Chris_m
asked on
Identifying Memory Resident Trojans
I am trying to clean up a mchine that was heavily infected and am down to the last Trojan. This one is memory resident because every time I delete the entries in the registry, they are immediately recreated.
How can I get a listing of memory resident services?
How can I get a listing of memory resident services?
ASKER
It may be a silly question, but I still would like to know if it is possible to get a list of tasks/services that are running in memory.
Regards
Regards
does such a list help if the trojan knows to hide itself
ASKER
Well, I hope so because adaware identifies it as virtumundo and whenever I delete the ATLEvents Registry entries in the HKEY_CLASSES_ROOT they are recreated and I cannot find the process that is causing this to happen.
Regards
Regards
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
If it is a memory trojan, shutdown, poweroff, then poweron and boot. Ready.
KISS - keep it stupid simple.