Vulnerability Development mailing list archives
Re: Suspecious JPEG Files
From: "Geoffrey Gowey" <gjgowey () gmail com>
Date: Tue, 5 Feb 2008 22:13:40 -0800
1) Install sandboxie on your system. 2) install filemon and regmon on your system 3) disconnect system from network 4) run filemon and regmon 5) run suspect program in sandbox 6) wait a little then kill, but don't delete sandbox. Now you can look at regmon and filemon to see what the program was trying to access/do without it killing your system. On 1 Feb 2008 17:10:13 -0000, poddima () yahoo com <poddima () yahoo com> wrote:
Hello, I recieved via e-mail two JPEG files, one of them was not opened properly (Default error message was displayed on the Windows Picture Viewer). The sender is known to me, and I suspect he was trying to attack my computer (I recieved also an infected executable file from him just a short time before, and I didn't opened it). If anyone is interested in trying to analyse the files, I'd be mostly grateful. Please contact me and I will send you the files. Thanks!
-- Kindest Regards, Geoff
Current thread:
- Suspecious JPEG Files poddima (Feb 04)
- Re: Suspecious JPEG Files Geoffrey Gowey (Feb 06)
- Re: Suspecious JPEG Files Valdis . Kletnieks (Feb 06)