发明名称 METHOD AND SYSTEM FOR DETECTING A COMPRESSED PESTWARE EXECUTABLE OBJECT
摘要 A method and system for detecting a compressed pestware executable object is described. In an illustrative embodiment, while a computer is booting up, an attempt by a running process to exit is detected. The running process is prevented from exiting until a pestware detection procedure has been performed. In one embodiment, the pestware detection procedure includes scanning for pestware signatures the portion of executable program memory associated with the suspended running process. In a different embodiment, the pestware detection procedure includes writing to a file at least the portion of executable program memory associated with the running process, after which the running process is permitted to exit. The file can then be scanned for pestware signatures at a convenient time.
申请公布号 WO2007124420(A3) 申请公布日期 2008.01.17
申请号 WO2007US67082 申请日期 2007.04.20
申请人 WEBROOT SOFTWARE, INC.;BONEY, MATTHEW, L. 发明人 BONEY, MATTHEW, L.
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址
您可能感兴趣的专利