The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 29, 2019

Filed:

Feb. 13, 2017
Applicant:

AO Kaspersky Lab, Moscow, RU;

Inventors:

Maxim Y. Golovkin, Moscow, RU;

Alexey V. Monastyrsky, Moscow, RU;

Vladislav V. Pintiysky, Moscow, RU;

Mikhail A. Pavlyushchik, Moscow, RU;

Vitaly V. Butuzov, Moscow, RU;

Dmitry V. Karasovsky, Moscow, RU;

Assignee:

AO Kaspersky Lab, Moscow, RU;

Attorneys:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 3/0484 (2013.01); G06F 21/53 (2013.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
G06F 21/53 (2013.01); G06F 21/566 (2013.01); G06F 2221/034 (2013.01);
Abstract

Disclosed are system and method for detecting malicious code in files. One exemplary method comprises: intercepting, by a processor, one or more application program interface (API) calls during an execution of a process launched from a file of a computing device; determining and detecting, by the processor, a presence of an exit condition of the process; in response to detecting the exit condition, identifying one or more signatures of a first type and transferring one or more saved memory dumps of the computing device to an emulator for execution; and determining and identifying a malicious code in the file in response to detecting one or more signatures of a second type based at least upon execution results of the transferred memory dumps of the computing device.


Find Patent Forward Citations

Loading…