Inventors list

Assignees list

Classification tree browser

Top 100 Inventors

Top 100 Assignees


PC TOOLS TECHNOLOGY PTY LTD

PC TOOLS TECHNOLOGY PTY LTD Patent applications
Patent application numberTitlePublished
20090049550METHOD OF DETECTING AND BLOCKING MALICIOUS ACTIVITY - A method of detecting and blocking malicious activity of processes in computer memory during unpacking of a file after the code and data contained in the file are unpacked is described. The method includes inserting a hook function into one or more un-assessed processes running in the computer memory. A hook Is then placed on one or more system calls carried out by the one or more un-assessed processes; the one or more system calls determining an optimal time period in which to detect malicious activity in the un-assessed processes. During the optimal time period the one or more system calls carried out by the one or more un-assessed processes are suspended and attributes of the one or more un-assessed processes are detected and the likely maliciousness of the one or more un-assessed processes is determined from the attributes.02-19-2009