PDA

View Full Version : Process Hardening



mjq424
10-14-2007, 09:08 PM
Hi
It appears that you have started using process hardening techniques on pctsSvc.exe.
I have a slight problem, in that if I try to terminate the process with TaskManager, i get the Acces Denied dialog, but then the pc is unresponsive. I have to do a hard reboot to solve it. No CPU usage, RAM stays the same, it just "dies".
This wouldn't be so good if malware was attacking it because that in itself would cause a DoS attack!
Any thoughts?
I have tried to use DiamondCS Advanced Process Terminator, but that causes the same problem when it tries Option2 (TerminateThread), PCTIS "passes" Option1 (TerminateProcess), in that the process refuses to die! How many of those methods are resisted by PCTIS?

My other security apps:
Sunbelt CounterSpy 2.5
ThreatFire 3.0.10

Running on WinXP SP2 fully patched

AChen
10-17-2007, 02:44 AM
Hi Mjq424,

Are you on a domain? are you logged in as an Administrator when attempting this action? Is kernel compatibility mode enabled/disabled? At what point are you trying to kill pctsSvc.exe? At startup, idle or after you have asked SD to shutdown via the trayapp?

mjq424
10-17-2007, 08:39 AM
Hi
This is a home PC. I am an admin account. Testing was with kernel compatibilty off. Killing pctsSvc.exe while there was no other activity (CPU at 0-1%), after startup, not having tried the Shutdown. I was basically just testing.

AChen
10-18-2007, 05:57 AM
Thanks for the info mjq424. This has been escalated and I'll update you shortly.