windows smss.exe strings loaded in memory - are they hidden?



Hi all,

I had nothing better to do so I checked on what kind of strings I
could find inside Windows processes using the Sysinternals "Process
Explorer".

This tool can show strings inside executables currently running in
Windows. In fact it has two settings:
-"Image": to show the strings found inside the executable as it is on
the hard disk
-"Memory": to show the strings found inside the executable in RAM.

(The reason for the two separate settings is that some times malware
obfuscates strings so that they are visible only when the executable
is in RAM)

In any case, one of the processes I checked was smss.exe. I noticed
that it shows a lot of strings when the "Image" radio button is
selected, but when selecting the "Memory" radio button the window goes
completely blank. Sort of gives one the impression that Process
Explorer has no access to the in-memory strings?

And after checking other processes it seems that smss.exe is the only
MS process for which no strings are visible in the memory.

What could be the cause of this? Could this be a side effect of how
smss.exe itself is loaded into the memory?

Thanks in advance
.



Relevant Pages

  • Re: Outlook Express question
    ... You appear to be using XP Classic Windows Theme. ... > ARE two separate strings within the file displaying two separate ... > and the controls are somehow flagged. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Outlook Express question
    ... You appear to be using XP Classic Windows Theme. ... > ARE two separate strings within the file displaying two separate ... > and the controls are somehow flagged. ...
    (microsoft.public.windowsxp.general)
  • Re: RfD: XCHAR wordset
    ... It's somewhat worse, because Windows has "A" prototypes, which convert the ... current code page into UTF-16 on the fly. ... Actually, it might be possible to change the current code page to UTF-8, but ... Windows strings are usually not C strings, ...
    (comp.lang.forth)
  • Re: windows smss.exe strings loaded in memory - are they hidden?
    ... I had nothing better to do so I checked on what kind of strings I ... could find inside Windows processes using the Sysinternals "Process ... but when selecting the "Memory" radio button the window goes ... MS process for which no strings are visible in the memory. ...
    (microsoft.public.windows.server.security)
  • Re: sraytb.exe
    ... Restart in Safe mode by hitting F8 as Windows first begins to load on boot. ... Look in the right hand pane for the string or strings that load that file. ...
    (microsoft.public.windowsxp.general)