Hello.
Is it possible to change the protection in the newly injected memory in a process? Let's say from RWX to RX. If it's possible, can you name a malware that does this?
I know it's possible to strip the "MZ" header but if you also change the protection there should be no way to detect an injected process, am I right?
Thanks
Is it possible to change the protection in the newly injected memory in a process? Let's say from RWX to RX. If it's possible, can you name a malware that does this?
I know it's possible to strip the "MZ" header but if you also change the protection there should be no way to detect an injected process, am I right?
Thanks