4 ms·
How is it easy to disprove? The trojan could delete itself after downloading CP. Should be impossible to reconstruct what happened exactly.
by cx01 17y ago
How is it easy to disprove? The trojan could delete itself after downloading CP. Should be impossible to reconstruct what happened exactly.
- ErrantX 17y agoOf course there is an upper limit to how provable it is. But that is fairly elaborate malware your describing (because if that is all it did it should be fairly apparent - it also has to fake fairly extensive use as well). Mostly it is very easy to see the CP activity (dont forget were not just talking about images on the HDD here but actual activity indicative of behavior). If it were downloaded all together, with no references in, say, web history etc, no thumbnails and nothing in the cache files (which are FULL of rich information) then it would ring alarm bells :) Eventually even the most elaborate malware will make a mistake with activity that is not "normal" - and the investigation is intensive enough to pick this up.
- cx01 17y agoI don't think it would be hard. Just create a Windows application that hosts an IE ActiveX control and hides its main window. Or even better: When the user's screen saver is running, start a full-blown IE window and control it through Window messages. The traces would be identical to the case in which the user used IE himself.