- Restore Themida/Winlicense VM codes to original x86
- Debugging and unpacking NsPack
- Malware analysis Machine Reimaging
- Pokas x86 PE Emulator for Generic Unpacking
- Write your Own Unpacker
- analyze a dll
- How to analyze on a live system that is infected?
- immunity debugger plugin
- Unknown packed file prob Zbot variant
- {smartassembly} protection analysis + unpacker (with source)
- Armadillo help?
- Compromised by Super Private Keylogger
- Drive-by browser exploit analysis
- if WinRAR is in NullsoftInstaller, then...
- what about this sample?
- Java Malware question.
- AntiUnpacking Tricks of Malware
- KHOBE and Chicken Little
- extract runtime assembly code ?
- unlock file or folder , i hope this tool might be useful :)
- Interesting Malware analysis write up.
- IDA Debugger - strange behavior when debugging protectors
- Win32.Sinowal MBR rootkit
- Malware that tampers with debugger?
- Fake Virus Alert
- Relations Between APIs in Malware
- Easy and simple way to analyze malwares
- PHP Malware
- Parite.B virus
- Help to identify packer
- AntiDebug using GetKeyboardState?
- Autorun Malware
- unpack exe4j
- Infected, lets chase.
- JAVA malware
- Just 4 question ?
- Debugging an .msi .dll
- Setting up a malware analysis environment
- huh!? freeserials.ws Serials + Trojans!?!?
- KAV malware naming issue (funny)
- MBR worm
- Analysis of compiler infector Induc
- How Find Temporal Order Of API calls in PEs?
- Aurora Example
- Malware which password protects office files
- FSG unpacker with command line support?
- Is this malware?
- Trojan monitoring almost every browser
- Buster Sandbox Analyzer
- Visual Basic Packer???
- yoda cryptor help.
- swf exploit
- URLANDEXIT tag in WMV
- RBoT Packer Issues
- Tips for thwarting VM detection
- Best place to submit a new threat?
- Java Host Virus
- ARTeam: Swimming into Trojan and Rootkit GameThief.Win32.Magania Hostile Code
- MALWARE 0day..fun
- tools from china ->heuristic virus detection (bdv)
- problem with resource section after unpacking
- Malware for analysis - "Michael Jackson Gay" virus (Yahoo messenger spammer)
- i wrote a game music unpacker
- How to extract java classes from executable.
- [Question] How can you dump virtually allocated memory ?
- I got Trojanned
- Virii but we dont care!!!
- PDF Exploit
- exploited pdf
- Malware creates new thread, how do I follow it?
- funny comics unpacking tut
- Please help analysing new SWF exploit!
- LHA encoding/decoding
- Unpacking a MoleBox 2.5.7
- Entropy visualization utilities for packed malware?
- Trojan type infection perhaps?
- CRC calculation
- tinyPE reversing
- CrypKey Instant 6.x -> CrypKey Inc.
- Got a virus - please help analysing
- Question about an algorithm
- Trying to ID the packing in a BIOS file
- ExeCryptor kioresk Tut about lic
- psyb0t
- SANS malware analysis article
- Execryptor EC functions
- Common Malicious API's
- obscure rootkit(?) offer fr infected user, kernel detective (long post)
- Pace Interlok (iLok)
- Researchers unveil persistent BIOS attack methods
- Extracting shellcode from office docs?
- winzix fun??
- thekeys.ws virus (don't know what it is)
- securom nag
- How to deal with polymorphic code
- Where to download malware?
- VB injects DELHPI ~;
- Undetected home work
- Rootkit.Win32.TDSS.eyj Another custom packer/cryptor
- AV Emulators not able to handle far jmp, yet.
- fun malware cryptor ~;
- "HOT URL!" your PC infected, install AV2009
- Another unknown packer in malware
- Malware packed with unknown packer
- Trojan.Win32.VB.jir - Automated Analysis tools Aware
- in VB6 malware \Device\PhysicalMemory?
- today's torrent-malware fight
- Malware refuses to run properly on VMWare
- what's packer of this malware code.
- Conficker dll analyse
- fun remote DLL loading found in malware :)
- Themida protected plugin dll
- Question about Rootkit Unhooker
- Poison-Ivy RAT Packed with Molebox
- Some VB malware
- IDA - Analyzing offset independent malware
- lil malware unpacking contest here!
- Armadillo Inline Patching problem
- SVCHOST.EXE under seige.
- SecuRom 7.30.0012
- XP AntiVirus 2009
- Armadillo OEP
- Malware Challenge Contest
- Armadillo 5.x 6.x IAT problem (oep OK)
- LINK: A Quick Survey on Automatic Unpacking Techniques
- Shellcode analyzing
- PDF_stream_inflater
- Disinfecting a program.
- Themida IAT rebuild for Hardware Dependancys targets
- does this tmp5.tmp install any driver
- unpacked Srizbi
- For you guys to solve out
- recombining functions split into 1-cmd-chunks
- strange AntivirusXP2008?
- Trojan.Win32.Agent.vie
- Packed Malware - Double Packed?
- Please Dump me , Please !
- TR/Crypt.XPACK.Gen - Trojan
- Trojan horse...a Hellenes poetic fancy !!
- Unpacking Storm Worm
- Inside Parite.B virus
- Analyzing Google toolbar requests
- Trojan made in C#
- SWF Encrypt explanation.
- lARP v2.0 Ultra
- a packed exe file, can't be loaded normally
- an arma question
- Run-time Detection of Self-Replication
- Malware analysis examples @ Websense
- eEye BootRoot
- OEP of Arm 1.xx to 2.x protected Targets
- Virtual environment to test CIH (A.K.A Chernobyl) virus?
- seems to some script kiddies autit v3 virus
- Computer Viruses as Artificial Life
- SSDT Hooking + AV
- How to find a suspectious program?
- JSTrojan downloader
- Execryptor + Ollydbg
- 【Help】Please analyze the code
- How to solve this trick ?
- How to unpack this?
- Unpacking WinLicense
- found: Practical Malware Analysis
- Orer AKA W32/Hunk.a
- Very suspicious packed file
- Fake crackme on crackmes.de?
- Unpack securom 5.00.03
- Yoda's Crypter 1.2
- VM detection via VERR/VERW
- Example for nice custom obfuscation
- To start with malwares
- WORM/Nuj.A.124 - Something to play with...
- Debugged program unable to process exception
- help: packer identification
- PC Guard
- Strange section within EXE
- Packed sdbot variant
- SWF Encrypt (Flash 'obfuscator') hacking
- Who is working for an AV company?
- winlogon
- Quick Unpack v1.0 final
- Change file to work right
- possibble rootkit kdjfq.exe
- Malware (packed, polymorphic) dll. Pecompact 2.xx?
- the drivers are peed or wincom32 probably but the exe isnt detected by norton
- Article: "Stealth for Survival: Threat of the Unknown"
- AsProtect 2.2. Help with find OEP
- Recently appeared virus supposed to be from the German BKA :)
- Unwrapping PACE Interlok v5.5.0.2618
- Malware fight
- Suspicious file - Can't unpack
- Me code write good: The l33t skillz of the virus writer
- Capture, care and analysis of Malware made easy
- PE GRUM Virus and Some Search Engine Poisoning malware
- a nice paper on a trojan/malware
- Another trojan I couldn't identify the packer
- Another strange packer
- Strange Packer
- arma's processes
- Armadillo + other protections...
- Malware and Virtual Environments
- Old Stuff
- 2 malware video tutorials by Fifo
- Norwegian Bank Malware Analysis
- BIOHAZARD bags
- Malware analysis: Nailuj sys file
- Malware Forum RULES
- Ways to detect the difference between a packed and unpacked exe in memory
- Arma is breeding like a rabbit!
- Quality of WinLicense
- Malware Analysis: "Skype" Trojan
- Role of Imprec
- OVERLAY
- A new software protection method (Objantihack)
- Odd problem with Acudata
- SafeDisc 4.60 and on...
- HASP DOS Envelope
- re-write a MemoHasp-1 memory
- .NET dump
- armadillo I think, date check
- unknown packer / nice anti-olly trick
- Symbian 9.x ... how to decompress ?!
- Problem with Custom Armadillo Implentation
- [ARTeam] HASP SL - A Deeper Dig by potassium
- Packing / unpacking of Flash SWF files (yes, really!)
- Strange Packer
- 100% Unpacking Flash's tuts
- safedisc problem
- PECompact v1.67 Delphi DLL
- FSG 2 and Delphi...
- Another unknown
- Yoda's Protector 1.3
- Themida - VirtualAllocMemory of four bytes
- WIBU WkbCrypt2 (WITH dongle)
- HardLock Envelope unpacking (WITH dongle)
- Merging Imports with Exports?
- Safedisc dump
- Updating a Wise installation package
- How to extract a Install Shield 10.5 project
- Extracting java classes from exe ?
- SerialShield
- Code to find IAT
- Having trouble with an ARTtut.....arma related
- ASProtect 2.1x SKE
- Looking for the following tuturials
- ARTeam: TheMida_defeating_ring0_by_deroko
- What the heck is this
- Unpacking question
- Can't get the Import table right
- Help ACProtect
