System and method for neutralizing pestware that is loaded by a desirable process
First Claim
Patent Images
1. A method of removing pestware, comprising:
- identifying a pestware construct, wherein the pestware construct is loaded by a desirable process;
identifying at least one pestware thread that is loaded by the pestware construct into the desirable process;
suspending the at least one pestware thread; and
neutralizing the pestware construct.
1 Assignment
0 Petitions
Accused Products
Abstract
Systems and methods for managing pestware on a protected computer are described. In one implementation, a pestware construct is identified. Threads loaded by the pestware construct into a desirable process are identified and suspended. Neutralization of the pestware construct is accomplished by preventing code underlying pestware functions exported by the pestware construct from executing. In variations of the invention, registry entries associate with the pestware construct are detected and deleted, and the pestware construct is scheduled for deletion after the next reboot of a protected computer.
-
Citations
24 Claims
-
1. A method of removing pestware, comprising:
-
identifying a pestware construct, wherein the pestware construct is loaded by a desirable process;
identifying at least one pestware thread that is loaded by the pestware construct into the desirable process;
suspending the at least one pestware thread; and
neutralizing the pestware construct. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A computer-readable medium comprising executable instructions to:
-
identify a pestware construct, wherein the pestware construct is loaded by a desirable process;
identify at least one pestware thread that is loaded by the pestware construct into the desirable process;
suspend the at least one pestware thread; and
neutralize the pestware construct. - View Dependent Claims (10, 11, 12, 13, 14, 15, 16)
-
-
17. A system of removing pestware, comprising:
-
a detection module configured to;
identify a pestware construct that is loaded by a desirable process; and
identify at least one pestware thread loaded by the pestware construct into the desirable process; and
a removal module configured to;
suspend the at least one pestware thread; and
neutralize the pestware construct. - View Dependent Claims (18, 19, 20, 21, 22, 23, 24)
-
Specification