Re: identifying malware process
"Martin Visser" <[email protected]>
| Newsgroups | gmane.org.user-groups.slug.chat |
|---|---|
| Message-ID | <[email protected]> |
voytek, you were using the right sort of tools. the problem is though, that once a rogue program has 'got root' it has got root. that is, pretty much can own any file or table it wants. so it can hide it's tracks from log files, process tables, or anything else to hide itself. of course no rogue can truly hide invisibly without completely rejigging the kernel and other system libraries, but they certainly have a good go! Martin On 11/17/08, Voytek Eymont <[email protected]> wrote: > I've got an XP with some sort of malware sending notification popup 'your > computer is infected' > > I thought systeminternals 'process explorer' would show and help in > identifying what process is the rogue process ? but, not having much luck > > clicking on balloon starts a process that tries to download stuff from > remote server, and, that process I can identify in 'process explorer', > and, from that, several related files > > but, I can not identify anything that makes the ballon come up, can that > be running hidden in a 'normal' process > > what other tools are there for identifying that sort of stuff ? > > > > -- > Voytek > > -- > SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/ > Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html > -- Regards, Martin [email protected] -- SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/ Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html