×

Malware protection

  • US 9,501,644 B2
  • Filed: 03/15/2010
  • Issued: 11/22/2016
  • Est. Priority Date: 03/15/2010
  • Status: Active Grant
First Claim
Patent Images

1. A method of detecting malware in a computer system, the method comprising:

  • determining that an executable file should be identified as not being legitimate by determining that an identifier for the executable file is contained in a database relating to executable files;

    executing the executable file in a real environment, and providing indications to the executable file that it is being executed within an emulated environment by intercepting a communication between the executable file and the computer system during execution of the executable file, wherein upon executing, the executable file is caused to believe it is being executed in an emulated environment;

    monitoring the behaviour of the executable file to determine if the executable file attempts to take an evasive action by at least one of failing to request access to the Internet, failing to attempt to provide a notification, and failing to attempt to collect information relating to the emulated environment;

    determining that the executable file, believing that it is being executed in the emulated environment, is taking the evasive action by failing to respond in a way in which a legitimate file is expected to act; and

    determining that the executable file is malware.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×