Patents Assigned to PC TOOLS TECHNOLOGY PTY LTD.
  • Publication number: 20090049550
    Abstract: A method of detecting and blocking malicious activity of processes in computer memory during unpacking of a file after the code and data contained in the file are unpacked is described. The method includes inserting a hook function into one or more un-assessed processes running in the computer memory. A hook Is then placed on one or more system calls carried out by the one or more un-assessed processes; the one or more system calls determining an optimal time period in which to detect malicious activity in the un-assessed processes. During the optimal time period the one or more system calls carried out by the one or more un-assessed processes are suspended and attributes of the one or more un-assessed processes are detected and the likely maliciousness of the one or more un-assessed processes is determined from the attributes.
    Type: Application
    Filed: June 6, 2008
    Publication date: February 19, 2009
    Applicant: PC TOOLS TECHNOLOGY PTY LTD
    Inventor: Sergei Shevchenko
  • Publication number: 20080141376
    Abstract: A method of detecting malicious activity, including the steps of: intercepting activity in a processing system 100; detecting attributes of an un-assessed process 460 associated with the activity; comparing the process attributes and activity to a database 430 of attributes and activity associated with known malicious and non-malicious processes; and using an inference filter 470 to compute the likely maliciousness of the un-assessed process.
    Type: Application
    Filed: October 23, 2007
    Publication date: June 12, 2008
    Applicant: PC TOOLS TECHNOLOGY PTY LTD.
    Inventors: Simon Clausen, Rolf Repasi, Kien Sen Huang