Full Disclosure mailing list archives

RE: interesting trojan found


From: "Willem Koenings" <isec () europe com>
Date: Thu, 21 Oct 2004 09:22:37 -0500


hi,

But if it is a rootkit, does it not hide from normal AV scanning?

It's more like a worm. But it hides its presence in the file
system, when it's active - dirlist doesn't show it, so you can't
scan it like a file.

all the best,

W.


-- 
___________________________________________________________
Sign-up for Ads Free at Mail.com
http://promo.mail.com/adsfreejump.htm

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: