PDA

View Full Version : Packed Images in Process Explorer


pangea33
10-09-2005, 12:27 PM
I recently started using Process Explorer from the guys at SysInternals, and it's an excellent utility. It might even have too many features for a guy like me, who ends up spending more time than necessary looking at stuff that I don't fully comprehend.

Process Explorer has a color coding system for types of processes that are running. A couple of them have shown up as "Packed Images", which the help file says may be used by malware and viruses. Google obviously returns a bunch of noise for these search terms. I searched the forums on their site, and couldn't find any threads that gave enough information. Here's the best that I could find: http://www.sysinternals.com/Forum/forum_posts.asp?TID=442&KW=Packed+image

So far the packed processes that I've noticed are Acronis True Image, and Lavasoft AdAware. It's seems possible that utilities like these would have a packed image format, but how can I tell whether there is a security risk? Could someone please give a little info, or some links to more information?

Thanks again, and always. This forum has proven to be a fantastic resource.

FROM PROCESS EXPLORER HELP FILE:
Highlight Packed Images: malware, including viruses, spyware, and adware is often stored in a packed encrypted form on disk in order to attempt to hide the code it contains from antispyware and antivirus.