IP Library Patent Application 11229041
Patent Application
App. No. 11/229,041

Method and apparatus for removing harmful software

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/229,041
Abstract

Embodiments of the invention address the problem of removing malicious code from infected computers.

Claims (56)

1 . A method of protection from harmful software on a computer, comprising:

observing, at the computer, potentially harmful software on the computer at runtime;

determining, at the computer, that at least part of the potentially harmful software is harmful software; and

removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining, despite attempts by the harmful software to resist said removing.

2 . The method of clam 1 , wherein said determining is based on at least autonomous action by the computer, including said observing.

3 . The method of clam 1 , wherein said determining is based on at least input from a user of the computer.

4 . The method of claim 1 , wherein said removing includes:

reversing configuration changes made to the computer by the harmful software.

5 . The method of claim 1 , wherein said removing includes:

restoring configuration parts of the computer affected by the harmful software to system defaults.

6 . The method of claim 1 , wherein said removing includes:

removing files associated with the harmful software from the computer.

7 . The method of claim 1 , wherein said removing includes:

removing processes associated with the harmful software from the computer.

8 . The method of claim 1 , wherein said method occurs independent of the computer receiving a security update subsequent to installation of code performing the method, the security update being generated specifically for the harmful software by a security vendor of the code performing the method.

9 . The method of claim 1 , wherein said observing the potentially harmful software includes observing changes made by the potentially harmful software with approval by a user of the computer, and said determining and said removing occur despite the approval by the user.

10 . The method of claim 1 , wherein said removing is performed despite an absence of uninstall capability by the harmful software.

11 . A computer readable medium having a method of protection from harmful software on a computer, comprising:

the computer readable medium having the method, the method including:

observing, at the computer, potentially harmful software on the computer at runtime;

determining, at the computer, that at least part of the potentially harmful software is harmful software; and

removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining, despite attempts by the harmful software to resist said removing.

12 . A computer having a method of protection from harmful software on the computer, comprising:

the computer having the method, wherein the method includes:

observing, at the computer, potentially harmful software on the computer at runtime;

determining, at the computer, that at least part of the potentially harmful software is harmful software; and

removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining, despite attempts by the harmful software to resist said removing.

13 . A method of protection from harmful software on a computer, comprising:

observing, at the computer, potentially harmful software on the computer at runtime;

determining, at the computer, that at least part of the potentially harmful software is harmful software; and

removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining,

wherein said method occurs independent of the computer receiving a security update subsequent to installation of code performing said method, the security update being generated specifically for the harmful software by a security vendor of the code performing the method.

14 . The method of clam 13 , wherein said determining is based on at least autonomous action by the computer, including said observing.

15 . The method of clam 13 , wherein said determining is based on at least input from a user of the computer.

16 . The method of claim 13 , wherein said removing includes:

reversing configuration changes made to the computer by the harmful software,

17 . The method of claim 13 , wherein said removing includes:

restoring configuration parts of the computer affected by the harmful software to system defaults.

18 . The method of claim 13 , wherein said removing includes:

removing files associated with the harmful software from the computer.

19 . The method of claim 13 , wherein said removing includes:

removing processes associated with the harmful software from the computer.

20 . The method of claim 13 , wherein said observing the potentially harmful software includes observing changes made by the potentially harmful software with approval by a user of the computer, and said determining and said removing occur despite the approval by the user.

21 . The method of claim 13 , wherein said removing is performed despite an absence of uninstall capability by the harmful software.

22 . A computer readable medium having a method of protection from harmful software on a computer, comprising:

the computer readable medium having the method, the method including:

observing, at the computer, potentially harmful software on the computer at runtime;

determining, at the computer, that at least part of the potentially harmful software is harmful software; and

removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining,

wherein said method occurs independent of the computer receiving a security update subsequent to installation of code performing said method, the security update being generated specifically for the harmful software by a security vendor of the code performing the method.

23 . A computer having a method of protection from harmful software on the computer, comprising:

the computer having the method, wherein the method includes:

observing, at the computer, potentially harmful software on the computer at runtime;

determining, at the computer, that at least part of the potentially harmful software is harmful software; and

removing, at runtime, effects of the harmful software from the computer based on at least said observing and said determining,

wherein said method occurs independent of the computer receiving a security update subsequent to installation of code performing said method, the security update being generated specifically for the harmful software by a security vendor of the code performing the method.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Mar 26, 2021
From: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
To: AVAST SOFTWARE, S.R.O.; AVAST SOFTWARE B.V.
Reel/Frame 055726/0407 →
MERGER Recorded Oct 11, 2017
From: AVG TECHNOLOGIES B.V.
To: AVAST SOFTWARE B.V.
Reel/Frame 043841/0899 →
MERGER Recorded Oct 11, 2017
From: AVG NETHERLANDS B.V.
To: AVG TECHNOLOGIES HOLDINGS B.V.
Reel/Frame 043841/0615 →
MERGER Recorded Oct 11, 2017
From: AVG TECHNOLOGIES HOLDINGS B.V.
To: AVG TECHNOLOGIES B.V.
Reel/Frame 043841/0844 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVG NETHERLANDS B.V.
To: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
Reel/Frame 041111/0914 →
RELEASE OF SECURITY INTEREST Recorded Oct 3, 2016
From: HSBC BANK USA, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: LOCATION LABS, INC.; AVG NETHERLANDS B.V.
Reel/Frame 040205/0406 →
SECURITY INTEREST Recorded Oct 16, 2014
From: AVG NETHERLANDS B.V.; LOCATION LABS, INC.
To: HSBC BANK USA, N.A.
Reel/Frame 034012/0721 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2014
From: AVG TECHNOLOGIES CY LIMITED
To: AVG NETHERLANDS B.V.
Reel/Frame 032129/0751 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2009
From: SANA SECURITY, INC.
To: AVG TECHNOLOGIES CY LIMITED
Reel/Frame 022560/0496 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2005
From: WILLIAMSON, MATTHEW; GORELIK, VLADIMIR
To: SANA SECURITY
Reel/Frame 017339/0863 →