US2007067844A1PendingUtilityA1
Method and apparatus for removing harmful software
Est. expirySep 16, 2025(expired)· nominal 20-yr term from priority
G06F 21/566G06F 21/568
47
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Embodiments of the invention address the problem of removing malicious code from infected computers.
Claims
exact text as granted — not AI-modified1 . A method of protection from harmful software on a computer, comprising:
observing, at the computer, potentially harmful software on the computer at runtime; determining, at the computer, that at least part of the potentially harmful software is harmful software; and removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining, despite attempts by the harmful software to resist said removing.
2 . The method of clam 1 , wherein said determining is based on at least autonomous action by the computer, including said observing.
3 . The method of clam 1 , wherein said determining is based on at least input from a user of the computer.
4 . The method of claim 1 , wherein said removing includes:
reversing configuration changes made to the computer by the harmful software.
5 . The method of claim 1 , wherein said removing includes:
restoring configuration parts of the computer affected by the harmful software to system defaults.
6 . The method of claim 1 , wherein said removing includes:
removing files associated with the harmful software from the computer.
7 . The method of claim 1 , wherein said removing includes:
removing processes associated with the harmful software from the computer.
8 . The method of claim 1 , wherein said method occurs independent of the computer receiving a security update subsequent to installation of code performing the method, the security update being generated specifically for the harmful software by a security vendor of the code performing the method.
9 . The method of claim 1 , wherein said observing the potentially harmful software includes observing changes made by the potentially harmful software with approval by a user of the computer, and said determining and said removing occur despite the approval by the user.
10 . The method of claim 1 , wherein said removing is performed despite an absence of uninstall capability by the harmful software.
11 . A computer readable medium having a method of protection from harmful software on a computer, comprising:
the computer readable medium having the method, the method including:
observing, at the computer, potentially harmful software on the computer at runtime;
determining, at the computer, that at least part of the potentially harmful software is harmful software; and
removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining, despite attempts by the harmful software to resist said removing.
12 . A computer having a method of protection from harmful software on the computer, comprising:
the computer having the method, wherein the method includes:
observing, at the computer, potentially harmful software on the computer at runtime;
determining, at the computer, that at least part of the potentially harmful software is harmful software; and
removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining, despite attempts by the harmful software to resist said removing.
13 . A method of protection from harmful software on a computer, comprising:
observing, at the computer, potentially harmful software on the computer at runtime; determining, at the computer, that at least part of the potentially harmful software is harmful software; and removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining, wherein said method occurs independent of the computer receiving a security update subsequent to installation of code performing said method, the security update being generated specifically for the harmful software by a security vendor of the code performing the method.
14 . The method of clam 13 , wherein said determining is based on at least autonomous action by the computer, including said observing.
15 . The method of clam 13 , wherein said determining is based on at least input from a user of the computer.
16 . The method of claim 13 , wherein said removing includes:
reversing configuration changes made to the computer by the harmful software,
17 . The method of claim 13 , wherein said removing includes:
restoring configuration parts of the computer affected by the harmful software to system defaults.
18 . The method of claim 13 , wherein said removing includes:
removing files associated with the harmful software from the computer.
19 . The method of claim 13 , wherein said removing includes:
removing processes associated with the harmful software from the computer.
20 . The method of claim 13 , wherein said observing the potentially harmful software includes observing changes made by the potentially harmful software with approval by a user of the computer, and said determining and said removing occur despite the approval by the user.
21 . The method of claim 13 , wherein said removing is performed despite an absence of uninstall capability by the harmful software.
22 . A computer readable medium having a method of protection from harmful software on a computer, comprising:
the computer readable medium having the method, the method including:
observing, at the computer, potentially harmful software on the computer at runtime;
determining, at the computer, that at least part of the potentially harmful software is harmful software; and
removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining,
wherein said method occurs independent of the computer receiving a security update subsequent to installation of code performing said method, the security update being generated specifically for the harmful software by a security vendor of the code performing the method.
23 . A computer having a method of protection from harmful software on the computer, comprising:
the computer having the method, wherein the method includes:
observing, at the computer, potentially harmful software on the computer at runtime;
determining, at the computer, that at least part of the potentially harmful software is harmful software; and
removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining,
wherein said method occurs independent of the computer receiving a security update subsequent to installation of code performing said method, the security update being generated specifically for the harmful software by a security vendor of the code performing the method.Join the waitlist — get patent alerts
Track US2007067844A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.