Malware Analysis Tools - SANS Computer Forensics
Malware Analysis Tools - SANS Computer Forensics
Malware Analysis Tools - SANS Computer Forensics
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Densityscout<br />
Mathematically<br />
based on Bytehist<br />
Computing (all)<br />
files of a filesystem<br />
location<br />
Result is a<br />
descending<br />
ordered list<br />
Reveals potentially<br />
unwanted<br />
software<br />
(0.03763) | c:\Windows\System32\bootres.dll<br />
(0.05214) | c:\Windows\System32\WdfCoinstaller01009.dll<br />
(0.05963) | c:\Windows\System32\VAIO S Series ‐ Summer 2011.scr<br />
(0.11521) | c:\Windows\System32\LkmdfCoInst.dll<br />
(0.12726) | c:\Windows\System32\mcupdate_GenuineIntel.dll<br />
(0.20664) | c:\Windows\System32\iglhsip64.dll<br />
(0.27113) | c:\Windows\System32\pegibbfc.rs<br />
(0.27516) | c:\Windows\System32\usk.rs<br />
(0.27633) | c:\Windows\System32\cero.rs<br />
(0.28895) | c:\Windows\System32\pegi.rs<br />
(0.30524) | c:\Windows\System32\AuthFWGP.dll<br />
(0.30681) | c:\Windows\System32\iscsicpl.exe<br />
(0.32147) | c:\Windows\System32\msshavmsg.dll<br />
(0.32388) | c:\Windows\System32\SrpUxNativeSnapIn.dll<br />
(0.32859) | c:\Windows\System32\qedwipes.dll<br />
(0.34056) | c:\Windows\System32\imagesp1.dll<br />
(0.34697) | c:\Windows\System32\oflc.rs<br />
(0.36592) | c:\Windows\System32\auditpolmsg.dll<br />
(0.36870) | c:\Windows\System32\onexui.dll<br />
(0.38369) | c:\Windows\System32\resmon.exe<br />
07.10.2012 6