Windows 7 Forums


Reply
Thread Tools

[SOLVED] Kill persistent malware processes before running your security software

 
 
Nibiru2012 Nibiru2012 is offline
Quick Scotty, beam me up!
Nibiru2012's Avatar
Join Date: Oct 2009
Location: Planet X
Posts: 4,851
Thanked: 1073
 
      06-07-2010
From: The Windows Club 6-7-2010

Sometimes persistent virus, spyware or malware processes will not allow a security software to run or to effect a complete removal of the infection, since these processes are themselves up and running on your Windows computer.


RKill is a easy to use tool that kills known processes that stop the use of normal anti-malware applications.

RKill just kills processes, imports a Registry file that removes incorrect file associations and fixes policies that stop us from using certain tools. Then it kills Explorer.exe so it will restart and enable some of the Registry changes. When done, RKill will then create a log listing all processes that were terminated while the program was running.

After running , it will display a log which will show the malware processes it has killed.


Now you should not reboot your computer as any malware processes that are set to start automatically, will just start up again.

Instead, after running RKill you should scan your computer using your malware removal tool of choice.

This will ensure a more complete removal of the malware which may have infected your Windows computer.

For download link & details visit BleepingComputer.

NOTE: It is HIGHLY recommended that you download RKILL when you need as it is updated on a daily basis at the BleepingComputer website, but does not have a auto update feature.
So download it when you need it so it will have the latest info.
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Catilley1092 will probably like this post!

Last edited by Nibiru2012; 12-21-2010 at 06:57 PM..
 
Reply With Quote
 
 
 
 
Kalario Kalario is offline
Aquarius
Kalario's Avatar
Join Date: Dec 2009
Location: Planet Gong
Posts: 586
Thanked: 64
 
      06-08-2010
Thanks Nibs...very informative. I am postmarking it for future use.
 
Reply With Quote
 
TrainableMan TrainableMan is offline
^ The World's First ^
TrainableMan's Avatar
Join Date: May 2010
Location: PA, USA
Posts: 4,654
Thanked: 887
 
      06-08-2010
Many of these malware programs protect themselves, when you stop one process another one watching restarts it. Is this effective against multiple programs at one time?
 
Reply With Quote
 
Nibiru2012 Nibiru2012 is offline
Quick Scotty, beam me up!
Nibiru2012's Avatar
Join Date: Oct 2009
Location: Planet X
Posts: 4,851
Thanked: 1073
 
      06-08-2010
According to the BleepingComputer website, it does work on multiple processes running at once.

Check it out, it is a very interesting website and has a lot of information.

Here's a screenshot:

 
Reply With Quote
 
catilley1092 catilley1092 is offline
Win 7/Linux Mint Lover
catilley1092's Avatar
Join Date: Nov 2009
Location: North Carolina, USA
Posts: 3,507
Thanked: 511
 
      06-09-2010
It also states that you may have to be persistent, starting the program several times to purge the malware. The tool appears to be worth having, I'll download it to my laptop and try it out on that first.
 
Reply With Quote
 
Veedaz Veedaz is offline
~
Veedaz's Avatar
Join Date: Sep 2009
Location: England
Posts: 1,988
Thanked: 330
 
      06-09-2010
RKill looks interesting, will download and see what it can do on a test PC thanks Nibiru.
 
Reply With Quote
 
yodap yodap is offline
No longer shovelling
yodap's Avatar
Join Date: Mar 2009
Location: NY, USA
Posts: 1,307
Thanked: 245
 
      06-09-2010
Thanks again, Nibs,
Keeping the info in my "anti bad stuff folder thingy"
 
Reply With Quote
 
Veedaz Veedaz is offline
~
Veedaz's Avatar
Join Date: Sep 2009
Location: England
Posts: 1,988
Thanked: 330
 
      06-18-2010
RKill works very well !, we have a test computer in the workshop (core 2 duo, 3 gig ram, twin HDDs, and ATI Asus 4830 GPU, Windows 7 Pro - 32-bit) after deliberately turning off Avast and visiting some very strange web sites and downloading all sorts of cr*p the test computer (now called TC) had a few infections / things running, within about one hour (scans with RKill and Avast) TC was %100 clean. So to conclude we will be keeping RKill on hand .... it Works !
 
Reply With Quote
 
TrainableMan TrainableMan is offline
^ The World's First ^
TrainableMan's Avatar
Join Date: May 2010
Location: PA, USA
Posts: 4,654
Thanked: 887
 
      11-27-2010
I have added a link to this thread from our freeware database because this is a good application for everyone to keep on a flash drive somewhere "just in case". You will need to update your copy periodically because this is updated when new processes are discovered. If at all possible, use an uninfected machine to retrieve it the day you actually need it.

Last edited by TrainableMan; 07-02-2011 at 03:43 AM..
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Software costs/usage limits/value. Mychael General Discussion 4 07-17-2010 09:57 AM
New attack bypasses EVERY Windows security product Jeffreyobrien Security 14 05-19-2010 04:11 AM
Homeland Security Warns About Latest Dangerous Apple Browser Bug Nibiru2012 Security 6 05-12-2010 05:01 PM
New Windows user needs help with security software Walldog Security 23 04-13-2010 03:48 PM
No/Delayed (11 min) Video Singal after POST until Windows Login screen Carl Urban General Discussion 4 03-31-2010 02:35 PM


All times are GMT +1. The time now is 09:10 AM.
W7Forums is an independent website and is not affiliated with Microsoft Corporation.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33