摘要:
Disclosed is a computer-implemented method for malware detection. The method comprises analyzing by an antivirus application (310) a software object (200) for presence of malware; retrieving from an antivirus database (160) of the antivirus application (310) an antivirus record associated with the analyzed object (200), wherein the antivirus record identifies the object (200) as malicious and wherein the antivirus record is adapted to include a working status (210) and a test status (220) and checking for a correction for the retrieved antivirus record, wherein said correction includes a change in the status of the antivirus record. When a correction for the antivirus record is found, said correction is used for the retrieved antivirus record for further operation of the antivirus application (310) with the object (200). When the processing of the software object (200) using a corrected record with working status (210) indicates that the software object (200) is malicious, the user is at least notified about detected malware; and when the processing of the software object (200) using a corrected record with test status (220) indicates that the software object (200) is malicious, the user is at least not notified about detected malware.
摘要:
Disclosed is a computer-implemented method for malware detection. The method comprises analyzing by an antivirus application (310) a software object (200) for presence of malware; retrieving from an antivirus database (160) of the antivirus application (310) an antivirus record associated with the analyzed object (200), wherein the antivirus record identifies the object (200) as malicious and wherein the antivirus record is adapted to include a working status (210) and a test status (220) and checking for a correction for the retrieved antivirus record, wherein said correction includes a change in the status of the antivirus record. When a correction for the antivirus record is found, said correction is used for the retrieved antivirus record for further operation of the antivirus application (310) with the object (200). When the processing of the software object (200) using a corrected record with working status (210) indicates that the software object (200) is malicious, the user is at least notified about detected malware; and when the processing of the software object (200) using a corrected record with test status (220) indicates that the software object (200) is malicious, the user is at least not notified about detected malware.
摘要:
Disclosed are system and method for correcting antivirus records. In an example method, during analysis of a software object for malware, an antivirus application retrieves from an antivirus database an antivirus record associated with the analyzed object, which identifies the object as malicious or clean. The application also checks if there is a correction for the antivirus record in an antivirus cache and use the correction for analysis of the software object. If no correction is found in the cache, the application checks correctness of the antivirus record with an antivirus server. The antivirus server uses statistical information about software objects collected from antivirus applications deployed on different computers to validate correctness of antivirus records. If the antivirus server provides a correction for the antivirus record, the application uses the provided correction for analysis of the software object for malware.