05-25-2015, 05:14 PM
(05-23-2015, 08:16 PM)AlexCa Wrote:(05-23-2015, 11:23 AM)Britec Wrote: I did try and use your program Alex on a infected machine, don't know if you see it. You might need to try and work out a way to stop malware stopping your program. This is one of the biggest problems with apps like these. Not bashing your program, just testing.
Hi Britec! I haven't saw it before, thank you for re-visiting my program I'll add that feature to my "to do" list, i'll have to research about that (that's a great suggestion)
For now i would suggest rkill or a AV boot cd to deal with extreme cases like those; or even a first run with Malwarebytes Chamaleon/MBAM, like you used, and then continue using Windows Repair Toolbox at will.
One way of achieving it may be to give the process(es) a alternative and random name. In the SAS program there is a Alternative start option which shows up in Task Manager as a random number (such as 2855179.exe), another option (and a better one) would be to give the program a .com extension as opposed to a .exe. This tends to fool malware into thinking it's a browser type program and as most malware need the internet to 'phone home' they tend to allow the process to continue. SAS Portable Free used to have this ability but they removed it some time ago, now I think the (purchased) Technicians Portable version is the only one that uses it.