|We don't bite newbies here... much|
Re^2: win32-process-hide infected with mal/packer?by Anonymous Monk
|on Feb 03, 2013 at 04:07 UTC||Need Help??|
really so different from the following which is available on many (most?) variants of *nix, and is documented in the perl docs?
Yes it is, changing $0 doesn't hide the process from ps -- hiding a process is purely rootkit territory