Malware hunting

17.12.2008

I tried using to see what was going on. Process Monitor is another free tool from the Microsoft SysInternals stable but that produces so much data that it's like looking for a needle in a haystack.

What I found is I appear to have a number of files laying around in the windows/system32 subdirectory that look like bits from various malware (files such as 0wiintemp.exe and 1wiintemp.exe), but much to my surprise, Lavasoft's  doesn't seem to care about them.

So, I looked around and in the Process Manager task list discovered something called taskmagr.exe was running. Nope, that's not the Windows task manager (which is actually named taskmgr.exe). A little research revealed that this file is a fairly new worm.

According to the security company , this malware was first seen on Nov. 23 this year, it is polymorphic, and registers a Dynamic Link Library file that is executed as a process in a new background service. It also has a whole slew of aliases and sizes (which you'd expect with it being polymorphic and all). In short, it appears to be very sneaky.

Why didn't my antivirus software detect it? Because somehow it had been disabled (I won't lie, I might have turned it off when I was doing some testing). So, I tried AVG Anti-Spyware and Prevx's CSI.