A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
Forum Statistics Last post
How to get started in Reversing Rootkits
by pctech2010  - Mon Oct 24, 2011 1:30 pm
1 Replies 
 3441 Views
 by rkhunter
 Mon Oct 24, 2011 2:12 pm
4 Replies 
 5302 Views
 by r2nwcnydc
 Sun Oct 23, 2011 12:28 pm
Find what terminated your process..
by listito  - Tue Sep 27, 2011 9:26 am
5 Replies 
 5458 Views
 by listito
 Sun Oct 23, 2011 6:47 am
Sample code that use TDISend
by Flopik  - Wed Oct 19, 2011 1:29 pm
1 Replies 
 2868 Views
 by EP_X0FF
 Wed Oct 19, 2011 2:41 pm
Inline patching problem.
by lorddoskias  - Sat Sep 17, 2011 8:18 pm
24 Replies 
 18355 Views
 by 0xC0000022L
 Tue Oct 18, 2011 10:33 pm
problem in using ZwQueryVirtualMemory
by noppy  - Mon Oct 17, 2011 12:37 pm
8 Replies 
 10801 Views
 by noppy
 Tue Oct 18, 2011 9:15 am
_DRIVER_SECTION/_MODULE_ENTRY
by lorddoskias  - Sun Oct 16, 2011 12:37 pm
3 Replies 
 5079 Views
 by EP_X0FF
 Sun Oct 16, 2011 1:25 pm
PsSetCreateProcessNotifyRoutine
by Tigzy  - Fri Oct 14, 2011 3:17 pm
4 Replies 
 6439 Views
 by Tigzy
 Fri Oct 14, 2011 3:48 pm
GetProcAddress in Kernel Mode
by utsav.0202  - Thu Aug 18, 2011 9:54 am
3 Replies 
 5671 Views
 by 0xC0000022L
 Tue Oct 11, 2011 8:08 pm
Problem with CreateService
by Tigzy  - Tue Sep 06, 2011 11:50 am
10 Replies 
 11612 Views
 by 0xC0000022L
 Tue Oct 11, 2011 8:00 pm
Crash Thread
by utsav.0202  - Fri Oct 07, 2011 8:37 am
2 Replies 
 3925 Views
 by utsav.0202
 Fri Oct 07, 2011 9:17 am
Detect hooks set with SetWindowsHookEx
by Tigzy  - Wed Sep 28, 2011 9:52 am
5 Replies 
 7957 Views
 by Vrtule
 Wed Oct 05, 2011 7:55 pm
Majorfunction without DriverObject
by Flopik  - Fri Sep 23, 2011 6:07 pm
3 Replies 
 4795 Views
 by rkhunter
 Mon Sep 26, 2011 1:08 pm
Interactive service win 7
by listito  - Fri Aug 05, 2011 5:03 pm
2 Replies 
 3316 Views
 by listito
 Sat Sep 24, 2011 1:47 am
NtOpenThread - Get parent PID
by Tigzy  - Fri Sep 23, 2011 9:32 am
2 Replies 
 5197 Views
 by Tigzy
 Fri Sep 23, 2011 9:45 am
From where is the file accessed?
by utsav.0202  - Wed Sep 21, 2011 11:47 am
0 Replies 
 3108 Views
 by utsav.0202
 Wed Sep 21, 2011 11:47 am
Locating SSDT
by _Lynn  - Mon Sep 19, 2011 3:38 pm
12 Replies 
 14047 Views
 by _Lynn
 Wed Sep 28, 2011 2:52 pm
MBR infection
by utsav.0202  - Thu Sep 15, 2011 9:50 am
1 Replies 
 3139 Views
 by EP_X0FF
 Sun Sep 18, 2011 12:27 am
Rootkit Unhooker Anti-Termination Technique
by __Genius__  - Thu Jun 10, 2010 11:43 am
7 Replies 
 9730 Views
 by erick
 Fri Sep 16, 2011 3:38 pm
Unpacking Help Needed - Ransom Pornorolik
by disturbed  - Sun Sep 11, 2011 8:21 pm
4 Replies 
 6887 Views
 by disturbed
 Mon Sep 12, 2011 5:46 pm
Inline function patching tutorial
by lorddoskias  - Sat Sep 10, 2011 11:40 pm
2 Replies 
 3815 Views
 by lorddoskias
 Sun Sep 11, 2011 2:12 am
Ransom Trojan .ENCODED
by CodeAddiction  - Tue May 03, 2011 6:12 pm
8 Replies 
 9675 Views
 by umerali
 Sat Sep 10, 2011 7:51 am
Problem with FltGetRequestorProcessId()
by irp  - Mon Sep 05, 2011 5:13 pm
2 Replies 
 4127 Views
 by irp
 Wed Sep 07, 2011 8:49 pm
c++ stl in native application
by noppy  - Mon Sep 05, 2011 8:12 am
2 Replies 
 4588 Views
 by noppy
 Tue Sep 06, 2011 4:45 am
SSDT Shadow Hook
by Tigzy  - Wed Aug 17, 2011 9:54 am
47 Replies 
 56598 Views
 by Tigzy
 Tue Aug 30, 2011 8:10 am
  • 1
  • 14
  • 15
  • 16
  • 17
  • 18
  • 20