Articles by Glyn Kennington
Mal/Xpaj-B - how to avoid looking like a virus
Many midinfecting viruses leave one or more tell-tale signs in their infected files, which can raise suspicion and increase the chances of heuristic detection. These include a writable code section, unusual imports, cross-section jumps and a large block of encrypted Read more…
Style over content - new Mac scareware emerges
Troj/MacSwp-B is a standard piece of scareware, only notable because it is one of the few examples that has been written for Mac OS X. The author has made a little effort with the presentation, to ensure that it looks Read more…
Apocalypse not yet
The USB worm W32/Zaap-A successfully spreads itself to removable disks, and in some cases to data CDs burned on the infected computer. The writer also intended for it to display the following message if it is run on a specific Read more…
A sandwich virus
One of the simplest methods of file infection is to put the virus at the start of the file, leaving the host at the end. A less common way is to put the host first and save the virus at the Read more…
Hidden poetry in the KillAV worm
Today's worm W32/KillAV-DX makes a nuisance of itself in the usual ways - leaving copies all over your hard disk and USB drives, disabling antivirus software and leaving the computer close to unusable - but its payload is a little less formulaic. Read more…
















