EP2637121A1

A method for detecting and removing malware

Abstract

A method for detecting and removing a suspicious software code in a computer system, according to which the installation process of the suspicious software code is monitored by a client agent residing within the computer system where predetermined operations of the suspicious software code are identified and registered during the installation process. The predetermined operations are compared with a known software code in order to define whether the software code is similar to the known software code. It is then determined if the suspicious software code is malware and if it is, the client agent is instructed to uninstall the suspicious software code from the OS, or to remove its entry from the boot registry.

EP2637121A1, drawing sheet 1
Sheet 1 of 2

Term

Projected expiry 21 February 2033.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

10 claims: 1 independent, 9 dependent

  1. 1
    A method for detecting and removing a suspicious software code in a computer system, comprising the steps of:a. monitoring the installation process of said suspicious software code by a client agent, being a security application residing within said computer system;b. identifying and registering predetermined operations of said suspicious software code during said installation process;c. comparing said predetermined operations with a known software code in order to define whether said suspicious software code is similar to said known software code;d. determining if said suspicious software code is malware and;ande. if it is, instructing said client agent to uninstall said suspicious software code from said OS, or to remove its entry from the boot registry.