FIELD: information technology.
SUBSTANCE: method of neutralising malware blocking computer operation includes using a separate antivirus activation device which is designed for activation of a malware counteracting procedure by a user and which has sockets for connecting a control bus, a controller and an activation unit. The computer unblocking and cleaning procedure is performed in response to an activation signal received from an antivirus activation device. Said unblocking and cleaning procedure includes: examining the state of the graphic subsystem of the operating system, searching all created windows and desktops visible for the user; analysing all processes and streams used on the computer at the moment of infection; constructing, based on the collected data, the association of each said window and desktop with a specific process and/or process hierarchy; analysing the obtained data on processes and detecting in each of them loaded modules participating in carrying out the process; searching for programs that are automatically executed when booting the operating system; forming a list of objects deemed malicious; and isolating a malicious object, deleting references thereto from the configuration files of the operating system, and deleting a malicious process originating from the object.
EFFECT: unblocking a computer without losing data and rebooting the computer, high efficiency of antivirus systems and improved computer system security.
6 cl, 3 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD OF DETECTING UNKNOWN PROGRAMS BY LOAD PROCESS EMULATION | 2011 |
|
RU2472215C1 |
SYSTEM AND METHOD FOR DETECTING MALWARE PREVENTING STANDARD USER INTERACTION WITH OPERATING SYSTEM INTERFACE | 2012 |
|
RU2530210C2 |
METHOD FOR DELAYED ELIMINATION OF MALICIOUS CODE | 2014 |
|
RU2583711C2 |
SYSTEM AND METHOD OF DETECTING FRAUDULENT ONLINE TRANSACTIONS | 2014 |
|
RU2571721C2 |
METHOD FOR DISTRIBUTED PERFORMANCE OF COMPUTER SECURITY TASKS | 2011 |
|
RU2494453C2 |
SYSTEM AND METHOD FOR IMPROVING QUALITY OF DETECTING MALICIOUS OBJECTS USING RULES AND PRIORITIES | 2012 |
|
RU2514140C1 |
SYSTEM AND METHOD FOR DEVICE CONFIGURATION-BASED DYNAMIC ADAPTATION OF ANTIVIRUS APPLICATION FUNCTIONAL | 2012 |
|
RU2477520C1 |
TRUSTED ENVIRONMENT FOR MALWARE DETECTION | 2008 |
|
RU2473122C2 |
SYSTEM AND METHOD FOR AUTOMATIC INVESTIGATION OF SAFETY INCIDENTS | 2011 |
|
RU2481633C2 |
METHOD OF ACCESSING PROCEDURES OF LOADING DRIVER | 2014 |
|
RU2586576C1 |
Authors
Dates
2014-09-10—Published
2013-04-24—Filed