Re: identifying malware process
"Voytek Eymont" <[email protected]>
| Newsgroups | gmane.org.user-groups.slug.chat |
|---|---|
| Message-ID | <[email protected]> |
On Mon, November 17, 2008 10:52 pm, Martin Visser wrote: > voytek, you were using the right sort of tools. the problem is though, > that once a rogue program has 'got root' it has got root. that is, pretty > much can own any file or table it wants. so it can hide it's tracks from > log files, process tables, or anything else to hide itself. of course no > rogue can truly hide invisibly without completely rejigging the kernel and > other system libraries, but they certainly have a good go! Martin, thanks executing the balloon was in a foreground process, cancellable from itself, (or process explorer), and, clearly identifiable in the process explorer, however, I guess ? the balloon itself was hidden in another process ? as I just couldn;t find anything that even remotely could be it as it is (going by file date/time) I identified most or all of the malware files fwiw, the actual executable that did the initial damage, and, caused the balloon is called 'WJQS', plus several luggage files that go with it, wrdwn?? I'm still perplexed how easily I've aquired and, auto executed the malware, I thought Firefox would prevent auto-execute stuff fwiw, Norton was about as useless as mammaries on a bull, detected zilch, nada (which I have seen on other occasions, Norton scan of exe-parading-as-doc fake emails passed clear, I mean, how can a file named stuff.doc.exe be passed clear regardless of what it in......) -- Voytek -- SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/ Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html