Next: Functionality Up: Tools and Techniques Previous: Summary

Knowledge-Based Virus Removal Tools

The primary means of automated removal of virus infection is knowledge-based removal tools. These removal tools attempt to reverse the modifications a virus makes to a file. After analyzing a particular virus to determine its effects on an infected file, a suitable algorithm is developed for disinfecting files. Tools are available which address only a single virus. These single virus disinfectors are usually developed as the result of a particularly virulent outbreak of a virus. Others detectors are general virus removal programs, containing removal algorithms for several viruses.



konczal@csrc.ncsl.nist.gov
Fri Mar 11 21:26:02 EST 1994