Solved

Trying to find a malware dll

Posted on 2011-02-11
3
354 Views
Last Modified: 2013-11-22
Using Procmon how do I found the setup_0a.dll?

A simple newbie question: a .txt file can be infected with malware?
0
Comment
Question by:rebelscum0000
3 Comments
 
LVL 4

Assisted Solution

by:HawyLem
HawyLem earned 150 total points
ID: 34875653
Everything can be infected with malware, particularly with a shell exploit (malicious artifact code that would exploit the editor/reader of the file). But in the specific case of a txt file, this would be very rare.. due to the low complexity of the notepad application too

Using Procmon you can double click and show properties for an executable image and list his DLLs modules
0
 
LVL 23

Assisted Solution

by:edbedb
edbedb earned 150 total points
ID: 34875717
Try finding it in regedit or with Process Explorer.
http://technet.microsoft.com/en-us/sysinternals/bb896653
0
 
LVL 30

Accepted Solution

by:
Sudeep Sharma earned 200 total points
ID: 34876190
Using ProcMon (Process Monitor) Press Ctrl+H or click on Filter --> Hightlight. It would open a new window.

In this window on first drop down select "Process Name" in second drop down "is" third "setup_0a.dll" and in fourth "include". Click on Add and then click on OK, how when ever the "setup_0a.dll" is used or invoked you would see it ProcMon in different color or highlighted.

Sudeep
tmp.JPG
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you thought ransomware was bad, think again! Doxware has the potential to be even more damaging.
No single Antivirus application (despite claims by manufacturers) will catch or protect you from all Virus / Malware or Spyware threats. That doesn't stop you from further protecting yourself however - and this article is to show you how.
This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question