Methods, apparati, and computer-readable media for detecting malicious
computer code in a host computer (1). A method embodiment of the present
invention comprises the steps of determining (32) whether data leaving
the host computer (1) is addressed to exit a port (15) of the host
computer (1) where outbound executable content normally does not appear;
when the data is addressed to exit such a port (15), determining (33)
whether a string (24) from a pre-established runtime database (9) of
executable threads is present in said data; and when a string (24) from
said runtime database (9) is present in said data, declaring (34) a
suspicion of presence of malicious computer code in said data.