View Single Post
  #1  
Old 08-31-2013, 02:21
mr.exodia mr.exodia is offline
Retired Moderator
 
Join Date: Nov 2011
Posts: 783
Rept. Given: 490
Rept. Rcvd 1,123 Times in 305 Posts
Thanks Given: 89
Thanks Rcvd at 716 Times in 333 Posts
mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299
hmm, that's indeed a problem...

you could point ctrl+alt+del to the task manager and from there hook CreateProcess to kill it even before it started. Another way would be to simply rename taskmgr to taskmgr_ or something like that. This could be done every time your museum shell is started... Even another solution would be to inject a custom DLL into every process (using this registry trick you see in some malware) that just checks if a mutex or something similar exists and then kills taskmgr when your museum shell does not give the green light.

Hope there is an idea you like..
Reply With Quote