x
48h OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
SPECIAL OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
HALLOWEEN OFFER
take advantage of our
terrific discounts
BUY NOW AND GET A 50% OFF
x
CHRISTMAS OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 40% OFF
x
SPECIAL OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 50% OFF
x
BLACKFRIDAY OFFER
Buy the best antivirus
at the best price
TODAY ONLY UP TO 70% OFF
x
CYBERMONDAY OFFER
Buy the best antivirus
at the best price
(Only for homeusers)
TODAY ONLY UP TO 70% OFF
Active Scan. Scan your PC free
Panda Protection

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

KillRDLL.A

Threat LevelLow threatDamageHighDistributionNot widespread
Common name:KillRDLL.A
Technical name:Trj/KillRDLL.A
Threat level:Medium
Type:Trojan
Effects:  

It creates a copy of itself whenever the user accesses a directory. This file has the icon of a Windows folder and the extension hidden so that the user thinks it is a folder. It does not spread automatically using its own means.

Affected platforms:

Windows 2003/XP/2000/NT/ME/98/95

First detected on:June 23, 2009
Detection updated on:June 25, 2009
StatisticsNo

Brief Description 

    

KillRDLL.A is a Trojan designed to create a copy of itself whenever the user accesses a directory. This file has the icon of a Windows folder and the extension hidden so that the user thinks it is a folder.

If the user accesses any subdirectory, it also creates the copy of itself.

KillRDLL.A does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer.

Visible Symptoms 

    

KillRDLL.A is easy to recognize, as it displays the following symptoms:

  • Whenever the user accesses any directory, it creates a new folder, which is actually a copy of itself. The folder Favorites of the image, is in fact a copy of the Trojan disguised as a Windows folder:

  • These are some of the names it uses to create copies of itself, among others:
    Angelina Jolie
    Clips
    Documents
    Favorites
    Flash Games
    Games
    My Documents
    My Folder
    Picture
    Video
    WallPapers
  • Additionally, when it is run, it opens the website of a search engine which falsifies the results:

>

>