A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #9388  by pctech2010
 Mon Oct 24, 2011 1:30 pm
I am very interested in getting more in depth then just identifying rootkits and malware and using removal tools.

I would like to go out and get malware samples and purposely infect a machine to see what it does and how it works but I am lacking information on what to look for... i.e. how to look at a boot sector and identify bad code in the boot sector, how to get the rootkit samples in the wild, how to check running memory, how to find out what processes it hooks etc. and anyting else related to reversing rootkits and malware that I have not mentioned.

I would really like to get into reversing rootkits and malware as I enjoy fighting it using various tools and/ or manually removing the infections.

Any beginner books to read, tutorials or other information would be greatly appreciated :D
 #9390  by rkhunter
 Mon Oct 24, 2011 2:12 pm
What rootkit are you interested?

For example, if you look branch about TDL4 "Rootkit TDL 4 (alias TDSS, Alureon.DX, Olmarik)", first post will tell you required information, including tools for remove and white papers description http://www.kernelmode.info/forum/viewto ... ?f=16&t=19.
This topic contains anti-rootkit tools http://www.kernelmode.info/forum/viewto ... ?f=11&t=10.
Also, using Search button.
Behavior of the threat can by analyzed with help of cloud sandboxes, look http://www.kernelmode.info/forum/viewto ... ?f=16&t=64.