Page 1 of 1

Protecting Processes (and blocking bad web sites)

Posted: Sat Apr 25, 2009 1:48 pm
by Neo
Is there any way or a free program I can download that will prevent any process (including itself) from being terminated?

The reason I'm asking is because I tried to use the K9 software that Bubbalou recommended so that my kid cousin can't do things like look for free \"games\" and stuff and end up loading malicious web pages or install malicious software since we all run as administrators (Windows XP). I like the way it works, but I discovered a security vulnerability where you can just press control+alternate+delete to bring up the task manager or Process Explorer and kill the process k9filter.exe.

Posted: Sat Apr 25, 2009 2:47 pm
by flip
If he's on a limited account I don't think he can do that. If he is on a limited account and he's still able to terminate processes, I'd guess there was somewhere in gpedit.msc that you could prevent that.

Posted: Sat Apr 25, 2009 6:19 pm
by Neo
Okay, I'll try this and report back. :) P.S.: check out the update I posted to your math thread :P

Posted: Sat Apr 25, 2009 7:01 pm
by Insurrectionist
Did you know that isn't the only place you can stop a process. You can also right click my computer go to Manage then Services and Applications and stop and/or disable the service there to. You might want to make the user who you want to block a standard user as flip suggested.

There is a neat program at http://tweaknow.com/WinSecret.html that will allow you to disable regedit and task manager but again you would have to hide the program from the one you are trying to block so they couldn't be able to re-enable them.

Posted: Sat Apr 25, 2009 8:02 pm
by Neo
Yeah, I couldn't find anything to stop administrators from killing processes. Maybe I can use a registry tweak. I just decided to change everyone to regular Users, even though it's only one person doing the dangerous browsing. They don't need to be admins, because they are computer noobs. :P They don't know how to install things, etc., so until I figure out a good registry tweak, or something, it's limited user for them. :P Unless the owner of each PC complains about something. lol

Posted: Sat Apr 25, 2009 8:07 pm
by Zantor
There is no way to stop a process from being terminated by an administrator unless you use the techniques hackers do with spyware/malware and somehow hide the process. You can also use OpenDNS to block bad sites, namely fraudulent, pornographic, suspect, piracy sites, and so on.

I have worked with K9 before and there should be no way possible to kill the process without crippling internet and networking capabilities of the affected system, as I've seen well-made filter software do this.