Re: identifying malware process

"Voytek Eymont" <[email protected]>
Newsgroups gmane.org.user-groups.slug.chat
Message-ID <[email protected]>
On Mon, November 17, 2008 10:52 pm, Martin Visser wrote:
> voytek, you were using the right sort of tools. the problem is though,
> that once a rogue program has 'got root' it has got root. that is, pretty
> much can own any file or table it wants. so it can hide it's tracks from
> log files, process tables, or anything else to hide itself. of course no
> rogue can truly hide invisibly without completely rejigging the kernel and
> other system libraries, but they certainly have a good go!

Martin, thanks

executing the balloon was in a foreground process, cancellable from
itself, (or process explorer), and, clearly identifiable in the process
explorer, however, I guess ? the balloon itself was hidden in another
process ? as I just couldn;t find anything that even remotely could be it

as it is (going by file date/time) I identified most or all of the malware
files

fwiw, the actual executable that did the initial damage, and, caused the
balloon is called 'WJQS', plus several luggage files that go with it,
wrdwn??

I'm still perplexed how easily I've aquired and, auto executed the
malware, I thought Firefox would prevent auto-execute stuff

fwiw, Norton was about as useless as mammaries on a bull, detected zilch,
nada (which I have seen on other occasions, Norton scan of
exe-parading-as-doc fake emails passed clear, I mean, how can a file named
stuff.doc.exe be passed clear regardless of what it in......)


-- 
Voytek

-- 
SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/
Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.