Never ever had any problems with my system in the past, it’s working flawlesly, but I’m just wondering what’s the story with that file… I don’t like to have anything that I don’t know what’s the purpose of it.

Here is the screenshot from a2…

Cheers !

You should have it tested here for a second opinion -
http://virusscan.jotti.dhs.org/

If you suspect a false positive - be sure to let Mr. Haak know over there at the a2 forum as well :wink:

I’ve got this (see attachment)… it looks like it’s non-destructive, but still, I don’t know why is it classified as malware… it comes from very good and respected sound card manufacturer… ???

Btw, thanks for the link… great !

Any thoughts Alwil ? Any opinion would be greatly appreciated.

I mean, it sounds so weird… characterized as Malware, but non-destructive malware… Malware is something like abbreviation from Malicious Software, if I’m not wrong… malicious is very close to destructive in these terms, so what shoudl I do when a2 asks me ? Completely delete the file or something else ? Biggest problem is 'cause I can’t find anything about the purpose of that file on Creative web site…

Well, according to the name, it sounds like a tool to kill other application. While some people may consider is “dangerous” (which is probably why it’s reported by KAV), it’s rather strange - you could report the Task Manager the same way.

If I’m getting it right (which only happens now and again ;D )
Riskware is legitimate software that can be used
to do harm.

Yeah, it’s really strange… why would any part of Creative Sound Blaster software package, like to “kill” some other processes ? Really strange…
I may try to completely erase it (uninstall Creative applications), clean the registry, and then reinstall it from the scratch… just to see what’s going to happen…

Hmmm my a2 doesn’t find Killapps.exe. in my creative drivers ???

Most likely not the same sound card. Mine is SB Live! Value… (quite different than normal SB Live!). Killapps.exe is located in Windows/System32 subfolder, not uder default Creative folder.

Also, there is another file that comes with that one, and it’s called Kill.ini
Here are contents of that file:

[KILL.B]
audiohqu.exe
rcman.exe

[KILL.A]
ahqrun.exe
ctltray.exe
ctltask.exe
ctplay2.exe
surmix2.exe
rcenter.exe
adgjdet.exe
mplayer2.exe
rcman.exe
cthelper.exe

As we all can see, those applications are Creative applications, nothing else… so it really looks like false alarm. I just reported it to a2 developers.

,

I don’t know, but this is official Creative web site where I downloaded latest drivers and utilities:
http://us.creative.com/support/downloads/download.asp

File is around 24 Mb…

I have that those drivers at least last 2 months, and never noticed anything unusual with my computer. Everything works perfect. avast! can’t find anything weird with that file, that’s why I asked if someone wants me to send that file for further checking. a2 is the only one program that reports it as malware, but not destructive malware as they said.

Cheers !

,

Sasha
ahqrun.exe For Creative Soundblaster Live! series soundcards. Specify for any audio application what audio preset to automatically associate with currently active speaker output. Available via AudioHQ
Stop worrying. It’s ok

Bob, ahqrun.exe is not a problem… file Killapps.exe is the one that a2 reports as malware…

EDIT: Maybe you guys didn’t notice, but those files listed and marked in blue color, are just text file, contents of Kill.ini file.

Only one that is suspicious is Killapps.exe

this is all I can up with:

There seems to be at least two different things here:-

a) Creative Labs’ Audigy sound card uses 2K_XP/Drivers/COMMON/killapps.exe. See here for details:- http://www.soundcard-drivers.com/drivers/58/58954.htm

b) Killapps - which is sofware used for the control of certain applications. See here:- http://www.killapps.com/screenshots.htm

c) Clearly, if the above two things do not apply, then we have to think in terms of malware.

The most likely explanation is the Audigy sound card.(see here:- http://research.pestpatrol.com/Anal...3-02_212212.asp).

Eliminate this possibility before considering anything else. It is not unknown for the heuristics of an AV to misinterpret the veracity of a prog designed to halt other processes.

Yes, that’s from Wilders forum I gave link for in my first post in this thread:

I've searched all over the net and found this thread at Wilders forum: http://www.google.ca/search?q=cache:g8LVPWp3MwsJ:www.wilderssecurity.com/showthread.php%3Ft%3D13039%26goto%3Dnextnewest+what+is+killapps.exe&hl=en

This Killapps.exe located in Windows/System32 subfolder is not sofware used for the control of certain applications… As I mentioed before, there is also Kill.ini file (part of this Killapps.exe) and it lists all Creative applications. I also wrote about that. See here:

http://forum.avast.com/index.php?topic=10465.msg89143#msg89143

Second problem… Sound Blaster Audigy is completely different product, much better than SoundBlaster Live! Value. I don’t have Audigy, but still have that file… it came withy latest driver updates from official Creative website.

I sent that sample to developers of a2, and we’ll see from there. Most likely I will never receive answer from them, because that’s what I’ve heard from some people that used to send some samples before… maybe, this time will be different, but that’s still just maybe…

Cheers !

Sasha
According to that info, what you have is a false positive from a2. It’s not the first one. and i’m sure there will be others.

Yes it really looks like that, but it’s maybe better to wait… we’ll see when I receive info from a2 team. For now, I just removed that file from System32 folder (I have backup)…

Cheers !

I just rename a suspicious file. exe=xee, com=moc, bat=tab, etc etc. ;D
Can’t run what doesn’t exist.

Yes I know, but I don’t want it to physically exist on my HD if it’s something suspicious, especially if it’s some file that I don’t even use. My sound card works great even without all those applications installed. Creative Mp3 player, 100% not needed, anyway I use WinAMP, Creative mixer good, but almost all those options and features you get with default Windows Mixer. Creative Rack in general, complete waste of HD space. The only real thing you need, are tose drivers…

I have backup and original installation CD, so if something goes wrong (and I’m 100% sure it won’t, because so far nothing is complaining about that file), I know what I have to do… however, I make backups of my whole system every week on Fridays, so one short visit to Ghost won’t cost me anything, haha ;D