File verdict·Decided by the MT AI Engine
Our call

Malicious

DefenderRemover.rar is a hacktool archive that disables Windows Defender using registry edits, PowerRun.exe, and scripts, confirmed by multiple tier-1 engines as KillAV.

KillAV
Trust score12Critical
MT AI confidence · 95%
DefenderRemover.rar
501.1 KB
b0398334d391988cfff8666f8df0
Antivirus engines
33 of 76 flagged
Code signing
Unsigned
Age
First seen 1mo ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

95%Confidence
Very high
Reasoning

High tier-1 malicious detections (12/17) focus on KillAV and Defender-disabling behavior, corroborated by dropped files like Remove_Defender reg files and PowerRun.exe. Hacktool labels from TrendMicro and others confirm offensive tooling. Unsigned RAR with security-tool-like filename but malicious intent. Behaviour shows impairment techniques (T1562.001) despite no sandbox consensus. Rare new file lacks positive history.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. ESET-NOD32 tier1 'BAT/KillAV.NHR trojan'

  2. TrendMicro tier1 'HackTool.Win32.KILLAV.G' with labelFlags.hacktool=true

  3. behaviour.offensiveTechniques 'T1562.001'; dropped files 'PowerRun.exe', 'Remove_Defender' reg files

  4. 12 tier1Malicious detections

  5. Ikarus tier1 'Trojan.WinREG.DisableDefender'

Points in its favour
  • No droppedChildren.hasMaliciousChild
  • No behaviour.hasMaliciousSandboxVerdict
  • No contactedHosts.maliciousHosts
Points against
  • 12/17 tier-1 engines malicious
  • Hacktool.KillAV detections (ESET, TrendMicro)
  • Drops Defender-disabling .reg and .ps1 files
  • PowerRun.exe for privilege escalation
  • MITRE T1562.001 (impair defenses)
  • Direct IP contact (162.159.36.2)
What to do

Quarantine and delete this file immediately. Perform a full system scan and verify Windows Defender status; restore from backup if tampered. Avoid running unknown 'remover' tools.

Threat family attribution

killav corroborated by 2 sources

  • VT (76 engines)
    killav
  • MT AI Engine
    KillAV
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
5

Adversary techniques mapped to the MITRE ATT&CK framework.

T1071T1082T1202T1497T1562.001
Spawned processes
6
$(unnamed)
"C:\Users\<USER>\AppData\Local\Temp\DefenderRemover.exe"
$(unnamed)
C:\Windows\system32\cmd.exe /c .\Script_Run.bat
$(unnamed)
choice /C:yas /N
$(unnamed)
C:\Windows\SysWOW64\unarchiver.exe "C:\Windows\SysWow64\unarchiver.exe" "C:\Users\user\Desktop\DefenderRemover.rar"
$(unnamed)
C:\Windows\SysWOW64\7za.exe "C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\llwlaa0a.51m" "C:\Users\user\Desktop\DefenderRemover.rar"
$(unnamed)
C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Network activity
1
IP addresses1
  • 162.159.36.2
Filesystem & mutexes
12
Files written12
  • C:\Users\<USER>\AppData\Local\Temp\7zSDF63.tmp\Remove_Defender
  • C:\Users\<USER>\AppData\Local\Temp\7zSDF63.tmp\Remove_SecurityComp
  • C:\Users\<USER>\AppData\Local\Temp\7zSDF63.tmp\RemoveSecHealthApp.ps1
  • C:\Users\<USER>\AppData\Local\Temp\7zSDF63.tmp\Remove_Defender\NomoreDelayandTimeouts.reg
  • C:\Users\<USER>\AppData\Local\Temp\7zSDF63.tmp\Remove_Defender\Output.reg
+7 more
Dropped payload

Files this sample writes at runtime

This file drops 10 children at runtime. None are currently flagged malicious in our cache.

10 unseen
  • 4108605207ef00fcbbfe82caccNever scanned
    never seen before
  • ffb369c1b359a99845d2fb9ba7Never scanned
    never seen before
  • 7d5785c1760909ac5dc6414913Never scanned
    never seen before
  • c717111084ec331d2d546cf674Never scanned
    never seen before
  • 9ddb1443316f0939106434bd16Never scanned
    never seen before
  • 778aa04d6a9395d77e160901e8Never scanned
    never seen before
  • 32ad97e2b83d1eb8b49caaa7cbNever scanned
    never seen before
  • a6fa768c4964c328c7481688d2Never scanned
    never seen before
  • b29d37c2d89b1d20ae79c35d32Never scanned
    never seen before
  • 167fd8c272e60eaf47d8e31bb4Never scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.

1 synthesis
MITRE ATT&CK profile
C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • DirectIpC2medium

    Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    162.159.36.2
Antivirus engine breakdown

33 detections across 76 engines

33 malicious0 suspicious43 clean
Tier-117 engines
12flag
Top commercial AVs (low FP rate)
Tier-238 engines
14flag
Mainstream engines with mixed FP rates
Low-trust21 engines
7flag
Heuristic / generic-AI engines (high FP rate)
AhnLab-V3
malicious
Malware/Win.Generic.R506848
alibabacloud
malicious
Trojan:Win/KillAV.NJY
Antiy-AVL
malicious
Trojan/BAT.DEFDISABLE
Avast
malicious
Script:SNH-gen [Trj]
AVG
malicious
Script:SNH-gen [Trj]
Avira
malicious
TR/Redcap.ssaok
CAT-QuickHeal
malicious
Hacktool.Powerrun
CTX
malicious
rar.trojan.killav
Cynet
malicious
Malicious (score: 99)
DeepInstinct
malicious
MALICIOUS
ESET-NOD32
malicious
BAT/KillAV.NHR trojan
F-Secure
malicious
Trojan.TR/Redcap.ssaok
Fortinet
malicious
W32/PossibleThreat
GData
malicious
BAT.Trojan.Agent.CW8GCS
Google
malicious
Detected
Gridinsoft
malicious
Trojan.Win32.Wacatac.cl
huorong
malicious
Trojan/BAT.KillAV.s
Ikarus
malicious
Trojan.WinREG.DisableDefender
K7AntiVirus
malicious
Hacktool ( 005d8d3d1 )
K7GW
malicious
Hacktool ( 005d8d3d1 )
Lionic
malicious
Trojan.Win32.KillAV.4!c
Malwarebytes
malicious
RiskWare.KillAV
Rising
malicious
Trojan.KillAV/BAT!8.13304 (CLOUD)
Sangfor
malicious
Hacktool.Win32.KillAV.Vw55
Skyhigh
malicious
BehavesLike.Dropper.hc
Sophos
malicious
Mal/Generic-S
Symantec
malicious
Trojan.Gen.NPE
Tencent
malicious
Win32.Trojan.Redcap.Yolw
TrellixENS
malicious
Artemis!817E8F46B739
TrendMicro
malicious
HackTool.Win32.KILLAV.G
TrendMicro-HouseCall
malicious
HackTool.Win32.KILLAV.G
Varist
malicious
W32/ABApplication.KFYU-4662
Webroot
malicious
W32.Malware.gen
Hash b0398334d391… cross-referenced against 76 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Barely seen in the wild and first surfaced recently. This is the footprint of targeted malware the AV industry hasn't signatured yet — extra scrutiny is warranted.

Rare & new
Unique uploaders
1
Very few people have ever uploaded this — rare.
Total submissions
1
Includes repeat uploads by the same source.
First seen by VT
1mo ago
Apr 20, 2026
Prevalence quadrant
here
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
4/20/2026, 3:28:03 PM
First seen (MalwareBazaar)
Last analysis (VT)
4/22/2026, 5:32:18 AM
Scanned here
4/24/2026, 2:02:51 AM
File name
DefenderRemover.rar
Size
501.1 KB
MIME type
application/x-compressed
Detected type
RAR
SHA-256
b0398334d391988cff2025b8aff0a925003f5afa70ceb4a3903212f8666f8df0
MD5
817e8f46b7399b4186f87625415ee332
SHA-1
3cde3c5ffb33df115aaafab51bf9fdafa162fc92
First seen (VT)
4/20/2026, 3:28:03 PM
Last analysis (VT)
4/22/2026, 5:32:18 AM
First scan (MalwareTips)
4/20/2026, 3:29:07 PM
Last scan (MalwareTips)
4/24/2026, 2:02:51 AM
Behavior tags
rardetect-debug-environment
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Scanned by
JackStaff
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.