kpatz
March 16th, 2009, 02:32 PM
Just wondering if anyone has an easy way of doing this, or has any suggestions.
Let's say that I'm running XP as a guest on virtualbox. I take a snapshot of the virtual drive. Then, I infect it with a virus. Now, I want to see what files the virus created/modified, by comparing the last snapshot to the current state.
Is there any way to do this?
I suppose one way is to setup another VM running a Linux distro, or even another copy of XP, and then mount the infected VM's disk images and compare them from there. But I don't think you can mount an image minus 1 snapshot without reverting the snapshot, can you? What would be cool is to be able to mount the image minus 1 snapshot as one read-only drive, and the image current state as another, and then do a compare from those.
I suppose another option is to clone the image rather than use snapshots, infect one image, then mount both in another VM to compare.
Thoughts? Any easier way to do this? A utility to view or mount Virtualbox images from the host OS would be handy for something like this.
Let's say that I'm running XP as a guest on virtualbox. I take a snapshot of the virtual drive. Then, I infect it with a virus. Now, I want to see what files the virus created/modified, by comparing the last snapshot to the current state.
Is there any way to do this?
I suppose one way is to setup another VM running a Linux distro, or even another copy of XP, and then mount the infected VM's disk images and compare them from there. But I don't think you can mount an image minus 1 snapshot without reverting the snapshot, can you? What would be cool is to be able to mount the image minus 1 snapshot as one read-only drive, and the image current state as another, and then do a compare from those.
I suppose another option is to clone the image rather than use snapshots, infect one image, then mount both in another VM to compare.
Thoughts? Any easier way to do this? A utility to view or mount Virtualbox images from the host OS would be handy for something like this.