RageMachine wrote:I found this on a system, very interesting and runs as a service on the target system. Was unable to kill the PID using all methods of force I knew (TerminateProcess, terminate threads, closing handles, WM_DEstroy, attaching debugger and then killing it) It prevents the target user from launching new devices on the system and its root dir in C:\Windows\Installer is untouchable. Defeated by removing registry key from windows repair.Very interesting by the way... I certainly try it... Thanks for sharing!!!
* Enables driver test signing mode
* installs two drivers and makes keys under HKLM\System\CurrentControlSet****\Services\
* Has target of syshost.exe in C:\windows\installer\{ }\
* Removes Windows Update related services including bits\wuauserv
* prevents loading of new drivers and continually closes handles to its files and keys
Andrea