Security Incidents mailing list archives
RE: New Virus?
From: Harlan Carvey <keydet89 () yahoo com>
Date: Mon, 15 Aug 2005 15:54:20 -0700 (PDT)
There are several things that folks can do prior to submitting to the list(s), or to A/V companies... 1. Post the file for others to view, or make it available upon request. 2. Perform some analysis of the file. Strings.exe from Sysinternals.com or BinText from FoundStone obviate the need for a Linux box just to run strings. Try PEDump from http://www.wheaty.net/downloads.htm. Or Dependency Walker from dependencywalker.com. 3. If the file is obfuscated or encrypted, try PeID from http://peid.has.it/ to determine which method is used (if possible). Thanks, Harlan ------------------------------------------ Harlan Carvey, CISSP "Windows Forensics and Incident Recovery" http://www.windows-ir.com http://windowsir.blogspot.com ------------------------------------------
Current thread:
- New Virus? Alex Arndt (Aug 15)
- Re: New Virus? Eduardo Vela (Aug 16)
- RE: New Virus? The AV Vendors respond (long post) Alex Arndt (Aug 16)
- RE: New Virus? James C Slora Jr (Aug 16)
- Re: New Virus? James Polley (Aug 18)
- RE: New Virus? James C Slora Jr (Aug 18)
- Re: New Virus? Eduardo Vela (Aug 19)
- Re: New Virus? James Polley (Aug 18)
- <Possible follow-ups>
- Re: New Virus? dave_mikesch (Aug 15)
- RE: New Virus? Ragnar Harper (Aug 15)
- RE: New Virus? Harlan Carvey (Aug 15)
