Invention Grant
- Patent Title: Detection of fake antivirus in computers
- Patent Title (中): 检测计算机中的假杀毒软件
-
Application No.: US13243498Application Date: 2011-09-23
-
Publication No.: US08700913B1Publication Date: 2014-04-15
- Inventor: Chia-Chi Chang , Sheng-Chuan Yen , Che-Fu Yeh
- Applicant: Chia-Chi Chang , Sheng-Chuan Yen , Che-Fu Yeh
- Applicant Address: JP Tokyo
- Assignee: Trend Micro Incorporated
- Current Assignee: Trend Micro Incorporated
- Current Assignee Address: JP Tokyo
- Agency: Okamoto & Benedicto LLP
- Main IPC: G06F11/30
- IPC: G06F11/30 ; G06F7/04

Abstract:
Detection of fake antivirus includes classifying text content of a user interface of an application program and scanning files associated with the application program for suspicious code. The user interface may be a graphical user interface (GUI) window of the application program. The text content may be obtained from a painted portion of the GUI window and by intercepting text changing operations performed on the GUI window. The text content may be input to a learning model to determine whether or not the application program belongs to the antivirus category. The application program is deemed to be fake antivirus when the application program is classified as belonging to the antivirus category and has a file with suspicious code.
Information query