US20130239214A1

Method for detecting and removing malware

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A method for detecting and removing a suspicious software code in a computer system, according to which the installation process of the suspicious software code is monitored by a client agent residing within the computer system where predetermined operations of the suspicious software code are identified and registered during the installation process. The predetermined operations are compared with a known software code in order to define whether the software code is similar to the known software code. It is then determined if the suspicious software code is malware and if it is, the client agent is instructed to uninstall the suspicious software code from the OS, or to remove its entry from the boot registry.

US20130239214A1, drawing sheet 1
Sheet 1 of 3

Term

Projected expiry 6 March 2032.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

10 claims: 2 independent, 8 dependent

  1. 1
    Broadest claimClaim Score 50, average(NHIP)A method for detecting and removing a suspicious software code in a computer system having an operating system, comprising the steps of:detecting installation of a suspicious software code in a computer system by a client agent residing within said computer system;registering suspected software operations by tagging at least a portion of files, registry keys, and operating system elements that have been added to said computer system or that have been changed with said computer system in response to the installation of said suspicious code;following the installation of said suspicious software code, offline comparing suspected operations with a predefined malware operation in order to determine whether said suspected operations are indicative of said malware operation;if said suspected operations have been found to be indicative of malware, instructing said client agent to uninstall said suspicious software code from the operating system by removing tagged files, tagged registry keys and tagged operating system elements from the operating system.