Chandan chandanlog(3C)
or sayings of an hearer
or A Blog of a Security Engineer
or The Official Online Journal of Chief Executive Prankster, Sun Microsystems Inc.,

All (Archive) | General | Solaris | Security | Art | About | |
General Solaris Security Art

« Previous day (Jun 15, 2005) | Main | Next day (Jun 17, 2005) »
16 Jun 2005 windows systems programs that are named like spyware?
Day before yesterday at the BARF (Bay Area Regional Forum of incident response and security teams) monthly dinner, we casually discussed about names of Microsoft Windows program files which look like some virus or spyware. When ever I get suspicious if anything like a virus is running on my Windows (BTW I dont run Windows often), I press control+alt+del to get a list of system processes. The names of processes look so PHr33KEd and 133ty, I get paranoid. (Does ALG.exe sounds like an AliGator virus?) and search on the net for that name.

Note that a perfectly legal sounding name still could be a trojan or a spyware.

Thanks to Casper, in Solaris world we have such a wonderful database of binary fingerprints. Doesn't look like Microsoft has anything similar to it.

A file integrity checker is a good solution, Solaris now has BART, which can do file integrity checks.

Technorati Tag:
Technorati Tag:
Technorati Tag:

Link | Comments [2]


« Previous day (Jun 15, 2005) | Main | Next day (Jun 17, 2005) »

Copyright (cc) 2004-2006 by Chandan chandanlog(3C): windows systems programs that are named like spyware?