Re: Suspecious JPEG Files



1) Install sandboxie on your system.
2) install filemon and regmon on your system
3) disconnect system from network
4) run filemon and regmon
5) run suspect program in sandbox
6) wait a little then kill, but don't delete sandbox.

Now you can look at regmon and filemon to see what the program was
trying to access/do without it killing your system.



On 1 Feb 2008 17:10:13 -0000, poddima@xxxxxxxxx <poddima@xxxxxxxxx> wrote:
Hello,


I recieved via e-mail two JPEG files, one of them was not opened properly
(Default error message was displayed on the Windows Picture Viewer).

The sender is known to me, and I suspect he was trying to attack my computer
(I recieved also an infected executable file from him just a short time
before, and I didn't opened it).


If anyone is interested in trying to analyse the files, I'd be mostly
grateful. Please contact me and I will send you the files.


Thanks!



--
Kindest Regards,

Geoff



Relevant Pages

  • Re: Administrator Help
    ... The process can be a little effort, when using the filemon ... ability to write in the install area on disk (and to destroy the ... the applications area in the registry, ... For finding these the regmon and filemon tools are a great ...
    (microsoft.public.security)
  • RE: OWA Error
    ... type the following command in order to register the .dll file. ... f) Test again whether the OWA works now. ... Please go to the following web sites to download and run Filemon and Regmon ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote Access Wizard - SBS 2003 SP1
    ... Could you please rerun Filemon and Regmon ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • RE: Impact of removing administrative rights in an enterprise running XP
    ... Regmon and Filemon are very useful tools - among others you can find at ... Impact of removing administrative rights in an enterprise ... You would be surprised the apps that require privilege to run... ...
    (Focus-Microsoft)
  • RE: User rights on Terminal Services
    ... I'm assuming you installed the application in "Install Mode"... ... Go to www.sysinternals.com and download regmon and filemon. ... User rights on Terminal Services ...
    (Focus-Microsoft)