Different approache...
 
Notifications
Clear all

Different approaches to examine a corrupted virus file?

11 Posts
6 Users
0 Reactions
1,271 Views
(@hellopanda)
New Member
Joined: 13 years ago
Posts: 4
Topic starter  

thread closed.


   
Quote
(@alastairfay)
Eminent Member
Joined: 14 years ago
Posts: 36
 

Do you have a non-infected file to compare it to?


   
ReplyQuote
(@hellopanda)
New Member
Joined: 13 years ago
Posts: 4
Topic starter  

Do you have a non-infected file to compare it to?

Nope, no just one file. wondering how should i examine it if its corrupted or if it contains any viruses. Trying to understand more first before i start examing it.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

More info is needed…what type of file is it, how is it infected, and how is it corrupted?

There's a difference in approaches between an EXE or DLL file that is infected via a file infector, and a document that includes potentially malicious executable code.


   
ReplyQuote
(@hellopanda)
New Member
Joined: 13 years ago
Posts: 4
Topic starter  

More info is needed…what type of file is it, how is it infected, and how is it corrupted?

There's a difference in approaches between an EXE or DLL file that is infected via a file infector, and a document that includes potentially malicious executable code.

it is just photos that have been compressed to zip file. When i try to open the file, a message is displayed saying that the file is corrupted. Want to find out what other approaches can i try to examine this zip file for further investigation. Any suggestions will be great to me, i'm just doing some research and hope to learn something new. Hope that clears it up.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

What tools are you using to try to open the zip file?

Have you examined the zip file with a hex editor to see if it really is a zip archive?


   
ReplyQuote
(@patrick4n6)
Honorable Member
Joined: 16 years ago
Posts: 650
 

A message during extraction from an archive that the file was corrupted would tend to me to indicate that the archive file was broken, not that a file had a virus.

Broken archive corruption
Virus file infection

The terminology you're using doesn't match your stated issue.

Is Windows / Winzip reporting the corruption? If it's infected, I'd expect to see that error from your AnitVirus software.


   
ReplyQuote
(@belkasoft)
Estimable Member
Joined: 17 years ago
Posts: 169
 

There are plenty of tools that can repair corrupted ZIP files. You may not be able to use the files that actually have corrupted parts in them, but at least you'll be able to extract them. Google has a good selection of such tools https://www.google.com/search?q=zip+recovery&sourceid=ie7&rls=com.microsoften-USIE-Address&ie=&oe=


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

Apart GUI tools the Infozip zip repair option often works, and dynamite and offset file zipper are also worth a shot.
These tools and a couple more ones are discussed/detailed in this seemingly unrelated thread
http//reboot.pro/topic/12255-need-help-with-virtual-floppy/

jaclaz


   
ReplyQuote
(@hellopanda)
New Member
Joined: 13 years ago
Posts: 4
Topic starter  

Hi guys thanks for the information. appreciated everyone who replied. Right now i am more concern about the different techniques/approaches to carry out my examination. Techniques like sheepdip and approaches like checking the header are things that i have done.

If anyone have more information to share, feel free to share here or give me a pm to know more about the problem i'm facing. thanks! D


   
ReplyQuote
Page 1 / 2
Share: