RE: New Virus?
Harlan Carvey <[email protected]>
| Newsgroups | gmane.comp.security.incidents |
|---|---|
| Message-ID | <[email protected]> |
There are several things that folks can do prior to submitting to the list(s), or to A/V companies... 1. Post the file for others to view, or make it available upon request. 2. Perform some analysis of the file. Strings.exe from Sysinternals.com or BinText from FoundStone obviate the need for a Linux box just to run strings. Try PEDump from http://www.wheaty.net/downloads.htm. Or Dependency Walker from dependencywalker.com. 3. If the file is obfuscated or encrypted, try PeID from http://peid.has.it/ to determine which method is used (if possible). Thanks, Harlan ------------------------------------------ Harlan Carvey, CISSP "Windows Forensics and Incident Recovery" http://www.windows-ir.com http://windowsir.blogspot.com ------------------------------------------