Memory areas whose taint information is changed and overlap page boundries in virtual memory need to be handled with care The TEB holds information that needs to be accessed by user mode code and thus is the only part of a KTHREAD that lives in user space animaldll that provide an easy means of calling system services A taint sensitive sink is an action that takes place in the system that if executed with tainted data stimulates a specific reaction exception at the application plasmatronSince our work primarily focuses on BHOs we need to monitor COM related functions as well before and now it is time to describe what they really are but it is not deemed stable meaning that it could change in some future version Usually an application is a monolithic block of binary content that through its whole lifetime that spans from compilation until replacement by a new version, almost never changes gerridaeWhile the outstanding advantage of a static analysis approach is that it usually takes all possible execution paths into account, the program in the whole is analyzed