Method for Identifying Unknown Virus and Deleting It
    3.
    发明申请
    Method for Identifying Unknown Virus and Deleting It 审中-公开
    识别未知病毒并删除它的方法

    公开(公告)号:US20080289042A1

    公开(公告)日:2008-11-20

    申请号:US12093948

    申请日:2006-10-31

    IPC分类号: G06F21/00

    CPC分类号: G06F21/566

    摘要: A method for identifying unknown virus program, includes: getting the behavior data of the program that would be tested, determining whether the said program is a virus program or not based on the behavior data of said program and the behavior data of pre-setting typical virus program. A method for deleting the virus program, according to the behavior of the virus program, sets and performs an anti-operation which is in reversed to the virus program, and gets back the destroyed data.

    摘要翻译: 一种用于识别未知病毒程序的方法,包括:获取要测试的程序的行为数据,基于所述程序的行为数据确定所述程序是否是病毒程序,以及预设典型的行为数据 病毒程序。 根据病毒程序的行为,删除病毒程序的方法设置并执行与病毒程序相反的反作用,并且恢复被破坏的数据。

    Method for Deleting Virus Program and Method to Get Back the Data Destroyed by the Virus
    4.
    发明申请
    Method for Deleting Virus Program and Method to Get Back the Data Destroyed by the Virus 审中-公开
    删除病毒程序的方法和取回病毒破坏的数据的方法

    公开(公告)号:US20080222215A1

    公开(公告)日:2008-09-11

    申请号:US12093776

    申请日:2006-10-31

    IPC分类号: G06F17/30

    CPC分类号: G06F21/568 G06F11/1446

    摘要: The present invention discloses a method of recovering data corrupted by a virus program, comprising: obtaining a devastating behavior operation step that can be performed by the virus program; establishing a reverse behavior operation step corresponding to the devastating behavior operation step; performing the corresponding reverse behavior operation step in response to the devastating behavior operation step that can be performed by the virus program. The present invention further provides a method of removing a virus program, comprising: establishing reverse behavior operation steps corresponding to operation steps of the virus program, executing the reverse behavior operation steps and removing the program to be checked. The method of the present invention employs different reverse behavior operation steps for different virus programs, recovering data corrupted by a virus program, eliminates the defect that existing methods of removing a virus perform a identical processing step for any virus program, enabling the computer removed of the virus program to recover as far as possible to its previous state before infected by the virus program.

    摘要翻译: 本发明公开了一种恢复由病毒程序损坏的数据的方法,包括:获取可由病毒程序执行的破坏行为操作步骤; 建立与破坏行为操作步骤对应的反向行为操作步骤; 响应于可由病毒程序执行的破坏行为操作步骤,执行相应的反向行为操作步骤。 本发明还提供了一种去除病毒程序的方法,包括:建立与病毒程序的操作步骤相对应的反向行为操作步骤,执行反向行为操作步骤和移除要检查的程序。 本发明的方法对于不同的病毒程序采用不同的反向行为操作步骤,恢复病毒程序损坏的数据,消除了现有的病毒删除方法对任何病毒程序执行相同处理步骤的缺陷, 病毒程序在病毒程序感染之前尽可能地恢复到之前的状态。

    CHARGED PARTICLE BEAM DEVICE AND A METHOD OF IMPROVING IMAGE QUALITY OF THE SAME
    6.
    发明申请
    CHARGED PARTICLE BEAM DEVICE AND A METHOD OF IMPROVING IMAGE QUALITY OF THE SAME 有权
    充电颗粒束装置和改进其图像质量的方法

    公开(公告)号:US20120274757A1

    公开(公告)日:2012-11-01

    申请号:US13513280

    申请日:2010-11-08

    IPC分类号: H04N7/18

    摘要: The invention relates to a technique of improving a contrast of a lower-layer pattern in a multi layer by synthesizing detected signals from a plurality of detectors by using an appropriate allocation ratio in accordance with pattern arrangement. In a charged particle beam device capable of improving image quality by using detected images obtained from a plurality of detectors and in a method of improving the image quality, a method of generating one or more output images from detected images corresponding to respective outputs of the detectors that are arranged at different locations is controlled by using information of a pattern direction, an edge strength, or others calculated from a design data or the detected image. In this manner, a detection area of the detected signals can be expanded by using the plurality of detectors, and the image quality such as the contrast can be improved by synthesizing the detected signals by using the pattern direction or the edge strength calculated from the design data or the detected images.

    摘要翻译: 本发明涉及一种通过根据图案布置使用合适的分配比例来合成来自多个检测器的检测信号来提高多层下层图案的对比度的技术。 在能够通过使用从多个检测器获得的检测图像来提高图像质量的带电粒子束装置中,以及提高图像质量的方法中,提供一种从与检测器的各个输出对应的检测图像生成一个或多个输出图像的方法 通过使用从设计数据或检测到的图像计算的图案方向,边缘强度或其他的信息来控制布置在不同位置处的位置。 以这种方式,可以通过使用多个检测器来扩展检测信号的检测区域,并且可以通过使用从设计计算出的图案方向或边缘强度合成检测信号来提高诸如对比度的图像质量 数据或检测到的图像。

    A METHOD FOR DETECTING THE OPERATION BEHAVIOR OF THE PROGRAM AND A METHOD FOR DETECTING AND CLEARING THE VIRUS PROGRAM
    8.
    发明申请
    A METHOD FOR DETECTING THE OPERATION BEHAVIOR OF THE PROGRAM AND A METHOD FOR DETECTING AND CLEARING THE VIRUS PROGRAM 审中-公开
    检测程序的操作行为的方法和用于检测和清除病毒程序的方法

    公开(公告)号:US20090133124A1

    公开(公告)日:2009-05-21

    申请号:US12093784

    申请日:2006-10-31

    申请人: Jie Bai

    发明人: Jie Bai

    IPC分类号: G06F21/00 G06F12/14

    CPC分类号: G06F21/564

    摘要: A method for detecting the operation behavior of the program includes: obtaining the destructive operation behavior of the known virus program; setting the corresponding control and process program according to the destructive operation behavior; making the control and process program get the control right of destructive operation behavior; the destructive operation behavior of the program to be detected calling the corresponding control and process program, the corresponding control and process program recording the operation behavior of the said program to be detected. The method can also return the success response information by the control and process program, so as to induce the program to be detected to perform the next behavior, but the program to be detected don't perform in practicality. That is, the present invention can provide a virtual environment for the program to be detected in order to record a series behavior of it. A method for clearing the virus program setup and perform the adverse behavior operation of the program based on the behavior of the virus program to realize the recovery of the demolished data by the virus.

    摘要翻译: 一种用于检测程序的操作行为的方法包括:获得已知病毒程序的破坏性操作行为; 根据破坏性操作行为设置相应的控制和处理程序; 使控制和处理程序获得破坏性操作行为的控制权; 要检测的程序的破坏性操作行为调用相应的控制和处理程序,相应的控制和处理程序记录要检测的所述程序的操作行为。 该方法还可以通过控制和处理程序返回成功响应信息,以便引导程序被检测以执行下一个行为,但是要检测的程序在实际上不执行。 也就是说,本发明可以为要检测的程序提供虚拟环境,以便记录其串行行为。 一种用于根据病毒程序的行为来清除病毒程序设置并执行程序的不利行为操作的方法,以实现病毒恢复被拆除的数据。