发明名称 Fixing computer files infected by virus and other malware
摘要 The disclosed invention is a new method and apparatus for detecting and removing virus from a computing device based on a web or network service. Virus is detected by transmitting the attributes and behavior of application modules on a computing device to another computing device via a web service, where it is analyzed. After the item has been classified, that information is sent back to the computing device along with the instructions on how the remove the virus. Along with the instructions on virus remediation a clean copy of the file or a network location of the clean copy can be sent.
申请公布号 US8935789(B2) 申请公布日期 2015.01.13
申请号 US200912504970 申请日期 2009.07.17
申请人 发明人 Shukla Jayant
分类号 G06F11/00;H04L29/06;G06F21/56 主分类号 G06F11/00
代理机构 代理人
主权项 1. A method for creating list of infected, malicious, and unclassified software or modules or applications on a computing device for a purpose of obtaining a classification and remedial action on the applications, software or modules from a remote computing node, comprising steps of: assigning a unique identifier to the computing device; listing items in file system, registry, and memory of the computing device; listing attributes of the listed items; computing cryptographic hash of the listed items; matching the attributes of the listed items with a local black/white list database; applying a filter to reduce the listed items;storing the unique identifier and filtered items along with the attributes of the listed items;classifying the filtered items and storing the classified items in graphical user interface or machine readable format and taking the remedial action on the classified items; transmitting the stored the classified items and application files to the remote computing node; based on the classification of the classified items, placing plurality of the application files of a computer system placed into a sandbox using intercepting API function calls using imported or exported functions table patching and inline hooking of functions that restrict actions on the classified items while the application files are in the computing device until a cleanup task is completed; and placing the computing device in a restricted mode that limits modifications of the application files until the task of repairing infected application files of the computer device is completed.
地址 Sierra Madre CA US