« Top 10 Spyware list for September
PATCH NOW! »

Malware analysis & removal

October 23rd, 2008

Our systems are receiving new malware samples every minute. What do we do with them? We analyze them of course :-)

Those samples are processed with “LogMachines” where they are run and their behaviour is logged. We use custom made command-line tools to analyze the samples:

We populate the malware actions into our Database.

A third step involves verifying that we are capable of completely removing the malware without damaging the system. Machines are set up to be infected and them we run our removal tool.

Sometimes the payload from executing the malware changes, or we need to adjust our signatures in order to fully remove, say, a randomly generated malware sample:

We are not using VMware to analyze threats as malware authors know how to check for a “real” environment. By doing so, we are matching what end users have if they get infected.

Jerome

    This entry was posted on Thursday, October 23rd, 2008 at 4:02 pm and is filed under Research. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    • (1) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • About
  • Contact Us



Malware Top 10

  • Privacy Center
  • Pro AntiSpyware 2009
  • Antivirus XP
  • Antivirus 2009
  • Antivirus 360
  • Internet Antivirus Pro
  • Ultimate Antivirus 2008
  • Ultimate Cleaner
  • Ultimate Defender
  • Renus



Archives

  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Botnets (2)
  • Exploits (14)
  • Fake codecs (14)
  • IM threats (1)
  • Keyloggers (1)
  • Mac security (4)
  • Malware Trends (64)
  • Phishing (5)
  • Research (25)
  • Rogue software (45)
  • Rootkits (2)
  • Uncategorized (66)
  • Wireless Security (1)



 
 
 

© 2009 ParetoLogic Inc.