发明名称 Detecting and removing rootkits from within an infected computing system
摘要 A computing system configured to detect and/or remove a rootkit. For detection, a snapshot component takes a snapshot of a storage unit. A rootkit detection component accesses an enumeration of individual files stored on the storage unit using an alternative file system I/O to detect the presence of a rootkit. For removal, the location of a rootkit is identified and a computing system shutdown is initiated. A snapshot component pauses the shutdown operation prior to the completion of the shut down and takes a snapshot of a file storage unit. A rootkit repair component accesses the identified location of the portion of the file storage unit containing the rootkit and modifies the portion of the snapshot of the file storage unit so as remove the rootkit.
申请公布号 US7631357(B1) 申请公布日期 2009.12.08
申请号 US20050243824 申请日期 2005.10.05
申请人 SYMANTEC CORPORATION 发明人 STRINGHAM RUSSELL R.
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址