You are here: silicon.com > Software > Security Strategy

Security Strategy

Photos: A day in the life of a virus hunter

The anatomy of malware

Tags: anti-virus, spyware, viruses, malware

By Nick Heath

Published: 9 October 2008 17:02 GMT


With hundreds of new pieces of malware being discovered every month, virus hunters are at the front line of the war on malicious software.

Symantec threat researcher Candid Wüest's job is to rip apart the malware that the company discovers each day, look into its guts and pass on its telltale signatures to protect machines worldwide.

Wüest laid bare the process of picking through the viruses and spyware that lands at the door of Symantec's 100-strong team of malware hunters in Europe.

One of the first things that Symantec does is to peer inside the malware using a Hex editor, as seen here, allowing the researchers to start piecing together how it works.

Here, for example, in the right-hand column the text strings show "MZ" indicating the malware is a Windows binary file.

Further down the screen you can see PEC2, indicating it has been packed into a runtime packer, a method of compressing an executable program.

Wüest and his team have to decrypt everything inside the malware and contend with the anti-reverse engineering techniques used by the malware writers, aimed at stopping the hunters in their tracks.

Photo credit: Symantec


  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Service Platform Engineer

It's what we do at Symantec. Symantec is the world leader in providing solutions to help individuals and enterprises assure the security, ...

Software Packaging Technician - Banking

Technically, it is mandatory that you have expertise with Sysprep, Symantec Ghost, PXE, Windows XP, Windows Registry, Active Directory and GPOs. My ...

Software Engineer - FTC

It's what we do at Symantec. Symantec is the world leader in providing solutions to help individuals and enterprises assure the security, ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: