How to: Kill process which just keep coming back

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Xon
Sith Acolyte
Posts: 6206
Joined: 2002-07-16 06:12am
Location: Western Australia

How to: Kill process which just keep coming back

Post by Xon »

Sometime when trying to clean a computer you get malware which keeps respawning from the grave.

Some tricky ones will even take ownership of the file to another user and monitor the file and reset it back when you try and change it.

If only there was some way to tell Windows to not load an application or extension. But there is(well for 2k/XP Pro/2k3, XP Home is out of luck)!

Run "secpol.msc", "Software Restriction Policies", right click and select the "new security policies"(it should be the only option in the rightclick menu). Then browse to "Additional Rules", right click -> "New <rule type> rule" and you can determine how you want to identify the file (md5/SHA-1 hash or path, etc), and windows will never run the file again.

You can then go to "Software Restriction Policies" and double click on "Enforcement", and determine if it applies to just the main executable or all libraries loaded by it and some other minor stuff.

This allows for preventing an application to run were you can not remove the file or alter the permisions for some reason.
Last edited by Xon on 2005-06-09 10:20am, edited 1 time in total.
"Okay, I'll have the truth with a side order of clarity." ~ Dr. Daniel Jackson.
"Reality has a well-known liberal bias." ~ Stephen Colbert
"One Drive, One Partition, the One True Path" ~ ars technica forums - warrens - on hhd partitioning schemes.
User avatar
Xon
Sith Acolyte
Posts: 6206
Joined: 2002-07-16 06:12am
Location: Western Australia

Post by Xon »

Crud, this isnt in the right forum. Can some mod dump this in the write place?
Last edited by Xon on 2005-03-02 06:22am, edited 1 time in total.
"Okay, I'll have the truth with a side order of clarity." ~ Dr. Daniel Jackson.
"Reality has a well-known liberal bias." ~ Stephen Colbert
"One Drive, One Partition, the One True Path" ~ ars technica forums - warrens - on hhd partitioning schemes.
User avatar
Grand Admiral Thrawn
Ruthless Imperial Tyrant
Posts: 5755
Joined: 2002-07-03 06:11pm
Location: Canada

Post by Grand Admiral Thrawn »

Right forum, not write forum. :wink:
"You know, I was God once."
"Yes, I saw. You were doing well, until everyone died."
Bender and God, Futurama
User avatar
InnocentBystander
The Russian Circus
Posts: 3466
Joined: 2004-04-10 06:05am
Location: Just across the mighty Hudson

Post by InnocentBystander »

Useful info, maybe we can sticky this, or even add it to some sort of "Computer Troubles Knowledge base"?
User avatar
Stormbringer
King of Democracy
Posts: 22678
Joined: 2002-07-15 11:22pm

Post by Stormbringer »

Spybot Search and Destroy has some tools for that.

Other than that something like Hijack This! is probably necessary.
Image
User avatar
Xon
Sith Acolyte
Posts: 6206
Joined: 2002-07-16 06:12am
Location: Western Australia

Post by Xon »

Grand Admiral Thrawn wrote:Right forum, not write forum. :wink:
I posted that at 1:13 am after finishing some reading on the msdn!
"Okay, I'll have the truth with a side order of clarity." ~ Dr. Daniel Jackson.
"Reality has a well-known liberal bias." ~ Stephen Colbert
"One Drive, One Partition, the One True Path" ~ ars technica forums - warrens - on hhd partitioning schemes.
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

Remind me to FAQ this if I haven't done it in a few days, ggs.
User avatar
Vertigo1
Defender of the Night
Posts: 4720
Joined: 2002-08-12 12:47am
Location: Tennessee, USA
Contact:

Post by Vertigo1 »

I'll have to make a note of that somewhere. Thx for posting this.
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong

Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
Post Reply