US2014150106A1PendingUtilityA1

Computer program, method, and system for preventing execution of viruses and malware

Assignee: VOODOO SOFT HOLDINGS LLCPriority: Jun 3, 2011Filed: Feb 3, 2014Published: May 29, 2014
Est. expiryJun 3, 2031(~4.8 yrs left)· nominal 20-yr term from priority
H04L 63/1408G06F 21/51H04L 63/145G06F 21/565H04L 63/1416
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Preventing execution of viruses or malware on a computing device includes compiling an inventory recordation of legitimate applications and terminating execution of any application not on the inventory recordation while in a protected mode. An instantaneous and unprompted inventory recordation known as a “snapshot” can be performed by the computer program. A user may further train the computer program to identify legitimate applications routinely accessed by the user and to be updated to the inventory recordation, such that the inventory recordation is personal to the user. After training, the protected mode can be activated. A smart icon graphical user interface is utilized, that automatically toggles between locked and unlocked depending on if the computing device is at risk or not, to place the computing device in a protected or unprotected mode.

Claims

exact text as granted — not AI-modified
1 . A malware prevention computer program stored on a non-transitory computer readable memory, the computer program comprising:
 a smart icon graphical user interface that toggles the computer program to a locked state, wherein said locked state denies all new non-whitelisted executable files, code, and modifications to a computer while a network application process is running or a network application is in focus.   
     
     
         2 . The malware prevention computer program of  claim 1 , wherein the smart icon is toggled to an unlocked state, wherein said unlocked state allows all executable files, code, and modifications to the computer when all network applications have been terminated or have lost focus. 
     
     
         3 . The malware prevention computer program of  claim 1 , wherein the computer program creates a whitelist snapshot, wherein said whitelist snapshot is a recordation of all currently running processes, wherein said whitelist snapshot is used by the computer program to allow execution of the executable files and code, along with all new modifications to the computer while in the locked state. 
     
     
         4 . The malware prevention computer program of  claim 1 , wherein the computer program denies execution of all new executable files and code, along with any and all new modifications to the computer while in the locked state. 
     
     
         5 . The malware prevention computer program of  claim 1 , wherein the smart icon is displayed prominently on a desktop graphical user interface of the computer and viewable over all other applications, further having an ability to minimize if instructed by the user. 
     
     
         6 . The malware prevention computer program of  claim 1 , wherein the smart icon has an ability to be left-clicked by the user to toggle the malware prevention computer program between the locked state and an unlocked state. 
     
     
         7 . The malware prevention computer program of  claim 1 , wherein said smart icon has an ability to be right-clicked by the user to display a menu of user-selectable options for instructing the malware prevention computer program. 
     
     
         8 . The malware prevention computer program of  claim 1 , wherein the computer program monitors for the presence of Internet activity, and if such Internet activity is detected, the computer program automatically toggles to the locked state upon detection of said Internet activity, for only a duration ending when the presence Internet activity is no longer detected by the computer program. 
     
     
         9 . The malware prevention computer program of  claim 1 , wherein the user is not required to respond to a prompt or to affirmatively instruct an operating system executing the computer program to prevent execution of the non-whitelisted application, and is alternatively presented with a passive flashing smart icon when an executable file or code or a system change is denied execution by the computer program, in which the user can click to run and allow said executable file or code or system change. 
     
     
         10 . The malware prevention computer program of  claim 1 , wherein the computer program instructs the processor to perform the steps of monitoring an elapsed period of time that an unlocked state is activated or that the computing device is idle, and upon the elapsed period of time being equal to or greater than a predetermined time, presenting to the user an option to enable the locked state. 
     
     
         11 . The malware prevention computer program of  claim 1 , wherein the user can activate a first program mode, a second program mode, and a third program mode, wherein an unlocked state is the first program mode, the locked state is the second program mode, and further including the third program mode comprising an always-off state, wherein when said always-off state is activated, the computer program allows execution of any application regardless of whether it is identified on an inventory recordation, an inventory recordation is not updated to include a new item, and an elapsed period of time is not monitored. 
     
     
         12 . A non-transitory computer-readable storage medium with an executable program stored thereon for preventing execution of a virus or malware on a computing device, wherein the program instructs a processor to perform the steps of:
 perform an instantaneous and unprompted inventory recordation of all currently running processes,   wherein the inventory recordation comprises information uniquely identifying a listing of processes approved for execution by the processor during use of the program by a user;   build the inventory recordation, wherein said building step further comprises instructing the processor to perform the steps of:
 receive information identifying at least one application requested by the user to be executed by the computing device, 
 supplement the inventory recordation to include the information identifying the at least one requested application; 
   activate a protected mode, wherein the protected mode is activated upon an event selected from the group consisting of instruction to activate by the user, detection of Internet activity, execution of a network application, gaining focus of a network application, and expiration of a predetermined time delay;   receive, while the protected mode is activated, information indicative of an instruction by the user to execute a new application, wherein the information indicative of an instruction by the user to execute the new application includes information identifying the new application;   compare the information identifying the new application with information identifying the listing of applications on the inventory recordation that are approved for execution;   identify the new application as an application approved for execution if the information identifying the new application matches with information identifying an application on the inventory recordation; and   identify the new application as an application not approved for execution if the information identifying the unconfirmed application does not match with information identifying an application on the inventory recordation.   
     
     
         13 . The computer-readable storage medium of  claim 12 , wherein the program further instructs the processor to perform the step of:
 deactivate the protected mode, wherein the protected mode is deactivated when the user instructs the program to deactivate the protected mode.   
     
     
         14 . The computer-readable storage medium of  claim 12 , wherein activation of the protected mode is activated upon the detection of Internet activity, the program further instructs the processor to perform the step of:
 deactivate the protected mode, wherein the protected mode is automatically deactivated when the Internet activity is no longer detected.   
     
     
         15 . The computer-readable storage medium of  claim 12 , wherein activation of the protected mode is activated upon the execution of a network application, the program further instructs the processor to perform the step of:
 deactivate the protected mode, wherein the protected mode is automatically deactivated when the network application is closed.   
     
     
         16 . The computer-readable storage medium of  claim 12 , wherein activation of the protected mode is activated upon the execution of a network application, the program further instructs the processor to perform the step of:
 deactivate the protected mode, wherein the protected mode is deactivated automatically when the network application loses focus.   
     
     
         17 . The computer-readable storage medium of  claim 12 , further comprising the step of:
 present a smart icon to the user,   wherein the smart icon is a graphical user interface operable to present visual output to the user and receive input by the user,   wherein the visual output presented by the smart icon is used to at least indicate a protection status selected from the group consisting of protected, unprotected, and process blocked.   
     
     
         18 . The computer-readable storage medium of  claim 17 ,
 wherein the smart icon can be configured for viewability over all other applications.   
     
     
         19 . The computer-readable storage medium of  claim 17 ,
 wherein the smart icon can be configured for minimization into the taskbar.   
     
     
         20 . The computer-readable storage medium of  claim 17 ,
 wherein when the visual output presented by the smart icon is used to indicate a process blocked, the program further instructs the processor to perform the step of:
 present a flashing indicator on the smart icon. 
   
     
     
         21 . The computer-readable storage medium of  claim 17 ,
 wherein when the visual output presented by the smart icon is used to indicate a process blocked, the program further instructs the processor to perform the step of:
 present the user with an option to enable the blocked process.

Join the waitlist — get patent alerts

Track US2014150106A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.