Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unable to detect ghosttasks #25

Open
j-wsy opened this issue Apr 8, 2024 · 5 comments
Open

Unable to detect ghosttasks #25

j-wsy opened this issue Apr 8, 2024 · 5 comments
Labels
bug Something isn't working

Comments

@j-wsy
Copy link

j-wsy commented Apr 8, 2024

Hi, love the tool.

I have a vm with a working ghosttask loaded (restarted and all that, and confirmed the ghosttask is functioning). I can see it in my regedit \tasks, and I can see it doesn't have a SD, as expected. I can see it doing the action I made it do.

Running the latest PersistenceSniper v1.16.0, I can't seem to detect it. I see a bunch of other false-positives, so the tool itself is working, but no output relating to ghosttask.

@j-wsy
Copy link
Author

j-wsy commented Apr 8, 2024

image

@j-wsy
Copy link
Author

j-wsy commented Apr 8, 2024

Here's another example using a ghosttask named "April1", on a separate clean vm. Could not detect using Find-AllPersistence.

Am I doing something wrong/do I need to do anything else?

postrebootScreenshot 2024-04-08 235441

@last-byte
Copy link
Owner

Hey there, solid copy. I’ll investigate it right away and fix it in the next minor release.

@last-byte last-byte added the bug Something isn't working label Apr 9, 2024
@j-wsy
Copy link
Author

j-wsy commented Apr 13, 2024

thanks, looking forward to it.

@daniele777
Copy link

Malware is fake amsi provider?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants