Link to home
Start Free TrialLog in
Avatar of Chris_m
Chris_m

asked on

Identifying Memory Resident Trojans

I am trying to clean up a mchine that was heavily infected and am down to the last Trojan.  This one is memory resident because every time I delete the entries in the registry, they are immediately recreated.  

How can I get a listing of memory resident services?

Avatar of ahoffmann
ahoffmann
Flag of Germany image

silly question: if you still know it is a memory trojan, why do you want to get a list?
If it is a memory trojan, shutdown, poweroff, then poweron and boot. Ready.
KISS - keep it stupid simple.
Avatar of Chris_m
Chris_m

ASKER

It may be a silly question, but I still would like to know if it is possible to get a list of tasks/services that are running in memory.

Regards
does such a list help if the trojan knows to hide itself
Avatar of Chris_m

ASKER

Well, I hope so because adaware identifies it as virtumundo and whenever I delete the ATLEvents Registry entries in the HKEY_CLASSES_ROOT they are recreated and I cannot find the process that is causing this to happen.

Regards
ASKER CERTIFIED SOLUTION
Avatar of tmcguiness
tmcguiness

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial