×

System and method for heuristic analysis to identify pestware

  • US 7,480,683 B2
  • Filed: 10/01/2004
  • Issued: 01/20/2009
  • Est. Priority Date: 10/01/2004
  • Status: Active Grant
First Claim
Patent Images

1. A method for blocking pestware activity, the method comprising:

  • detecting an initial pestware activity on a protected computer;

    recording the initial pestware activity;

    receiving an instruction from a user of the protected computer to block the initial pestware activity;

    blocking the initial pestware activity;

    detecting a subsequent pestware activity;

    comparing the subsequent pestware activity with the initial pestware activity;

    responsive to the subsequent pestware activity matching the initial pestware activity, automatically blocking the subsequent pestware activity;

    identifying a process responsible for the subsequent pestware activity;

    identifying, on a storage device, a program file corresponding to the process;

    injecting termination code into the program file corresponding to the process, the termination code determining whether the process is permitted to restart from the program file subsequent to being terminated; and

    terminating the process;

    wherein the termination code is configured to;

    cause the process, upon attempting to launch itself from the program file subsequent to being terminated, to compare itself against a list of pestware that is targeted for removal from the protected computer;

    prevent the process from starting up when the process matches pestware in the list of pestware that is targeted for removal from the protected computer; and

    permit the process to start up normally when the process does not match any pestware in the list of pestware that is targeted for removal from the protected computer.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×