February 2012
Intermediate to advanced
800 pages
23h 55m
English
These files were written specifically for this book, so as of this writing, you should not find a signature for them on VirusTotal.com. Of course, if these files become part of the antivirus signatures as a result of the publication of this book, the results will be different.
Both files were compiled on December 19, 2010, within 1 minute of each other.
There are no indications that either file is packed or obfuscated.
The interesting imports from Lab01-01.exe are FindFirstFile, FindNextFile, and CopyFile. These imports tell us that the program searches the filesystem
and copies files. The most interesting imports from Lab01-01.dll are CreateProcess and Sleep. We also see
that this file imports functions from WS2_32.dll ...