×

System and method for analyzing locked files

  • US 8,452,744 B2
  • Filed: 06/06/2005
  • Issued: 05/28/2013
  • Est. Priority Date: 06/06/2005
  • Status: Active Grant
First Claim
Patent Images

1. A method for scanning files located on a storage device of a protected computer for pestware, the method comprising:

  • identifying, using an application, a file on the storage device that is inaccessible to the application via an operating system of the protected computer, wherein the file is made inaccessible to the application by the operating system before the identifying, the application being separate from the operating system;

    locating, on the storage device while the file remains inaccessible to the application via the operating system, a listing of a plurality of pointers for the file, wherein each of the plurality of pointers in the listing points to a corresponding one of a plurality of locations on the storage device, and the storage device stores each of a plurality of portions of data for the file at a corresponding one of each of the plurality of locations;

    accessing, using the application while the file remains inaccessible to the application via the operating system, at least one of the plurality of portions of data;

    analyzing, while the file remains inaccessible to the application via the operating system, information from the at least one of the plurality of portions of data so as to determine whether the file is a potential pestware file; and

    altering the listing of a plurality of pointers in response to the file being identified as a pestware file and while the operating system continues to limit access to the file via the operating system;

    wherein altering the listing of a plurality of pointers comprises at least one of;

    (i) reading the file allocation table (FAT) into memory and zeroing out the FAT entries associated with the locked file; and

    (ii) deleting the locked file name from a file entry and removing at least a portion of the listing of pointers to the data for the locked file.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×