B
Bryan Wiegand
Hello all,
I don't know exactly were this thread really belongs, but
I suppose you can point me in the correct direction.
Some of the more recent malware infections load
themselves as DLL Modules into Memory. This makes them
very hard to kill. One malware in particular will load
itself with a new file name upon every reboot!
The new Microsoft AntiSpyware should also have a window
in the System Explorer in Advanced Tools to list the
Running Modules, much like the existing 'Running
Processes' already does.
There should also (Not sure if AntiSpyware alone could do
this, or some changes in Windows itself) be a way to End
Modules or Remove a running Module from Memory, so it can
be deleted without constant reboots. Like I say ealier,
some of these new malware infections load themselves as
DLL Modules, Protect thier Registry entires (they remake
an entry you delete), make copies of themselves with
differening files names, and load one of those variations
on every boot.
The ability to have more control over running Modules
would be a great blow to this particular infection.
If more technical information is needed about the
particular infections I'm refoerring to, it can be
provided.
Sufficed to say, this is my feature request:
A List of Running Modules (Just like the list in the
System Information Tool)
A way to End running Modules just like you end a running
Executable.
Well, thats my input. Let me know what you all think, or
where I should properly contact to make the feature
request.
Bryan Wiegand
I don't know exactly were this thread really belongs, but
I suppose you can point me in the correct direction.
Some of the more recent malware infections load
themselves as DLL Modules into Memory. This makes them
very hard to kill. One malware in particular will load
itself with a new file name upon every reboot!
The new Microsoft AntiSpyware should also have a window
in the System Explorer in Advanced Tools to list the
Running Modules, much like the existing 'Running
Processes' already does.
There should also (Not sure if AntiSpyware alone could do
this, or some changes in Windows itself) be a way to End
Modules or Remove a running Module from Memory, so it can
be deleted without constant reboots. Like I say ealier,
some of these new malware infections load themselves as
DLL Modules, Protect thier Registry entires (they remake
an entry you delete), make copies of themselves with
differening files names, and load one of those variations
on every boot.
The ability to have more control over running Modules
would be a great blow to this particular infection.
If more technical information is needed about the
particular infections I'm refoerring to, it can be
provided.
Sufficed to say, this is my feature request:
A List of Running Modules (Just like the list in the
System Information Tool)
A way to End running Modules just like you end a running
Executable.
Well, thats my input. Let me know what you all think, or
where I should properly contact to make the feature
request.
Bryan Wiegand