A piece of malware is running via process injection question

hojnstimh
8 years ago

0

A piece of malware is running on a Windows 7 machine via process injection, so it does not show up in a process list. What remote forensic technique could be used to discover the malware is running under the contents of a specific process?

5replies
2voices
795views
f0rk [HackingGuy]
8 years ago

0

Memory Analysis.
Now for the better question, why are you asking?

hojnstimh
8 years ago

0

Not for anything malicious. Spent about 7 hours today finding answers to about 5 questions on a quiz. Finally decided to start asking people.

f0rk [HackingGuy]
8 years ago | edited 8 years ago

0

Well, if you have any more questions go ahead and PM me ;)
We usually don’t consider the forum a “homework helper” or a “test taker” for people. lol
Of course I’d love to help tho :)

hojnstimh
8 years ago

0

Alright thank you, and my bad.

f0rk [HackingGuy]
8 years ago

0

Don’t worry about it :)
You didn’t know.

You must be logged in to reply to this discussion. Login
1 of 6

This site only uses cookies that are essential for the functionality of this website. Cookies are not used for tracking or marketing purposes.

By using our site, you acknowledge that you have read and understand our Privacy Policy, and Terms of Service.

Dismiss