![](https://webcf.waybackmachine.org/web/20240729123800im_/https://www.kaspersky.co.uk/content/en-gb/images/repository/smb/safeguarding-user-data-with-kaspersky-cryptomalware-countermeasures-subsystem.jpg)
Being part of Kaspersky System Watcher, this technology analyses the most relevant system event data, including information on the modification of files. When it registers a suspicious application attempting to open a user’s personal files it immediately makes a local protected backup copy of them. If the application is then judged to be malicious, Kaspersky System Watcher automatically rollbacks unsolicited changes.