Research and Implementation of Compression Shell Unpacking Technology for PE File

Li Lu, Liu Qiuju, XU Ting-rong · 2009

Packing portable executable (PE) file is an effective mean to protect software, but malware authors can also use packing to conceal their malicious executable string data and code. These methods make it difficult to analyze them in detail for virus analyst and software security researcher. They have to unpack the malware first. This paper illustrated the general unpacking methods and principles, using the notepad program in windows as an instance. Firstly analyzed the PE file structure and the principle of packing, and then expounded the steps of unpacking, finally, from the compression shell's point of view, focused on the principles and methods of unpacking technology.

Read the paper · More papers on PaperTik