View Single Post
01-17-06, 07:48 PM   #54
jaye1701
A Kobold Labourer
Join Date: Jan 2006
Posts: 1
thats pretty huge to change an exe or even to modify it.

You could always load it in a VM session and then use Ethereal to see what IP's it calling to.


Save the logfile then use www.whois.sc or www.dnsstuff.com to verify where the IP's are phoning home too.

Also you could check for other nasties like rootkit installers using RootkitRevealer, services.

Or even just install it on a VM Maching using INCTRL to see what it drops. What registry keys, values, etc.

but that would take some time
  Reply With Quote