The present invention provides a system, method, and computer-readable
medium for identifying and removing active malware from a computer.
Aspects of the present invention are included in a cleaner tool that may
be obtained automatically with an update service or may be downloaded
manually from a Web site or similar distribution system. The cleaner tool
includes a specialized scanning engine that searches a computer for
active malware. Since the scanning engine only searches for active
malware, the amount of data downloaded and resource requirements of the
cleaner tool are less than traditional antivirus software. The scanning
engine searches specific locations on a computer, such as data mapped in
memory, configuration files, and file metadata for data characteristic of
malware. If malware is detected, the cleaner tool removes the malware
from the computer.