发明名称 Method, device and system for processing computer virus
摘要 A method, an apparatus and a system for processing a computer virus. The method comprises: obtaining the file type of a file which is infected with a computer virus and the process information of a process which is used by the virus when accessing the file; monitoring whether a malicious event occurs in s system, wherein the malicious event is an event which is triggered when the process corresponding to the process information accesses the file of the file type; and refusing the process to access the file of the file type when it is monitored that the malicious event occurs.
申请公布号 US9626510(B2) 申请公布日期 2017.04.18
申请号 US201214123737 申请日期 2012.06.01
申请人 BEIJING QIHOO TECHNOLOGY COMPANY LIMITED 发明人 Li Bo;Zou Guiqiang
分类号 G06F21/56 主分类号 G06F21/56
代理机构 Baker & Hostetler 代理人 Baker & Hostetler
主权项 1. A method for processing a computer virus, comprising: extracting, from a scanning result, a file type of a first file infected with a computer virus; obtaining process information of a first process used by the computer virus to access the first file; storing a correspondence between the file type and the process information; refusing access to a second file by a second process based at least in part on the stored correspondence, wherein a file type of the second file matches the file type of the stored correspondence, and process information of the second process matches the process information of the stored correspondence; sending, by a first antivirus engine among a plurality of antivirus engines included in a system, the stored correspondence between the file type and the process information to a second antivirus engine among the plurality of antivirus engines; storing, by the second antivirus engine, the correspondence between the file type and the process information; and refusing, by the second antivirus engine, access to a third file by a third process based at least in part on the correspondence stored by the second antivirus engine, wherein a file type of the third file matches the file type of the correspondence stored by the second antivirus engine, and process information of the third process matches the process information of the correspondence stored by the second antivirus engine.
地址 Beijing CN