DISABLING EXECUTION OF MALWARE HAVING A SELF-DEFENSE MECHANISM

Patent №

US 8,763,125

Granted

2014-06-24

Filed 2008

Owner

TREND MICRO, INC.

Lab

AI components

1

hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

12238606

A dummy debugger program is installed within the user computer system. The dummy program is registered with the operating system as a debugger and may also be registered as a system service as if it is a kernel mode debugger. The dummy debugger program may have the name of a popular debugging program. Dummy registry keys are created that are typically used by a debugger to make it appear as if a debugger is present within the operating system of the user computer. Dummy program folders or dummy program names are created to make it appear as if a debugger is present within the operating system of the user computer. API calls are intercepted by using API hooks and modified to always return a meaningful value indicating that a debugger is present. Malware performing any checks to see if a debugger is present will be informed that a debugger is present and will then shutdown, sleep, terminate, etc. Or, in order to trick malware into thinking that an emulator is present, any API call is intercepted and the sleep time passed in is raised by a couple of milliseconds. Malware will determine that the time parameter passed in is not equivalent to the elapsed time from before the API call to after the call and the malware will determine that an emulator is present and will terminate.

AI hardwareG06F 21/53G06F 11/3624G06F 21/56G06F 2221/2127

AI classification

AI hardware0.94
Natural language0.04
Knowledge representation0.00
Planning0.00
Machine learning0.00
Speech0.00
Vision0.00
Evolutionary computation0.00

Ownership

TREND MICRO, INC.

assignment · 218800106

Assignors

FENG, HSIANG-AN

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC