glricht
Well-Known Member
- Reaction score
- 805
- Location
- Zephyrhills, Florida
RKill is primarily used to restore file associations like .exe and terminate processes that may simply corrupt the file association again or other programs it mistakens for malware.
Actually, the original reason why RKILL was written was to terminate currently-running rogue processes, e.g. get your foot in the door. Then you could run whatever tools you wanted to actually ferret out the malware. This has been a "go-to" tool for a long time.
The welcome ability to restore file associates, plus many other enhancements, was added in a major update (R2.0?) and subsequent revisions.
More info: http://www.bleepingcomputer.com/download/rkill/