
The anatomy of malware
By Nick Heath
Published: 9 October 2008 17:02 GMT
With hundreds of new pieces of malware being discovered every month, virus hunters are at the front line of the war on malicious software.
Symantec threat researcher Candid Wüest's job is to rip apart the malware that the company discovers each day, look into its guts and pass on its telltale signatures to protect machines worldwide.
Wüest laid bare the process of picking through the viruses and spyware that lands at the door of Symantec's 100-strong team of malware hunters in Europe.
One of the first things that Symantec does is to peer inside the malware using a Hex editor, as seen here, allowing the researchers to start piecing together how it works.
Here, for example, in the right-hand column the text strings show "MZ" indicating the malware is a Windows binary file.
Further down the screen you can see PEC2, indicating it has been packed into a runtime packer, a method of compressing an executable program.
Wüest and his team have to decrypt everything inside the malware and contend with the anti-reverse engineering techniques used by the malware writers, aimed at stopping the hunters in their tracks.
Photo credit: Symantec
Natural Language Processing: a) Extracting Keywords / topics b) Probabilistic Grammars c) Text classification Machine Learning: a) Kernel Methods b) ...
Your role will be To build or modify existing systems to meet the requirements captured by the team’s business analysts, to provide input and ...
They will need an indepth understanding of the process flow from front to back office. Market Risk Project Manager and Business Analysts- EXCELLENT ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...
Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech