The guys at the National Computer Emergency Response Team of Austria have come up with a useful guide for anyone who is interested but not a PRO at analysing malware. The guide and paper they posted online shows a simple way of building a malware analysis virtual machine, and they provide a binary which automatically logs everything using process monitor from sysinternals. Should be a good method to check out.
http://cert.at/downloads/software/minibis_en.html#configuration