Re: match up threads and modules

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Alexander Grigoriev (alegr_at_earthlink.net)
Date: 01/08/05


Date: Fri, 7 Jan 2005 20:41:21 -0800

Open Task Manager, kill all explorer.exe. Your desktop shell will be gone,
along with the offensive DLL. You can then open CMD.exe (Task
Manager->File->Run) and delete the file.

<grunin@hotmail.com> wrote in message
news:1105088345.537493.212600@z14g2000cwz.googlegroups.com...
>
> Phil Taylor wrote:
>> does
>> >
> http://msdn.microsoft.com/library/default.asp?url=/library/en-us/perfmon/base/thread_walking.asp
>> > help?
>>
>> that gets you a process-id per thread, from there you should be able
> to get
>> it.
>
> No, I'm afraid that's not it: the process and process-id are already
> known, but I don't want to kill the process. I just want to kill the
> one thread that has been launched by the malware injected into the
> process.
>
> The problem remains determining which of the many threads (all owned by
> the process) is the right one to kill.
>
> Regards,
> Eric Grunin
>



Relevant Pages

  • Re: uninstall printer
    ... Open task manager (Crtl-Alt-Delete) and kill all the process associated ... If you're lucky, it's an HP and all the processes ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Outlook Express
    ... prior instance. ... and kill the oe process. ... Mary Ann ...
    (microsoft.public.windowsxp.general)
  • Re: Cant Delete Old User Folder for Changed Name
    ... Also open Task Manager (Ctrl + ... Alt + Del) kill explorer.exe and then ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Cant delete file; Cant delete registry key
    ... When you run the virus scan, open the task manager and kill EXPLORER.EXE ... (desktop shell). ... Your desktop icons will disappear. ...
    (microsoft.public.windowsxp.general)