ebook hướng dẫn cho các bạn những bước cơ bản phân tích 1 Malware,chú ý:
Code:
-Always use a real computer not a virtual machine like they said in several paper it will prevent anti-virtual machine code.
-Freeze windows partition with software like deep freeze or returnil (I prefer returnil but it's my choice)
-Make a second partition for your documents and settings and your tools ( search on google on how to move documents and settings)
-Use monitoring tool to check what file do and reversing tool to analyse part of the file
download:
http://www.zshare.net/download/62949037a7ec76c9/
có thể đọc thêm các tut ở đây:
Code:
http://www.windowsecurity.com/articles/Reverse-Engineering-Malware-Part1.html
http://www.securityfocus.com/infocus/1780