发明名称 Detecting Rootkits using a malware scanner
摘要 <p>A method of detecting malware such as Rootkits within program code using a malware scanner comprises providing a first version of information relating to the program code to the scanner, causing a second version of the same information to be provided to the malware scanner by injecting code into a third party process, the third party process not being directly identifiable to malware as being associated with a malware scanner, and at the malware scanner, comparing the first and second versions of the information and identifying any differences that are indicative of the presence of malware. The injected code may be executable to collect the required information (fig. 1) or may be a launcher for a process that is executable to collect the required information (fig. 2). The third party process may be Windows (RTM) Explorer, Registry Editor, Task Manager or Command Prompt. The invention is able to detect Rootkits that have been developed to avoid detection by the "cross-view-diff" mechanism.</p>
申请公布号 GB2427716(A) 申请公布日期 2007.01.03
申请号 GB20050013254 申请日期 2005.06.30
申请人 F-SECURE OYJ 发明人 MIKA STAHLBERG;KIMMO KASSLIN;SAMULI LARVALA;ANTTI TIKKANEN
分类号 G06F1/00;G06F21/56 主分类号 G06F1/00
代理机构 代理人
主权项
地址