PaulDotCom mailing list archives

Re: Reverse Engineering.


From: Joel Esler <joel.esler () me com>
Date: Mon, 15 Aug 2011 12:12:03 -0400

ClamAV is an open source antivirus program that is very easy to get started with and learn to write antivirus 
signatures.

Joel

On Aug 15, 2011, at 10:26 AM, Matt Erasmus wrote:

Howdy

On 15 August 2011 15:24, Mohsen Mostafa Jokar <mohsenjokar () gmail com> wrote:
For Reverse a virus what should i do?
How a antivirus company reverse a virus and write virus signature?
Which programming language is need?
I glad if you show me some tools for it or show me a good Doc for learning
reverse.

Check out the malware analysts cookbook for the virus signature stuff.
It's a great book for most things malware related.

Lenny Zeltser also wrote a number of great posts on the topic:

http://zeltser.com/reverse-malware-paper/
http://zeltser.com/reverse-malware/reverse-malware-cheat-sheet.html

I also found this series of posts very useful:

http://resources.infosecinstitute.com/step-by-step-tutorial-on-reverse-engineering-malware-the-zeroaccessmaxsmiscer-crimeware-rootkit/

There is a lot of info out there on Malware reversing so I'd suggest
checking with Google, Bing, Yahoo, my mom etc..

./m
_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

_______________________________________________
Pauldotcom mailing list
Pauldotcom () mail pauldotcom com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com


Current thread: