×

System and method for scanning memory for pestware offset signatures

  • US 7,591,016 B2
  • Filed: 04/14/2005
  • Issued: 09/15/2009
  • Est. Priority Date: 04/14/2005
  • Status: Active Grant
First Claim
Patent Images

1. A method for scanning executable memory of a protected computer for pestware comprising:

  • identifying at least one reference point in the executable memory of the protected computer, wherein the at least one reference point is associated with a process being executed by the protected computer via the executable memory of the protected computer, wherein the process is potentially a predetermined type of pestware;

    selecting a first offset and a second offset based on the predetermined type of pestware;

    accessing the memory at the first offset from the at least one reference point so as to identify a first set of information in the executable memory that begins at the first offset from the at least one reference point;

    accessing the memory at the second offset from the at least one reference point so as to identify a second set of information in the executable memory that begins at the second offset from the at least one reference point; and

    wherein the first and second sets of information are separated in the executable memory by information not included in the first and second sets of information wherein the second set of information is spawned from the first set of information upon execution of the first set of information in the executable memory, and wherein the process is identifiable as the predetermined type of pestware when the first and second sets of information each include information specific to the predetermined type of pestware.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×