China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --

Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
DOS stands for freedom, openness and progress. Let us work hard, learn from the openness and GNU spirit of FreeDOS and Linux, and together build and grow a free GNU GPL world!

中国DOS联盟论坛
The time now is 2026-08-02 21:40
中国DOS联盟论坛 » DOS批处理 & 脚本技术(批处理室) » How to end hidden processes with batch processing? View 1,736 Replies 7
Original Poster Posted 2006-12-20 01:46 ·  中国 江苏 连云港 海州区 电信
初级用户
Credits 63
Posts 24
Joined 2006-12-19 09:59
19-year member
UID 73949
Gender Male
From 南京
Status Offline
Killing a virus, can only see hidden processes with icesword and end them. I don't know how to write it with batch processing... Hope an expert can give guidance!
Floor 2 Posted 2006-12-21 12:23 ·  中国 湖北 武汉 电信
版主
★★★★★
Credits 11,386
Posts 4,938
Joined 2006-07-23 17:10
20-year member
UID 59080
Status Offline

If you know the process name or process ID, you can end it, unless it's a stubborn process or a system core process.

taskkill /im imagename /f
::
taskkill /f /pid processid
Floor 3 Posted 2006-12-23 02:36 ·  中国 江苏 连云港 电信
初级用户
Credits 63
Posts 24
Joined 2006-12-19 09:59
19-year member
UID 73949
Gender Male
From 南京
Status Offline
Can it automatically read the pid and use it as a variable to end the process?
Floor 4 Posted 2006-12-23 03:07 ·  中国 湖北 武汉 电信
版主
★★★★★
Credits 11,386
Posts 4,938
Joined 2006-07-23 17:10
20-year member
UID 59080
Status Offline

Why do you always need to know the PID to end a process?

If you know the process name, you can end it without knowing its ProcessID.

Both tasklist and wmic process can be used to view the PID of a process.
Floor 5 Posted 2006-12-23 04:57 ·  中国 江苏 连云港 电信
初级用户
Credits 63
Posts 24
Joined 2006-12-19 09:59
19-year member
UID 73949
Gender Male
From 南京
Status Offline
I know the process name, but it's hidden...

It seems these can't end hidden processes, right?
Floor 6 Posted 2006-12-23 06:32 ·  中国 北京 朝阳区 联通
高级用户
★★
朦胧的世界
Credits 579
Posts 218
Joined 2006-10-24 04:29
19-year member
UID 67972
Status Offline
Most hidden processes use Rootkit technology. Continuing to use your IceSword is still the most convenient.

认识自己,降伏自己,改变自己
,才能改变别人!
Floor 7 Posted 2006-12-23 09:26 ·  中国 江苏 连云港 电信
初级用户
Credits 63
Posts 24
Joined 2006-12-19 09:59
19-year member
UID 73949
Gender Male
From 南京
Status Offline
I want to write a special killer for batch processing, which is more convenient...

I don't know if there is a way to achieve it?
Floor 8 Posted 2006-12-23 10:14 ·  中国 江苏 南京 电信
高级用户
★★
Credits 623
Posts 214
Joined 2006-09-22 20:48
19-year member
UID 63387
Status Offline
You need to post the process name you want to end and the virus name you want to scan for viruses. In this way, we can help you in a targeted manner. We need to know the methods and some properties of process hiding to write batch processing. Usually, most hidden processes are mostly hooked in the explorer process.
Forum Jump: