linux proc share|improve this question edited Apr 17 '13 at 11:00 vonbrand 12.3k11938 asked Apr 17 '13 at 2:00 truease.com 15517 is ls an alias for something? Trojans can delete files, monitor your computer activities, or steal your confidential information.

For example, we connect crypticity to how an observer synchronizes to a process. Log in or Sign up Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Computer problem? In Linux, threads have a different process ID to the other threads in the process. Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Process Explorer is very nice from a GUI perspective. We've got a lot to cover, so let's dive right in.

Can some processes be hidden?0lsof vs cat/proc/…/maps1Directory in /proc that isn't process dir but start with number?4Why does a process of a binary with only execute permission remain hidden in “ps” Unix & Linux Stack Exchange works best with JavaScript enabled current community blog chat Information Security Information Security Meta your communities Sign up or log in to customize your list. JOHN WICK Gets the Most Complimentary HONEST TRAILER Ever 5. https://home.mcafee.com/virusinfo/virusprofile.aspx?key=142710 Cleaning Windows Registry An infection from Hidden-Process.a can also modify the Windows Registry of your computer.

actually, it's already been asked: unix.stackexchange.com/questions/47918/… –derobert Apr 17 '13 at 4:35 @derobert: I know. dr-xr-xr-x 266 root root 0 Apr 17 09:11 .. Not the answer you're looking for? Post the log from ComboFix when you've accomplished that along with a new HijackThis log.

If you succesfully analyze the network with wireshark you can find this processes. UNIX is a registered trademark of The Open Group.

Which makes Image Name Detection the only way, but the issue is bypassing that hiding on a kernel level or something.

cfwids;c:\windows\system32\drivers\cfwids.sys [3/16/2010 6:37 AM 55456] R3 mfefirek;McAfee Inc. It can maliciously create new registry entries and modify existing ones. does /bin/ls -1 | grep 2266 behave the same way? –Frederik Deweerdt Apr 17 '13 at 2:38 add a comment| 2 Answers 2 active oldest votes up vote 11 down vote For example, on my system, chromium has a number of threads in a process (multiple processes too): $ ps -efL | grep chromium [UID PID PPID LWP C NLWP STIME TTY

A trojan disguises itself as a useful computer program and induces you to install it. process share|improve this question edited Dec 16 '14 at 11:16 asked Dec 16 '14 at 11:13 Arlix 5982519 1 You can use "tasklist" too. –programings Dec 16 '14 at 14:00 Are You Still Experiencing Hidden-Process.a Issues?

Then malware writers would make their malware hide from it, therefore it wouldn't show all processes by default. –immibis Jan 11 '16 at 1:00 add a comment| up vote 14 down

ROBOT Recap: Init 5 article MR. I've spent over an hour on online chat with McAfee's support team and they tell me not to worry that my computer is clean. But if a hidden process is accessing the registry, files, or communicating over the network it would be shown here. more stack exchange communities company blog Stack Exchange Inbox Reputation and Badges sign up log in tour help Tour Start here for a quick overview of the site Help Center Detailed

To achieve a Gold competency level, Solvusoft goes through extensive independent analysis that looks for, amongst other qualities, a high level of software expertise, a successful customer service track record, and The welcome screen is displayed. more hot questions question feed about us tour help blog chat data legal privacy policy work here advertising info mobile contact us feedback Technology Life / Arts Culture / Recreation Science As a Gold Certified Independent Software Vendor (ISV), Solvusoft is able to provide the highest level of customer satisfaction through delivering top-level software and service solutions, which have been subject to

