发明名称 Method and system for detection of previously unknown malware components
摘要 A system, method, and computer program product for identifying malware components on a computer, including detecting an attempt to create or modify an executable file or an attempt to write to a system registry; logging the attempt as an auditable event; performing a malware check on executable files of the computer; if malware is detected on the computer, identifying all other files created or modified during the auditable event, and all other processes related to the auditable event; terminating the processes related to the auditable event; deleting or quarantining the executable files created or modified during the auditable event; and if the deleted executable files include any system files, restoring the system files from a trusted backup. Optionally, all files and processes having a parent-child relationship to a known malware component or known infected file are identified. A log of auditable events is maintained, and is recoverable after system reboot.
申请公布号 US7472420(B1) 申请公布日期 2008.12.30
申请号 US20080108457 申请日期 2008.04.23
申请人 KASPERSKY LAB, ZAO 发明人 PAVLYUSHCHIK MIKHAIL A.
分类号 G06F11/00;G06F12/14;G06F15/18;G06F17/30 主分类号 G06F11/00
代理机构 代理人
主权项
地址