Method and system for detecting dependent pestware objects on a computer
First Claim
Patent Images
1. A method for detecting pestware on a computer, comprising:
- detecting a primary pestware process in an executable memory of the computer, the primary pestware process including an associated check value by which the primary pestware process can be identified;
locating, at a predetermined offset in the executable memory relative to the check value, a pointer to a string, the string comprising an address of a secondary pestware object stored on the computer; and
following the pointer to the string to ascertain the address of the secondary pestware object.
9 Assignments
0 Petitions
Accused Products
Abstract
A system and method for detecting dependent pestware objects on a computer is described. One illustrative embodiment detects a primary pestware process in an executable memory of the computer, the primary pestware process including an associated check value by which the primary pestware process can be identified; locates, at a predetermined offset in the executable memory relative to the check value, a pointer to a string, the string comprising an address of a secondary pestware object stored on the computer; and follows the pointer to the string to ascertain the address of the secondary pestware object.
89 Citations
24 Claims
-
1. A method for detecting pestware on a computer, comprising:
-
detecting a primary pestware process in an executable memory of the computer, the primary pestware process including an associated check value by which the primary pestware process can be identified;
locating, at a predetermined offset in the executable memory relative to the check value, a pointer to a string, the string comprising an address of a secondary pestware object stored on the computer; and
following the pointer to the string to ascertain the address of the secondary pestware object. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A system for detecting pestware, comprising:
-
a pestware detection module to detect pestware on a computer, the pestware detection module being configured to;
detect a primary pestware process in an executable memory of the computer, the primary pestware process including an associated check value by which the primary pestware process can be identified;
locate, at a predetermined offset in the executable memory relative to the check value, a pointer to a string, the string comprising an address of a secondary pestware object stored on the computer; and
follow the pointer to the string to ascertain the address of the secondary pestware object. - View Dependent Claims (9, 10, 11, 12, 13, 14)
-
-
15. A system for detecting pestware on a computer, comprising:
-
means for detecting a primary pestware process in an executable memory of the computer, the primary pestware process including an associated check value by which the primary pestware process can be identified;
means for locating, at a predetermined offset in the executable memory relative to the check value, a pointer to a string, the string comprising an address of a secondary pestware object stored on the computer; and
means for following the pointer to the string to ascertain the address of the secondary pestware object. - View Dependent Claims (16, 17)
-
-
18. A computer-readable storage medium containing program instructions to detect pestware on a computer, comprising:
-
a first instruction segment configured to identify a primary pestware process in an executable memory of the computer, the primary pestware process including an associated check value by which the primary pestware process can be identified;
a second instruction segment configured to locate, at a predetermined offset in the executable memory relative to the check value, a pointer to a string, the string comprising an address of a secondary pestware object stored on the computer; and
a third instruction segment configured to follow the pointer to the string to ascertain the address of the secondary pestware object. - View Dependent Claims (19, 20, 21, 22, 23, 24)
-
Specification