Home > ParetoLogic Blogs > Malware Diaries > Malware analysis & removal
Reply
 
Thread Tools Display Modes
  #1  
Old 10-24-2008, 01:02 AM
Michael Michael is offline
Administrator
Join Date: May 2007
Posts: 313
Default Malware analysis & removal

Our systems are receiving new malware samples every minute. What do we do with them? We analyze them of course :-)

Those samples are processed with "LogMachines" where they are run and their behaviour is logged. We use custom made command-line tools to analyze the samples:



We populate the malware actions into our Database.

A third step involves verifying that we are capable of completely removing the malware without damaging the system. Machines are set up to be infected and them we run our removal tool.



Sometimes the payload from executing the malware changes, or we need to adjust our signatures in order to fully remove, say, a randomly generated malware sample:



We are not using VMware to analyze threats as malware authors know how to check for a "real" environment. By doing so, we are matching what end users have if they get infected.

Jerome
Reply With Quote
  #2  
Old 10-24-2008, 01:20 PM
thomas16 thomas16 is offline
Junior Member
Join Date: Oct 2008
Posts: 1
Default Virus protection

Antivirus protection is the matter you need for your security to defend against worms and trojans. So that I utilize ************.
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use