This is likely a false positive since it only shows up in psscan - psscan is like a carver for processes so sometimes it gives a false positive.
Michael.
Anyone ever seen anything like this? It came out of a WinXPSP3x86 ram capture.
PCSXView results;
Offset(P) Name PID pslist psscan thrdproc pspcid csrss session deskthrd
---------- -------------------- ------ ------ ------ -------- ------ ----- ------- --------
0x0a074da0 X???E?P??(O'? 23...6 False True False False False False False
PSSCan results;
Offset(P) Name PID PPID PDB Time created Time exited
---------- ---------------- ------ ------ ---------- ------------------------------ ------------------------------
0x0a074da0 X???E?P??(O'? 23...6 23...4 0x8a274dc0
Thanks,
Robert Ayers,
_______________________________________________
Vol-users mailing list
Vol-users@volatilesystems.com
http://lists.volatilityfoundation.org/mailman/listinfo/vol-users