IP Library Granted Patent US 10,250,644
Granted Patent B2
US 10,250,644 · App. 15/787,593 · Granted Apr 2, 2019

Detection and removal of unwanted applications

Inventors: Carlos Ardanza Azcondo (Bilbao, ES); Elisabeth Irizar Nieto (Bergara, ES); Luis Maria Zubia Murguiondo (Balmaseda, ES); Francisco Sanchez Peña (Santurtzi, ES); Pedro Bustamante Lopez-Chicheri (Mountain View, CA)
Assignee: Malwarebytes, Inc.
H04L63/20G06F21/577H04L63/1441G06F2221/2143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,250,644
App. No.
15/787,593
Granted
Apr 2, 2019
Kind
B2
Abstract

A protection application detects and removes unwanted applications. The protection application scans a client device for suspected unwanted applications. A security server provides an application rating for detected applications to the client device. The application rating is generated based on application retention data received from client devices indicating whether users of the clients choose to remove or retain the application when given the option. The application retention data may be weighed based on a categorization of the clients providing the application retention data into to clients expected to have different reliability levels. The security server can also provide a definition specifying all known components associated with a suspected unwanted application. Responsive to a selection to remove a suspected unwanted application, the protection application uninstalls all components of the application.

Claims (48)

1. A method comprising:

detecting, by a protection application executing on a client device, a suspected unwanted application file associated with an application on the client device;

providing, from the client device to a security server, an indication of the suspected unwanted application file on the client device;

receiving, from the security server by the client device, an application rating and a definition for the application, the application rating representing a reputation of the application for being unwanted, wherein the application rating is based on a weighted combination of counts of detections of respective instances of the suspected unwanted application on a plurality of client devices that resulted in selections to remediate the respective instances, the counts weighted based on versions of protection applications executing on the plurality of client devices from which the selections were made;

responsive to determining that the application rating meets a threshold rating, presenting an option by the client device to remediate the application by:

detecting, during an installation process associated with the application, that a control element of a user interface of the installation process is selected by default to install the application; and

modifying the control element of the user interface to skip installing the application absent user intervention;

responsive to receiving a selection to remediate the application on the client device:

remediating the application using the definition for the application; and

providing, from the client device to the security server, an indication of the selection to remediate and a version of the protection application executing on the client device, wherein the security server updates the application rating based on the selection to remediate and the version of the protection application.

2. The method of claim 1 , wherein presenting the option to remediate the application on the client device further comprises:

providing a message for display in the user interface for presentation on the client device, the message indicating that the application has a high reputation for being an unwanted application; and

presenting a user interface option to remove the application.

3. The method of claim 1 , wherein the versions of protection applications include at least a first version associated with a consumer-level license to the protection applications and a second version associated with a professional-level license to the protection applications, the security server weighting first application retention data associated with the first version less than second application retention data associated with the second version.

4. The method of claim 1 , wherein remediating the application using the definition for the application comprises removing components of the application stored on the client device at a directory address indicated by the definition for the application.

5. The method of claim 1 , wherein the definition for the application includes at least one of an installation file, registry entry, scheduled task, service, and binary file associated with the application, and excludes files known to be safe for the client device.

6. A non-transitory computer-readable storage medium storing instructions, the instructions when executed by a processor causing the processor to perform steps including:

detecting, by a protection application executing on a client device, a suspected unwanted application file associated with an application on the client device;

providing, from the client device to a security server, an indication of the suspected unwanted application file on the client device;

receiving, from the security server by the client device, an application rating and a definition for the application, the application rating representing a reputation of the application for being unwanted, wherein the application rating is based on a weighted combination of counts of detections of respective instances of the suspected unwanted application on a plurality of client devices that resulted in selections to remediate the respective instances, the counts weighted based on versions of protection applications executing on the plurality of client devices from which the selections were made;

responsive to determining that the application rating meets a threshold rating, presenting an option by the client device to remediate the application by:

detecting, during an installation process associated with the application, that a control element of a user interface of the installation process is selected by default to install the application; and

modifying the control element of the user interface to skip installing the application absent user intervention;

responsive to receiving a selection to remediate the application on the client device:

remediating the application using the definition for the application; and

providing, from the client device to the security server, an indication of the selection to remediate and a version of the protection application executing on the client device, wherein the security server updates the application rating based on the selection to remediate and the version of the protection application.

7. The non-transitory computer-readable storage medium of claim 6 , wherein presenting the option to remediate the application on the client device further comprises:

providing a message for display in the user interface for presentation on the client device, the message indicating that the application has a high reputation for being an unwanted application; and

presenting a user interface option to remove the application.

8. The non-transitory computer-readable storage medium of claim 6 , wherein the versions of protection applications include at least a first version associated with a consumer-level license to the protection applications and a second version associated with a professional-level license to the protection applications, the security server weighting first application retention data associated with the first version less than second application retention data associated with the second version.

9. The non-transitory computer-readable storage medium of claim 6 , wherein remediating the application using the definition for the application comprises removing components of the application stored on the client device at a directory address indicated by the definition for the application.

10. The non-transitory computer-readable storage medium of claim 6 , wherein the definition for the application includes at least one of an installation file, registry entry, scheduled task, service, and binary file associated with the application, and excludes files known to be safe for the client device.

11. A computing system comprising:

a processor; and

a non-transitory computer-readable storage medium storing instructions, the instructions when executed by the processor causing the processor to perform steps including:

detecting, by a protection application executing on a client device, a suspected unwanted application file associated with an application on the client device;

providing, from the client device to a security server, an indication of the suspected unwanted application file on the client device;

receiving, from the security server by the client device, an application rating and a definition for the application, the application rating representing a reputation of the application for being unwanted, wherein the application rating is based on a weighted combination of counts of detections of respective instances of the suspected unwanted application on a plurality of client devices that resulted in selections to remediate the respective instances, the counts weighted based on versions of protection applications executing on the plurality of client devices from which the selections were made;

responsive to determining that the application rating meets a threshold rating, presenting an option by the client device to remediate the application by:

detecting, during an installation process associated with the application, that a control element of a user interface of the installation process is selected by default to install the application; and

modifying the control element of the user interface to skip installing the application absent user intervention;

responsive to receiving a selection to remediate the application on the client device:

remediating the application using the definition for the application; and

providing, from the client device to the security server, an indication of the selection to remediate and a version of the protection application executing on the client device, wherein the security server updates the application rating based on the selection to remediate and the version of the protection application.

12. The system of claim 11 , wherein the versions of protection applications include at least a first version associated with a consumer-level license to the protection applications and a second version associated with a professional-level license to the protection applications, the security server weighting first application retention data associated with the first version less than second application retention data associated with the second version.

13. The method of claim 1 , wherein the control element of the user interface is a checkbox, and wherein modifying the control element includes unchecking the checkbox.

14. The non-transitory computer-readable storage medium of claim 6 , wherein the control element of the user interface is a checkbox, and wherein modifying the control element includes unchecking the checkbox.

15. The system of claim 11 , wherein the control element of the user interface is a checkbox, and wherein modifying the control element includes unchecking the checkbox.

Assignments (8)
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 21, 2024
From: COMPUTERSHARE TRUST COMPANY, N.A.
To: MALWAREBYTES INC.
Reel/Frame 069193/0505 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Oct 21, 2024
From: COMPUTERSHARE TRUST COMPANY, N.A.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 069193/0563 →
SECURITY INTEREST Recorded Oct 18, 2024
From: MALWAREBYTES INC.; MALWAREBYTES CORPORATE HOLDCO INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 068943/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2024
From: MALWAREBYTES INC.
To: MALWAREBYTES CORPORATE HOLDCO INC.
Reel/Frame 066900/0386 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 26, 2024
From: MALWAREBYTES CORPORATE HOLDCO INC.
To: COMPUTERSHARE TRUST COMPANY, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 066373/0912 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 1, 2023
From: MALWAREBYTES INC.
To: COMPUTERSHARE TRUST COMPANY, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 062599/0069 →
SECURITY INTEREST Recorded Oct 10, 2019
From: MALWAREBYTES INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 050681/0271 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2017
From: ARDANZA AZCONDO, CARLOS; IRIZAR NIETO, ELISABETH; ZUBIA MURGUIONDO, LUIS MARIA; SANCHEZ PEÑA, FRANCISCO; BUSTAMANTE LOPEZ-CHICHERI, PEDRO
To: MALWAREBYTES INC.
Reel/Frame 043903/0364 →
Continuity (2)
Continuation 15491879 · Apr 19, 2017
Related Publication 20180309793A1 · Oct 25, 2018