发明名称 Method and apparatus for detecting and removing kernel rootkits
摘要 In one embodiment, an anti-rootkit module compares operating system kernel binary files to their loaded kernel file image in memory to find a difference between them. The difference may be scanned for telltale signs of rootkit modification. To prevent rootkits from interfering with memory access of the kernel file image, a pre-scan may be performed to ensure that paging functions and the interrupt dispatch table are in known good condition. If the difference is due to a rootkit modification, the kernel file image may be restored to a known good condition to disable the rootkit. A subsequent virus scan may be performed to remove remaining traces of the rootkit and other malicious codes from the computer.
申请公布号 US7802300(B1) 申请公布日期 2010.09.21
申请号 US20070702965 申请日期 2007.02.06
申请人 TREND MICRO INCORPORATED 发明人 LIU PETER;YUEH JASON;LIN GENE
分类号 G06F11/00;G06F7/04;G06F12/14;G06F12/16;G06F17/30;G08B23/00;H04N7/16 主分类号 G06F11/00
代理机构 代理人
主权项
地址