Invention Grant
- Patent Title: System and method for analyzing packed files
- Patent Title (中): 用于分析打包文件的系统和方法
-
Application No.: US11460032Application Date: 2006-07-26
-
Publication No.: US08578495B2Publication Date: 2013-11-05
- Inventor: Michael Burtscher
- Applicant: Michael Burtscher
- Applicant Address: US CO Broomfield
- Assignee: Webroot Inc.
- Current Assignee: Webroot Inc.
- Current Assignee Address: US CO Broomfield
- Agency: Sheridan Ross P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A system and method for analyzing executable files on a computer is described. The method in one embodiment includes initiating, with an operating system of the computer, execution of a loader-process; loading, using the loader-process, code of a first executable file into an executable-memory of the computer; and executing the code of the first executable file, wherein the code of the first executable file unpacks other packed-code to generate unpacked code. In addition, the loader-process executes the unpacked code and stops execution of the unpacked code in response to the unpacked code attempting to make a potentially dangerous system call. The unpacked code is analyzed, in response to the unpacked code attempting to make the potentially dangerous system call, to assess whether the first executable file is a pestware file.
Public/Granted literature
- US20080028388A1 SYSTEM AND METHOD FOR ANALYZING PACKED FILES Public/Granted day:2008-01-31
Information query