A program clearing method, device, equipment and medium
Patent Information
- Application Number
- CN202611138540.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-29
- Publication Date
- 2026-09-25
AI Technical Summary
[0003]然而,对于具备“驻留、自启动、自恢复”特征的程序(下文简称为目标程序),在上述清除方式中,由于安全管理人员通常仅能定位到目标程序当前正在运行的组件的可执行文件处,难以完整识别目标程序的全量组件及其所有驻留路径,容易导致组件残留,从而导致无法实现对目标程序的彻底清除
本申请实施例提供了一种程序清除方法、装置、设备及介质,本申请通过采集持久化入口对象、运行实体对象和文件对象的对象信息并生成对象链,能够完整锁定需要进行清除的目标程序的全量组件及其所有驻留路径。并且,本申请在处理时首先阻断持久化入口对目标程序的拉起能力并冻结运行实体对象的活动,再对文件对象和持久化入口对象执行清除操作,从而从根本上阻断了目标程序在清除过程中的对抗行为,实现了对目标程序的彻底清除。
Smart Images

Figure CN122816652A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a method, apparatus, device and medium for program removal. Background Technology
[0002] With the continuous development of computer technology, security administrators often need to remove programs in computer terminal security scenarios. Currently, this is usually done by directly locating the executable file of the program and deleting it.
[0003] However, for programs with the characteristics of "residual, self-starting, and self-recovering" (hereinafter referred to as target programs), in the above-mentioned removal methods, since security managers can usually only locate the executable file of the currently running component of the target program, it is difficult to completely identify all the components of the target program and all its resident paths, which can easily lead to component residues, thus making it impossible to completely remove the target program. Summary of the Invention
[0004] In view of the above problems, this application provides a program removal method, apparatus, device and medium that can completely remove the target program.
[0005] The embodiments of this application disclose the following technical solutions: In a first aspect, this application discloses a program removal method, the method comprising: Collect object information of multiple target objects in the terminal; the multiple target objects include persistent entry objects, running entity objects, and file objects; By determining the relationships between the multiple target objects, at least one object chain is generated; If the object chain is determined to be the target object chain according to the preset judgment conditions, then the blocking operation is first performed on the persistent entry object and the running entity object included in the target object chain, and then the clearing operation is performed on the file object and the persistent entry object included in the target object chain.
[0006] Optionally, generating at least one object chain by determining the association relationships between the multiple types of target objects includes: At least one object chain is generated by determining at least one of the following relationships: the path pointing relationship between the persistent entry object and the file object, the command chain relationship between the persistent entry object and the file object, the run-up relationship between the running entity objects, the file symbiotic relationship between the file objects, and the time proximity relationship between the multiple types of target objects.
[0007] Optionally, determining the object chain as the target object chain based on preset judgment conditions includes: The object chain is determined to be the target object chain if it meets at least one of the following preset judgment conditions: the file object lacks a valid digital signature; at least two persistent entry objects simultaneously point to the same file object or the same path cluster; the parent process of the running entity object is a script interpreter or a program in a temporary directory; the file object is located in the user's temporary directory or a hidden subdirectory of the system; the running entity object reappears within a preset time after being terminated; the object chain includes both a main program file and an auxiliary launch component; the object chain includes a disguised or hidden persistent entry object.
[0008] Optionally, after performing the cleanup operation on the file objects and the persistent entry objects included in the target object chain, the method further includes: If at least one of the following situations is detected: the persistent entry object included in the target object chain is not cleared, the running entity object reappears, or the storage path of the file object is rewritten, an alarm indication is triggered.
[0009] Optionally, performing a cleanup operation on the file objects included in the target object chain includes: Move the file objects included in the target object chain to the isolation area for storage, and record the original path and recovery information of the file objects; When a rollback instruction is received, the file object is restored from the quarantine area to the original path according to the recovery information.
[0010] Optionally, the method for determining the association relationship between the multiple types of target objects is as follows: The object information of the multiple target objects is processed by at least one of path normalization processing, command line expansion processing, and target parsing processing to obtain the processed object information. Based on the processed object information, the association relationships between the multiple target objects are determined.
[0011] Optionally, the persistent entry object includes at least one of a service object, a scheduled task object, a registry startup object, a startup directory object, and a Windows Management Instrumentation (WMI) persistent event object; The object information of the running entity object includes at least one of the following: process identifier, parent process identifier, image path, command line, startup time, token information, and a list of loaded modules; The object information of the file object includes at least one of the following: file path, file hash, digital signature status, creation time, modification time, and file occupancy status.
[0012] Secondly, this application discloses a program clearing device, the device comprising: an information acquisition module, a link generation module, and a link processing module; The information acquisition module is used to collect object information of multiple target objects in the terminal; the multiple target objects include persistent entry objects, running entity objects, and file objects; The link generation module is used to generate at least one object chain by determining the association relationship between the multiple types of target objects; The link processing module is configured to, if determined to be a target object chain according to preset judgment conditions, first perform a blocking operation on the persistent entry object and the running entity object included in the target object chain, and then perform a clearing operation on the file object and the persistent entry object included in the target object chain.
[0013] Optionally, the link generation module is specifically used to: generate at least one object chain by determining at least one of the following association relationships: the path pointing relationship between the persistent entry object and the file object, the command chain relationship between the persistent entry object and the file object, the run-start relationship between the running entity objects, the file symbiotic relationship between the file objects, and the time proximity relationship between the multiple types of target objects.
[0014] Optionally, the link processing module is specifically configured to: determine the object chain as a target object chain if the object chain satisfies at least one of the following preset judgment conditions: the file object lacks a valid digital signature; at least two persistent entry objects simultaneously point to the same file object or the same path cluster; the parent process of the running entity object is a script interpreter or a program in a temporary directory; the file object is located in a user temporary directory or a hidden subdirectory of the system; the running entity object reappears within a preset time after being terminated; the object chain simultaneously includes a main program file and an auxiliary launch component; the object chain includes a disguised or hidden persistent entry object.
[0015] Optionally, the device further includes: an alarm indication module; The alarm indication module is used to trigger an alarm indication if at least one of the following occurs: the persistent entry object included in the target object chain is not cleared, the running entity object reappears, or the storage path of the file object is rewritten.
[0016] Optionally, the link processing module is specifically used to: move the file objects included in the target object chain to the isolation area for storage, and record the original path and recovery information of the file objects; when a rollback instruction is received, restore the file objects from the isolation area to the original path according to the recovery information.
[0017] Optionally, the link generation module is specifically used to: perform at least one of the following processes on the object information of the multiple types of target objects: path normalization processing, command line expansion processing, and target parsing processing, to obtain processed object information; and determine the association relationship between the multiple types of target objects based on the processed object information.
[0018] Optionally, the persistent entry object includes at least one of a service object, a scheduled task object, a registry startup object, a startup directory object, and a Windows Management Instrumentation (WMI) persistent event object; The object information of the running entity object includes at least one of the following: process identifier, parent process identifier, image path, command line, startup time, token information, and a list of loaded modules; The object information of the file object includes at least one of the following: file path, file hash, digital signature status, creation time, modification time, and file occupancy status.
[0019] Thirdly, this application discloses an electronic device, the device comprising: a memory and a processor; The memory is used to store programs; The processor is configured to execute the program to implement the various steps of the program cleanup method as described in the first aspect.
[0020] Fourthly, this application discloses a computer-readable medium having a computer program stored thereon, characterized in that, when the computer program is executed by a processor, it implements the steps of the program clearing method as described in the first aspect.
[0021] Compared with the prior art, this application has the following beneficial effects: This application provides a program cleanup method, apparatus, device, and medium. By collecting object information of persistent entry objects, running entity objects, and file objects and generating an object chain, this application can completely lock all components of the target program to be cleaned and all its resident paths. Furthermore, during processing, this application first blocks the persistent entry point's ability to launch the target program and freezes the activity of the running entity objects, and then performs cleanup operations on the file objects and persistent entry objects. This fundamentally blocks the target program's resistant behavior during the cleanup process, achieving complete cleanup of the target program. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 A flowchart illustrating a program cleanup method provided in this application embodiment; Figure 2 A schematic diagram of a program clearing device provided in an embodiment of this application; Figure 3 This is a schematic diagram of a computer-readable medium provided in an embodiment of this application. Detailed Implementation
[0024] As described above, for target programs with the characteristics of "residual, self-starting, and self-recovering", the above removal methods are difficult to completely identify all components of the target program and all its resident paths because security managers can usually only locate the executable file of the currently running component of the target program. This can easily lead to component residue, thus making it impossible to completely remove the target program.
[0025] Through research, the inventors have provided a method, apparatus, device, and medium for program cleanup. This application, by collecting object information of persistent entry objects, running entity objects, and file objects and generating an object chain, can completely lock all components of the target program to be cleaned and all its resident paths. Furthermore, during processing, this application first blocks the persistent entry point's ability to launch the target program and freezes the activity of the running entity objects, and then performs cleanup operations on the file objects and persistent entry objects, thereby fundamentally blocking the target program's resistant behavior during the cleanup process and achieving complete cleanup of the target program.
[0026] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.
[0027] See Figure 1 The figure is a flowchart of a program cleanup method provided in an embodiment of this application. The method includes: S101: Collect object information of multiple target objects in the terminal; the multiple target objects include persistent entry objects, running entity objects and file objects.
[0028] A persistent entry point object is a startup configuration mechanism that a target program implants into the underlying system mechanism to enable it to run automatically when the Windows operating system restarts, a user logs in, or a specific event is triggered. For example, a persistent entry point object includes at least one of the following: a Service object, a Scheduled Task object, a Registry Autorun object, a Startup Folder object, and a Windows Management Instrumentation (WMI) persistent event object.
[0029] For service objects, the collected object information includes at least one of the following: service name, display name, binary executable file path, startup type (e.g., automatic, manual, disabled), current running status, and failure recovery configuration. It is understandable that the reason for including failure recovery configuration in the collected object information is that target programs often use failure recovery configuration to trigger a restart or execute another auxiliary script when the service terminates unexpectedly.
[0030] For scheduled tasks, the collected object information includes at least one of the following: task name, execution command (including the main program path), execution parameters, triggering conditions (e.g., power-on trigger, idle trigger, specific event trigger), task author, and running account.
[0031] For registry startup objects, the collected object information includes key-value pairs of common startup locations in both system and user environments, such as the key names, key value types, and specific data content of locations like Run, RunOnce, Policies\Explorer\Run, and Winlogon\Userinit under HKEY_LOCAL_MACHINE and HKEY_CURRENT_USER.
[0032] For startup directory objects, the collected object information includes executable files, script files (e.g., .bat, .vbs, .ps1), and shortcut files (.lnk) in the system global startup menu and the current user's startup menu directory. For shortcuts, their target path, working directory, and startup parameters need to be further collected.
[0033] For WMI persistent event objects, the collected object information includes the event filter (__EventFilter, which defines the triggering conditions), the consumer (EventConsumer, such as CommandLineEventConsumer, which defines the command line to be executed), and the binding relationship between the two (__FilterToConsumerBinding).
[0034] A running entity object refers to the executable body of a target program that is currently active or suspended in system memory, including process or thread entities. For example, the object information of a running entity object includes at least one of the following: process identifier (PID), parent process identifier (PPID), image path, command line, startup time, token information, and a list of loaded modules (e.g., a list of DLL dynamic link libraries).
[0035] A file object refers to a static file (such as .exe, .sys, .dll files, etc.) that the target program has stored on a physical storage medium such as a terminal disk. For example, the object information of a file object includes at least one of the following: file path, file hash, digital signature status, creation time, modification time, and file occupancy status (i.e., whether it is occupied).
[0036] S102: Generate at least one object chain by determining the association between multiple types of target objects.
[0037] The object information of the multiple target objects obtained in step S101 is often isolated data points in its original state. This application performs the following steps A1-A3 to generate at least one object chain by determining the association relationship between the multiple target objects.
[0038] A1: Perform at least one of the following processing steps on the object information of multiple target objects: path normalization, command line expansion, and target parsing, to obtain the processed object information.
[0039] The reason for path normalization is that target programs often use environment variables, relative paths, system short filenames, or device paths to hide their true physical storage paths. By introducing a path normalization engine, the phenomenon of duplicate names for the same thing can be eliminated, ensuring the uniqueness of subsequent node comparisons.
[0040] The reason for requiring command-line expansion is that target programs often use the system's built-in legitimate interpreter or program as a shell to execute highly obfuscated scripts, Base64 encoded instructions, or instructions concatenated through environment variables. Command-line expansion, by introducing abstract syntax tree parsing and virtual sandbox decoding techniques, can perform multi-layered decoding and deobfuscation of nested instructions, exposing the payload of the indirectly called real target component or the file path it ultimately points to.
[0041] The reason for needing target parsing is that for non-direct text objects such as shortcuts, complex registry keys, or WMI event filters, target parsing techniques, such as parsing the LNK file structure to extract the working directory and command-line arguments, or parsing the WMI CommandLineEventConsumer object, can accurately extract the actual execution payload or target file path that it points to.
[0042] A2: Based on the processed object information, determine the relationships between multiple target objects.
[0043] The relationships between multiple target objects include: path pointing from persistent entry objects to file objects, command chain relationships from persistent entry objects to file objects, run-launch relationships between running entity objects, file symbiosis relationships between file objects, and temporal proximity relationships between multiple target objects, as shown in Table 1 below: Table 1
[0044] A3: Generate at least one object chain based on the relationships between multiple target objects.
[0045] First, based on the relationships between various target objects, an object association graph G=(V,E) is generated. Here, the vertex set V represents each type of target object, and the edge set E represents the relationships between each type of target object. Then, based on the object association graph, at least one object chain is determined.
[0046] S103: If the object chain is determined to be the target object chain according to the preset judgment conditions, then the blocking operation is first performed on the persistent entry object and the running entity object included in the target object chain, and then the clearing operation is performed on the file object and the persistent entry object included in the target object chain.
[0047] First, based on preset judgment criteria, determine whether the object chain is the target object chain. For example, the preset judgment criteria may be as follows: The file object in the object chain lacks a valid digital signature (or although it has a signature, its signature issuer information, file description, and actual file behavior are seriously inconsistent); at least two persistent entry objects in the object chain simultaneously point to the same file object or the same path cluster; the parent process of the running entity object in the object chain is a script interpreter, system tool, or program in a temporary directory; the file object in the object chain is located in the user's temporary directory or a hidden subdirectory of the system; the running entity object in the object chain reappears within a preset time (e.g., 5 seconds) after being terminated; the object chain includes both the main program file and auxiliary launch components (e.g., a resident memory daemon process monitors the main process, and is recreated when the main process exits, i.e., the classic daemon chain phenomenon exists); the object chain includes disguised or hidden persistent entry objects (e.g., registering the service name as "svch0st" or "Windows Update Svc," etc., obfuscated names).
[0048] If an object chain satisfies at least N of the above preset judgment conditions (N is a positive integer, for example, N=3), then the object chain is determined to be a high-risk target object chain.
[0049] At this point, firstly, blocking operations are performed on the persistent entry object and running entity object included in the target object chain. These blocking operations are used to cut off the ability of the persistent entry object and running entity object to be restarted before clearing. For example, blocking operations include: pausing or disabling the corresponding service object; disabling the corresponding scheduled task object; for registry startup objects, instead of immediately deleting them, renaming or setting their key-value data to null; and for WMI persistent event objects, temporarily unbinding __FilterToConsumerBinding so that the triggering condition can no longer call and execute the consumer.
[0050] Subsequently, a cleanup operation is performed on the file objects and persistent entry objects included in the target object chain. This cleanup operation is used for controlled cleanup after blocking. It should be noted that, to improve security, this application introduces an isolation rollback mechanism. Specifically, firstly, the file objects included in the target object chain are moved to an isolation zone (e.g., a specific isolated directory with encrypted storage), and the original paths and recovery information (e.g., permission information, associated registry entries, etc.) of the file objects are recorded. Then, when a rollback command is received, the file objects are restored from the isolation zone to their original paths based on the recovery information.
[0051] It should also be noted that after performing the cleanup operation on the file objects and persistent entry objects included in the target object chain, the task does not end directly, but continues to be reviewed. Within a preset time window after the cleanup action is completed (e.g., after a reboot, or within 30 minutes of operation), if at least one of the following occurs: the persistent entry object included in the target object chain is not cleaned up (e.g., protected by a kernel-level driver), the running entity object reappears (e.g., there is an unrecognized higher-level protection mechanism), or the storage path of the file object is rewritten (e.g., resurrection via network), an alarm is triggered. This alarm will not only record detailed recurrence telemetry logs and upload them to the cloud threat intelligence center, but will also notify senior security administrators on the endpoint to intervene, thereby guiding further program cleanup.
[0052] In summary, this application discloses a program cleanup method. By collecting object information from persistent entry objects, running entity objects, and file objects and generating an object chain, this application can completely locate all components of the target program to be cleaned and all its resident paths. Furthermore, during processing, this application first blocks the persistent entry point's ability to launch the target program and freezes the activity of the running entity objects, and then performs cleanup operations on the file objects and persistent entry objects, thereby fundamentally blocking the target program's resistant behavior during the cleanup process and achieving complete cleanup of the target program.
[0053] See Figure 2 The figure is a schematic diagram of a program clearing device provided in an embodiment of this application. The program clearing device 200 includes: an information acquisition module 201, a link generation module 202, and a link processing module 203.
[0054] Information acquisition module 201 is used to collect object information of multiple target objects in the terminal; the multiple target objects include persistent entry objects, running entity objects and file objects; The link generation module 202 is used to generate at least one object chain by determining the association relationship between multiple types of target objects; The link processing module 203 is used to, if the object chain is determined to be the target object chain according to the preset judgment conditions, first perform blocking operations on the persistent entry object and running entity object included in the target object chain, and then perform clearing operations on the file object and persistent entry object included in the target object chain.
[0055] In one specific implementation, the link generation module 202 is specifically used to: generate at least one object chain by determining at least one of the following relationships: the path pointing relationship between the persistent entry object and the file object, the command chain relationship between the persistent entry object and the file object, the run-start relationship between running entity objects, the file symbiotic relationship between file objects, and the temporal proximity relationship between multiple types of target objects.
[0056] In one specific implementation, the link processing module 203 is specifically used to: determine the object chain as the target object chain if the object chain meets at least one of the following preset judgment conditions: the file object lacks a valid digital signature; at least two persistent entry objects simultaneously point to the same file object or the same path cluster; the parent process of the running entity object is a script interpreter or a program in a temporary directory; the file object is located in the user's temporary directory or a hidden subdirectory of the system; the running entity object reappears within a preset time after being terminated; the object chain includes both the main program file and the auxiliary launch component; the object chain includes a disguised or hidden persistent entry object.
[0057] In one specific implementation, the program clearing device 200 further includes: an alarm indication module; The alarm indication module is used to trigger an alarm indication if at least one of the following occurs: the persistent entry object included in the target object chain is not cleared, the running entity object reappears, or the storage path of the file object is rewritten.
[0058] In one specific implementation, the link processing module 203 is specifically used to: move the file objects included in the target object chain to the isolation area for storage, and record the original path and recovery information of the file objects; when a rollback instruction is received, restore the file objects from the isolation area to the original path according to the recovery information.
[0059] In one specific implementation, the link generation module 202 is specifically used to: perform at least one of the following processing on the object information of multiple types of target objects: path normalization processing, command line expansion processing, and target parsing processing, to obtain the processed object information; and determine the association relationship between the multiple types of target objects based on the processed object information.
[0060] In one specific implementation, the persistent entry object includes at least one of the following: service object, scheduled task object, registry startup object, startup directory object, and Windows Management Instrumentation (WMI) persistent event object; the object information of the running entity object includes at least one of the following: process identifier, parent process identifier, image path, command line, startup time, token information, and list of loaded modules; the object information of the file object includes at least one of the following: file path, file hash, digital signature status, creation time, modification time, and file occupancy status.
[0061] In summary, this application discloses a program cleanup device. By collecting object information of persistent entry objects, running entity objects, and file objects and generating an object chain, this application can completely lock all components of the target program to be cleaned and all its resident paths. Furthermore, during processing, this application first blocks the persistent entry point's ability to launch the target program and freezes the activity of the running entity objects, and then performs cleanup operations on the file objects and persistent entry objects, thereby fundamentally blocking the target program's resistant behavior during the cleanup process and achieving complete cleanup of the target program.
[0062] This application also provides corresponding electronic devices and computer-readable media for implementing the program clearing method provided in this application.
[0063] The electronic device includes a memory and a processor. The memory is used to store instructions or code, and the processor is used to execute the instructions or code to cause the device to perform a program clearing method according to any embodiment of this application.
[0064] See Figure 3 This figure is a schematic diagram of a computer-readable medium provided in an embodiment of this application. The computer-readable medium 300 stores a computer program 311, which, when executed by a processor, implements the above-described... Figure 1 The steps for the program cleanup method.
[0065] It should be noted that, in the context of this application, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0066] It should be noted that the machine-readable medium described above in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0067] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.
[0068] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.
[0069] While several specific implementation details are included in the foregoing discussion, these should not be construed as limiting the scope of this application. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0070] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.
Claims
1. A program removal method, characterized in that, The method includes: Collect object information of multiple target objects in the terminal; the multiple target objects include persistent entry objects, running entity objects, and file objects; By determining the relationships between the multiple target objects, at least one object chain is generated; If the object chain is determined to be the target object chain according to the preset judgment conditions, then the blocking operation is first performed on the persistent entry object and the running entity object included in the target object chain, and then the clearing operation is performed on the file object and the persistent entry object included in the target object chain.
2. The method according to claim 1, characterized in that, The step of generating at least one object chain by determining the association relationships between the multiple types of target objects includes: At least one object chain is generated by determining at least one of the following relationships: the path pointing relationship between the persistent entry object and the file object, the command chain relationship between the persistent entry object and the file object, the run-up relationship between the running entity objects, the file symbiotic relationship between the file objects, and the time proximity relationship between the multiple types of target objects.
3. The method according to claim 1, characterized in that, The step of determining the object chain as the target object chain according to preset judgment conditions includes: The object chain is determined to be the target object chain if it meets at least one of the following preset judgment conditions: the file object lacks a valid digital signature; at least two persistent entry objects simultaneously point to the same file object or the same path cluster; the parent process of the running entity object is a script interpreter or a program in a temporary directory; the file object is located in the user's temporary directory or a hidden subdirectory of the system; the running entity object reappears within a preset time after being terminated; the object chain includes both a main program file and an auxiliary launch component; the object chain includes a disguised or hidden persistent entry object.
4. The method according to claim 1, characterized in that, After performing the cleanup operation on the file objects and the persistent entry objects included in the target object chain, the method further includes: If at least one of the following situations is detected: the persistent entry object included in the target object chain is not cleared, the running entity object reappears, or the storage path of the file object is rewritten, an alarm indication is triggered.
5. The method according to claim 1, characterized in that, The step of performing a cleanup operation on the file objects included in the target object chain includes: Move the file objects included in the target object chain to the isolation area for storage, and record the original path and recovery information of the file objects; When a rollback instruction is received, the file object is restored from the quarantine area to the original path according to the recovery information.
6. The method according to claim 1, characterized in that, The method for determining the association relationships between the various target objects is as follows: The object information of the multiple target objects is processed by at least one of path normalization processing, command line expansion processing, and target parsing processing to obtain the processed object information. Based on the processed object information, the association relationships between the multiple target objects are determined.
7. The method according to any one of claims 1-6, characterized in that, The persistent entry object includes at least one of the following: service object, scheduled task object, registry startup object, startup directory object, and Windows Management Instrumentation (WMI) persistent event object; The object information of the running entity object includes at least one of the following: process identifier, parent process identifier, image path, command line, startup time, token information, and a list of loaded modules; The object information of the file object includes at least one of the following: file path, file hash, digital signature status, creation time, modification time, and file occupancy status.
8. A program clearing device, characterized in that, The device includes: an information acquisition module, a link generation module, and a link processing module; The information acquisition module is used to collect object information of multiple target objects in the terminal; the multiple target objects include persistent entry objects, running entity objects, and file objects; The link generation module is used to generate at least one object chain by determining the association relationship between the multiple types of target objects; The link processing module is configured to, if determined to be a target object chain according to preset judgment conditions, first perform a blocking operation on the persistent entry object and the running entity object included in the target object chain, and then perform a clearing operation on the file object and the persistent entry object included in the target object chain.
9. An electronic device, characterized in that, The device includes: a memory and a processor; The memory is used to store programs; The processor is configured to execute the program to implement the steps of the program clearing method as described in any one of claims 1 to 7.
10. A computer-readable medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the program cleanup method as described in any one of claims 1 to 7.