Forum     

Go Back   Digit Technology Discussion Forum > Community > Tutorials
Register FAQ Calendar Mark Forums Read

Tutorials This section offers tutorials and How to's on just about anything related to computers and IT. Note: All tutorials are courtesy the posters and not verified by Digit


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 26-11-2009, 02:51 PM   #1 (permalink)
Apprentice
 
ritesh.techie's Avatar
 
Join Date: Jul 2009
Location: Bhopal, India
Posts: 99
Exclamation Delete processes when taskamanger is disabled


Most of the viruses when attacks your computer they disables Taskmanager, so that you can’t kill the process/program (ie running virus) most of you got stuck when a nasty virus enters your Computer and take away all your happiness. You try hard to find the exe file name of this virus to kill it, but worst it disbales your taskmanager therefore you are not able to know which processs are running.

Do read our previous tutorial on How To: Delete Stored Network Passwords from Windows to Secure Network to improve your security.

Therefore I came up with a tutorial which will show you how to find out which processes are currently running on your system without using taskmanager, so that you can look for any running malicious program or a program of which you don’t have any information.


The command which we are using is TASKLIST.

Quote:
Syntax: TASKLIST [/S system [/U username [/P [password]]]]
[/M [module] | /SVC | /V] [/FI filter] [/FO format] [/NH]
This command line tool displays a list of application(s) and associated task(s)/process(es) currently running on either a local or remote system.

Here are some eg. which will show you how to use it effectively.Examples:

Quote:
TASKLIST
TASKLIST /M
TASKLIST /V
TASKLIST /SVC
TASKLIST /M wbem*
TASKLIST /S system /FO LIST
TASKLIST /S system /U domain\username /FO CSV /NH
TASKLIST /S system /U username /P password /FO TABLE /NH
TASKLIST /FI “USERNAME ne NT AUTHORITY\SYSTEM” /FI “STATUS eq running”
So now you have got the list of all process running on your system now its time to kill the malicious program.

The command which we are using for this is TASKKILL.

Quote:
Syntax: TASKKILL [/S system [/U username [/P [password]]]]
{ [/FI filter] [/PID processid | /IM imagename] } [/F] [/T]
This command line tool can be used to end one or more processes. Processes can be killed by the process id or image name.

Well if you want some more detaliled description go to command propmt and type TaskKill/?
Here are some eg. which will show you how to use it effectively. Examples:

Quote:
TASKKILL /S system /F /IM notepad.exe /T
TASKKILL /PID 1230 /PID 1241 /PID 1253 /T
TASKKILL /F /IM notepad.exe /IM mspaint.exe
TASKKILL /F /FI “PID ge 1000″ /FI “WINDOWTITLE ne untitle*”
TASKKILL /F /FI “USERNAME eq NT AUTHORITY\SYSTEM” /IM notepad.exe
TASKKILL /S system /U domain\username /FI “USERNAME ne NT*” /IM *
TASKKILL /S system /U username /P password /FI “IMAGENAME eq note*”

Summary: Find the list of running processes from TaskList command and kill the malicious program by using taskKill.
__________________
Get all latest tips and tricks at http://beingpc.com/
ritesh.techie is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 28-11-2009, 08:29 PM   #2 (permalink)
Alpha Geek
 
CA50's Avatar
 
Join Date: May 2007
Location: GraveYard
Posts: 918
Default Re: Delete processes when taskamanger is disabled

Thanks man its grt
__________________
| A Bit IP35-Pro | E8400 | GTS250 | Gskill 2x2GB | 1.9 TB | CM EP+ 460W | 2x DVD-RW|
| Win XP x86 | Win 7 Ult x86 | LinuxMint |
| Nokia 2700c |
CA50 is offline  
Old 28-11-2009, 09:14 PM   #3 (permalink)
Simply a DIGITian
 
krishnandu.sarkar's Avatar
 
Join Date: Nov 2007
Location: Kolkata
Posts: 2,956
Default Re: Delete processes when taskamanger is disabled

Wow......!! Awesum yaar.......!! Really gr8 tutorial...!!
__________________
  • Read The Forum RULES First.
  • Before PM'ing Or Asking Any Questions To Any Mod Read The FAQ's
  • Before Starting A New Thread Read The STICKY THREADS First
  • Before Participating In Bazaar Section Read The BAZAAR RULES
krishnandu.sarkar is online now  
Old 28-11-2009, 09:52 PM   #4 (permalink)
Apprentice
 
hluachawngthu's Avatar
 
Join Date: Apr 2006
Location: Look_east
Posts: 63
Default Re: Delete processes when taskamanger is disabled

This is really great tutorial. Could you go further that what type of a virus disabled Task Manager?
hluachawngthu is offline  
Old 29-11-2009, 10:37 AM   #5 (permalink)
In The Zone
 
TheHumanBot's Avatar
 
Join Date: Sep 2008
Posts: 320
Default Re: Delete processes when taskamanger is disabled

thanks for this tutorial
really awesome
__________________
Twitter Handle : /TheHumanBot
TheHumanBot is offline  
Old 29-11-2009, 11:32 AM   #6 (permalink)
"Aal Izz Well"
 
Krazzy Warrior's Avatar
 
Join Date: Apr 2008
Location: Inside ur BRaIN..!!
Posts: 1,832
Default Re: Delete processes when taskamanger is disabled

Pretty Nice Tut..
__________________
http://webchat.freenode.net/?channels=krow

http://twitter.com/krazzywarrior
Krazzy Warrior is offline  
Old 29-11-2009, 01:27 PM   #7 (permalink)
Alive Again...
 
satyamy's Avatar
 
Join Date: May 2005
Location: Mumbai
Posts: 1,668
Default Re: Delete processes when taskamanger is disabled

nice one......... and helpful too...
__________________
! जय हिंद ! Proud to be INDIAN
satyamy is offline  
Old 29-11-2009, 01:58 PM   #8 (permalink)
Coming back to life ..
 
it_waaznt_me's Avatar
 
Join Date: Nov 2003
Location: A bit closer to heaven
Posts: 1,997
Default Re: Delete processes when taskamanger is disabled

Hmmm .. Or just type this in Start > Run :

Code:
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f
Too bad there is no awk in Windows system or tasklist would've been of some advantage.
-----------------------------------------
Posted again:
-----------------------------------------
Hmmm .. Or just type this in Start > Run :

Code:
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f
Too bad there is no awk in Windows system or tasklist would've been of some advantage.
__________________
Sleight of hand and twist of fate...
On a bed of nails she makes me wait...
And I wait without you ...
With or without you ..
----
Batty = Too Busy Now !!!

Last edited by it_waaznt_me; 29-11-2009 at 01:58 PM. Reason: Automerged Doublepost
it_waaznt_me is offline  
Old 30-11-2009, 07:35 PM   #9 (permalink)
Broken In
 
rohitshubham's Avatar
 
Join Date: Jul 2008
Posts: 137
Default Re: Delete processes when taskamanger is disabled

thank you for the nice tip
rohitshubham is offline  
Old 04-12-2009, 10:47 AM   #10 (permalink)
Gracias Senor
 
dreams's Avatar
 
Join Date: Apr 2005
Location: Heven & Hell
Posts: 848
Default Re: Delete processes when taskamanger is disabled

thnx for the share..really useful for me, since diabled tm thru gpo.
__________________
iPT 2G(S) - 8GB - JBn
iPhone 3GS 16GB - JBn
MAC OSx86 on P4 2.4Ghz
HTC Touch - Elfin - P3452 - WM 6.5

- Dont Dre@m... Juz Chase it -
dreams is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Share your Tweaking Tips here Raaabo Software Q&A 305 23-06-2011 09:53 AM
Due Kernel I/O error, system refuses to boot randomly gary4gar Open Source 33 04-05-2008 10:22 AM
help me wid win xp services... mohit Software Q&A 2 12-03-2005 09:53 PM

 
Latest Threads
- by clmlbx
- by Krow
- by Who
- by Tech&ME
- by icebags

Advertisement




All times are GMT +5.5. The time now is 08:45 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2