Re: Executing a console program during the startup process like CHKDSK



>From MSDN (MOVEFILE_DELAY_UNTIL_REBOOT) :-

<snip>The system moves the file immediately after AUTOCHK is executed, but
before creating any paging files.</snip>

Looks like this is what you want. The file is deleted before it's loaded
(even if it's a device driver).

--
Regards,
Nish [VC++ MVP]
http://www.voidnish.com
http://blog.voidnish.com


"He Shiming" <mailbill(NOSPAM)@21cn.com.nospam> wrote in message
news:%23wwCLqCPFHA.3076@xxxxxxxxxxxxxxxxxxxxxxx
> Well, I suppose a few of those spyware remover were using MoveFileEx to
> delete the file. But I'm still not sure when is Windows going to delete
> it. It certainly can't be deleted during shutdown, because the driver is
> still loaded. If Windows were to delete it at startup, then at which
> point?
>
> --
> He Shiming
>
> "MSalters" <MSalters@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:338FB32F-703F-4384-BC78-10080F9E6E41@xxxxxxxxxxxxxxxx
>> "He Shiming" wrote:
>>
>>> Hi,
>>>
>>> I'm working on a spyware removal tool, which, is designed to remove a
>>> really
>>> annoy spyware program who installs itself as a device driver. There's no
>>> way
>>> to uninstall it when the system is up and running. So I'll have to
>>> execute
>>> it during (actually before) the startup process, just like CHKDSK does.
>>
>> MoveFileEx( name,0,MOVEFILE_DELAY_UNTIL_REBOOT )
>> seems logical, if the driver file is deleted it won't load. Reboot and
>> rinse.
>>
>> Regards,
>> Michiel Salters
>>
>
>


.



Relevant Pages

  • Re: FreeBSD and User Security
    ... this loss largely due to the use of spyware. ... safeguarding the machine against network attacks. ... unix mail clients as a rule do not execute ... vulnerabilities, and a determined cracker would create his own program. ...
    (freebsd-questions)
  • Re: FreeBSD and User Security
    ... Today I read an article describing how my government had lost ... XFCE) to attacks, including cracking and spyware. ... prevent spyware being installed (assuming root has been properly ... If allowed access to execute any thing ...
    (freebsd-questions)
  • Re: Microsoft Anti Spyware
    ... >>spyware, and i don't even have a hardware firewall. ... >>the Free version of AdAware does Not stop the installation of spyware. ... to execute. ... security is ultimately a matter of degree. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: spyware included in windows security updates
    ... Welcome to my world ....THE REASON YOUR SECURITY UPDATES HAVE SPYWARE IN THEM ... TURN OFF YOUR FAKE SERVICES THAT THE DEVICE DRIVER WRITES TO AND MANUALLY ... dozen spyware programs from my system? ...
    (microsoft.public.windowsupdate)
  • Re: "stealth" spyware
    ... | I keep receiving a message that my computer has been hijacked by the spyware ... Execute; SmitFraud.exe ... You may have to disable your software FireWall or allow WGET.EXE to go through your ... It is suggested that you move the report out of c:\mcafee before performing another scan. ...
    (microsoft.public.windowsxp.security_admin)

Quantcast