Nah, that's not enough to make the distinction reliably. PC Tattletale
could have easily named their executable in lower case as well though, as
you say, they didn't and you can use that as a hint but you really have to
be more thorough than that.
Some suggestions I have seen are to look at the Image Path Name in Task
Manager (click View->Select Columns) and if you see svchost or winload or
rundll32 running from a path other than your WINDOWS\SYSTEM\SYSTEM32 folder,
it is obviously suspect.
That said, svchost.exe and rundll32.exe are both huge security risks even
when you know that the application is the legitimate one. Both of those
applications are used to run other applications and obfuscate the real
process that those two are running. Any installation program, including the
installation for SideBar gadgets, can configure your system to run any
program it wants using those two applications and the running application
will not show up in task manager.
Dale
Post by Stacy M. WoodsIt depends on what "winload.exe" looks like. "winload.exe" is part of Vista
and "WinLoad.exe" is part of PC TATTLETALE
Post by DaleMany such programs don't show up on menus and are obfuscated in various
ways such as calling their executable rundll.exe or svchost.exe.
Dale
Post by T5doing a google search I get that is actually a keylogger program that
you can buy as a parental control but I cannot find it anywhere on my
system
but yet xoftspy finds it
Post by PipboyPost by T5xoftspy tells me that I have a keylogger called PCTattletale but windows
defender doesnt pick it up nor does Norton 2007 protection centre nor does
Hijackthis nor spybot S&D so do i have it or not?
In a recent post a user told me that it must have been installed manually if
it is there but I havent installed anything other than the os and office
(apart from of course the antispy progs I have mentioned)
Is PCTattletale a part of the parental control software in Vista?
Never heard of that anti-spyware prog. What is the file name it says is a
keylogger? Search for that file on the internet and see what info you get
about it.