Last weekend, the RusCrypto'2010 conference took place. Each year, it gathers leading experts in the field of information security. The conference has long expanded its thematic boundaries, and now only one section is dedicated to cryptography. And within the rest, a wide range of practical issues related to information security is considered. For example, two years ago the section “Internet and Information Security” debuted, and this year the sections “Investigation of incidents” were added. Mechanisms, technologies, problems, experience ”and“ Penetration testing internals ”. Every year such transformations attract more and more practitioners to participate in the conference, which favorably distinguishes RusCrypto from other information security measures, where the emphasis is often placed on the marketing orientation of the participants and their reports. This year we took an active part in this conference, and also became sponsors of the RusKrypto CTF student competition. In the section “Investigation of incidents. Mechanisms, technologies, problems, experience ”our report“ Malware research from the point of view of investigation of incidents ”was presented (do not judge strictly the quality of the record, it was produced by amateurs, and in no case does it pretend to be professionalism).