发明名称 Method and system for treatment of cure-resistant computer malware
摘要 A system, method and computer program product for treating a malware in a computer having multiple copies of the same malicious code activated, where the multiple copies monitor each other's existence, including (a) identifying a presence of the malicious code on the computer; (b) blocking actions that permit one active copy of the malicious code to activate another copy of the malicious code; (c) deleting, from persistent storage, a file containing executable code of the malware; and (d) rebooting the computer. The actions include disabling writes to the persistent storage, disabling writes to a system registry, and/or blocking activation of new processes. The blocking utilizes a driver loaded into the kernel space. The identifying can use signature identification for malware detection.
申请公布号 US8099785(B1) 申请公布日期 2012.01.17
申请号 US20070743730 申请日期 2007.05.03
申请人 PAVLYUSHCHIK MIKHAIL A.;KASPERSKY LAB, ZAO 发明人 PAVLYUSHCHIK MIKHAIL A.
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址