Re: identifying malware process

"Martin Visser" <[email protected]>
Newsgroups gmane.org.user-groups.slug.chat
Message-ID <[email protected]>
voytek,
you were using the right sort of tools. the problem is though, that
once a rogue program has 'got root' it has got root. that is, pretty
much can own any file or table it wants. so it can hide it's tracks
from log files, process tables, or anything else to hide itself. of
course no rogue can truly hide invisibly without completely rejigging
the kernel and other system libraries, but they certainly have a good
go!

Martin


On 11/17/08, Voytek Eymont <[email protected]> wrote:
> I've got an XP with some sort of malware sending notification popup 'your
> computer is infected'
>
> I thought systeminternals 'process explorer' would show and help in
> identifying what process is the rogue process ? but, not having much luck
>
> clicking on balloon starts a process that tries to download stuff from
> remote server, and, that process I can identify in 'process explorer',
> and, from that, several related files
>
> but, I can not identify anything that makes the ballon come up, can that
> be running hidden in a 'normal' process
>
> what other tools are there for identifying that sort of stuff ?
>
>
>
> --
> Voytek
>
> --
> SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/
> Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html
>


-- 
Regards, Martin

[email protected]
-- 
SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/
Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.