The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 18, 2014

Filed:

Feb. 04, 2010
Applicant:

Pavel Turbin, Tuusula, FI;

Inventor:

Pavel Turbin, Tuusula, FI;

Assignee:

F-Secure Oyj, Helsinki, FI;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 11/30 (2006.01); G06F 12/14 (2006.01); G06F 21/56 (2013.01); G06F 21/55 (2013.01); G06F 21/62 (2013.01); G06F 12/16 (2006.01); G08B 23/00 (2006.01); G06F 21/51 (2013.01); G06F 9/44 (2006.01); G06F 21/12 (2013.01); G06F 17/30 (2006.01);
U.S. Cl.
CPC ...
G06F 21/566 (2013.01); G06F 21/56 (2013.01); G06F 21/554 (2013.01); G06F 21/568 (2013.01); G06F 21/6281 (2013.01); G06F 21/561 (2013.01); G06F 21/51 (2013.01); G06F 9/4406 (2013.01); G06F 21/121 (2013.01); G06F 9/442 (2013.01); G06F 17/30117 (2013.01);
Abstract

According to a first aspect of the present invention there is provided a method of operating a computer to detect malware, which malware writes a copy of an executable file to a non-volatile memory of the computer and creates a launch point that causes that executable file to be run at start-up of the computer. The method includes, during the shutdown procedures of the computer, monitoring the creation and/or modification of any launch points and, for any such modification or creation, saving a further copy of any executable file associated with the launch point to the non-volatile memory, and, following a subsequent start-up of the computer, examining said further copy to determine if it is potential malware.


Find Patent Forward Citations

Loading…