DETECTING AND REMOVING ROOTKITS FROM WITHIN AN INFECTED COMPUTING SYSTEM

Patent №

US 7,631,357

Granted

2009-12-08

Filed 2005

Owner

SYMANTEC CORPORATION

Lab

AI components

1

hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

11243824

A computing system configured to detect and/or remove a rootkit. For detection, a snapshot component takes a snapshot of a storage unit. A rootkit detection component accesses an enumeration of individual files stored on the storage unit using an alternative file system I/O to detect the presence of a rootkit. For removal, the location of a rootkit is identified and a computing system shutdown is initiated. A snapshot component pauses the shutdown operation prior to the completion of the shut down and takes a snapshot of a file storage unit. A rootkit repair component accesses the identified location of the portion of the file storage unit containing the rootkit and modifies the portion of the snapshot of the file storage unit so as remove the rootkit.

AI hardwareG06F 21/568G06F 21/56

AI classification

AI hardware0.78
Planning0.01
Knowledge representation0.01
Natural language0.00
Vision0.00
Speech0.00
Evolutionary computation0.00
Machine learning0.00

Ownership

SYMANTEC CORPORATION

assignment · 169460856

Assignors

STRINGHAM, RUSSELL R.

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC