Sunday, February 24, 2013

virus on pc

Easily individuating a virus on pc

 One of the characteristics of modern virus is to hide among the useful applications and launch processes with the same name.

It is therefore almost impossible to distinguish from the original process.

To do this, press CTRL-ALT-DELETE.

This will open the task manager, an application that allows you to view all the applications currently running, and therefore the virus.

Head to the Processes tab.

Then choose "View" from the top menu and click "Choose Columns" (Or at least something similar).

You will see a list of options, you select "Number Thread", or just "Thread".

Once that is done, you will see a column next to the existing ones under which you will see the numbers. Do not worry, we will show soon what they are.

Now click on the Image Name column, all processes will be reordered.

Found then the process that you need to expose and his double, are sorted one under the other.

Now for each check the corresponding number in the column thread and finish what has only one (Caution: Do this at your own risk if you do not know the thread management processes windows).

For example, the process explorer.exe original has 2 or 3 threads instead a virus that tries to imitate it has only one since it is known that the multi-threaded programming is very difficult and certainly a virus writer will not attempt to learn just to create a virus.

 

No comments:

Post a Comment