Invention Grant
- Patent Title: System and method for rootkit detection and cure
- Patent Title (中): 用于rootkit检测和治疗的系统和方法
-
Application No.: US11623364Application Date: 2007-01-16
-
Publication No.: US07921461B1Publication Date: 2011-04-05
- Inventor: Andrey V. Golchikov , Andrey V. Sobko
- Applicant: Andrey V. Golchikov , Andrey V. Sobko
- Applicant Address: RU Moscow
- Assignee: Kaspersky Lab, ZAO
- Current Assignee: Kaspersky Lab, ZAO
- Current Assignee Address: RU Moscow
- Agency: Bardmesser Law Group
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F9/00 ; G08B23/00

Abstract:
A system, method and computer program product for system for detecting a rootkit on a computer having an operating system, including a native application in ring 0 which, when the operating system is in a trusted state upon a reboot of the computer, after loading of the boot drivers but before loading of non-boot drivers, generates a first snapshot for selected files of the operating system and for a registry; the first snapshot being stored on a persistent storage medium of the computer; a second snapshot for the selected files and for the registry generated by the ordinary application after the loading of the non-boot drivers, generating; means for comparing the second snapshot with the first snapshot; and upon detecting, in the comparing step, one of a masked file and a masked registry branch, means for informing a user of possible rootkit presence on the computer.
Information query