Invention Grant
- Patent Title: Detecting ransomware based on file comparisons
-
Application No.: US15895673Application Date: 2018-02-13
-
Publication No.: US10229269B1Publication Date: 2019-03-12
- Inventor: Mark William Patton , Zohiartze Herce San Martín , Jorge Alejandro Duran Royo , Sherab Giovannini
- Applicant: Malwarebytes Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Malwarebytes Inc.
- Current Assignee: Malwarebytes Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Fenwick & West LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/55 ; G06F21/60

Abstract:
An anti-malware application detects and remediates ransomware. The anti-malware application monitors processes executing on a computing device and detects that a process is opening a file for editing. A portion of the original file is saved prior to being edited by the process. Once the edited file is saved, the anti-malware application compares a portion of the edited file to the portion of the original file to determine if the edited file is encrypted. The anti-malware application may determine the process is associated with ransomware based on whether the edited file is encrypted.
Information query