IP Library Granted Patent US 7,546,638
Granted Patent B2
US 7,546,638 · App. 10/392,593 · Granted Jun 9, 2009

Automated identification and clean-up of malicious computer code

Assignee: Symantec Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,546,638
App. No.
10/392,593
Granted
Jun 9, 2009
Kind
B2
Abstract

Malicious computer code ( 101 ) is automatically cleaned-up from a target computer ( 103 ). An operating system ( 109 ) automatically boots ( 201 ) in the computer memory ( 105 ) of the target computer ( 103 ). The booted operating system ( 109 ) automatically runs ( 203 ) a malicious code processing script ( 113 ) in the computer memory ( 105 ) of the target computer ( 103 ), under control of the booted operating system ( 109 ). The malicious code processing script ( 113 ) automatically copies ( 205 ) and runs ( 207 ) at least one malicious code clean-up script ( 115 ). At least one malicious code clean-up script ( 115 ) automatically cleans-up ( 209 ) malicious code ( 101 ) from the target computer ( 103 ).

Claims (73)

1. A computer implemented method for automatically cleaning-up malicious computer code from a target computer, the target computer having computer memory and an associated operating system, the method comprising the steps of:

automatically booting an operating system in the computer memory of the target computer from computer readable media, the booted operating system comprising an operating system other than the operating system associated with the target computer;

the booted operating system automatically running a malicious code processing script in the computer memory of the target computer, under control of the booted operating system;

the malicious code processing script automatically identifying a malicious code that has infected the target computer;

the malicious code processing script automatically copying at least one malicious code clean-up script for the identified malicious code from a location;

the malicious code processing script automatically running the at least one copied malicious code clean-up script in the computer memory of the target computer; and

the at least one malicious code clean-up script automatically cleaning-up the identified malicious code from the target computer.

2. The method of claim 1 further comprising:

the malicious code processing script automatically determining a location where latest malicious code clean-up scripts are available;

the malicious code processing script automatically determining which of the latest malicious code clean-up scripts at the location to copy and run;

the malicious code processing script automatically copying each determined latest malicious code clean-up script from the location; and

the malicious code processing script automatically running each determined latest malicious code clean-up script in the computer memory of the target computer.

3. The method of claim 1 , further comprising the step of:

the malicious code processing script automatically copying a scanner from a location;

the malicious code processing script automatically running the scanner in the computer memory of the target computer to identify the malicious code that has infected the target computer.

4. The method of claim 1 , further comprising the steps of:

the malicious code processing script reading system information from the target computer, in order to determine whether the target computer has access to any remotely mountable file systems;

the malicious code processing script, responsive to determining that the target computer has access to at least one remotely mountable file system, mounting at least one remotely mountable file system to which the target computer has access; and

at least one malicious code clean-up script automatically cleaning-up malicious code from at least one remotely mounted file system.

5. The method of claim 1 , 2 or 3 wherein: the location comprises a remote server computer.

6. The method of claim 5 further comprising the steps of:

the malicious code processing script prompting a user for connectivity information needed in order to establish a network connection; and

the malicious code processing script using the provided connectivity information to establish a network connection.

7. The method of claim 1 , 2 or 3 wherein:

the location comprises a removable computer media.

8. The method of claim 1 wherein the computer readable media from which the operating system is automatically booted comprises a computer readable media from the group of computer readable media comprising:

a removable computer readable media;

a remote computer readable media; and

a separate partition on the target computer.

9. A computer readable medium containing a computer program product for automatically cleaning-up malicious computer code from a target computer, the target computer having computer memory and an associated operating system, the computer program product comprising:

program code for enabling an operating system to automatically boot in the computer memory of the target computer, from computer readable media, the booted operating system comprising an operating system other than the operating system associated with the target computer;

program code for enabling the booted operating system to automatically run a malicious code processing script in the computer memory of the target computer, under control of the booted operating system;

program code for automatically identifying a malicious code that has infected the target computer;

program code for automatically copying at least one malicious code clean-up script for the identified malicious code from a location;

program code for automatically running the at least one copied malicious code clean-up script in the computer memory of the target computer; and

program code for automatically cleaning-up the identified malicious code from the target computer.

10. The computer program product of claim 9 further comprising:

program code for automatically determining a location where latest malicious code clean-up scripts are available;

program code for automatically determining which of the latest malicious code clean-up scripts at the location to copy and run;

program code for automatically copying each determined latest malicious code clean-up script from the location; and

program code for automatically running each determined latest malicious code clean-up script in the computer memory of the target computer.

11. The computer program product of claim 9 , further comprising:

program code for automatically copying a scanner from a location;

program code for automatically running the scanner in the computer memory of the target computer to identify the malicious code that has infected the target computer.

12. The computer program product of claim 9 , further comprising:

program code for reading system information from the target computer, in order to determine whether the target computer has access to any remotely mountable file systems;

program code for mounting at least one remotely mountable file system to which the target computer has access; and

program code for automatically cleaning-up malicious code from at least one remotely mounted file system.

13. The computer program product of claim 9 , 10 or 11 wherein:

the location comprises a remote server computer.

14. The computer program product of claim 13 further comprising:

program code for prompting a user for connectivity information needed in order to establish a network connection; and

program code for using the provided connectivity information to establish a network connection.

15. The computer program product of claim 9 , 10 or 11 wherein:

the location comprises a removable computer media.

16. A computer system for automatically cleaning-up malicious computer code from a target computer, the target computer having computer memory and an associated operating system, the computer system comprising:

an operating system booting module, for automatically booting an operating system in the computer memory of the target computer from computer readable media, the booted operating system comprising an operating system other than the operating system associated with the target computer;

a script running module, for automatically running a malicious code processing script in the computer memory of the target computer, under control of the booted operating system, and for automatically running at least one malicious code clean-up script in the computer memory of the target computer, the script running module being communicatively coupled to the operating system booting module;

a script copying module, for automatically identifying a malicious code that has infected the target computer, and for automatically copying at least one malicious code clean-up script for the identified malicious code from a location, the script copying module being communicatively coupled to the script running module; and

a malicious code clean-up module, for automatically cleaning-up the identified malicious code from the target computer, the malicious code clean-up module being communicatively coupled to the script running module.

17. The computer system of claim 16 , wherein:

the script copying module is further adapted to automatically determine a location where latest malicious code clean-up scripts are available;

the script copying module is further adapted to automatically determine which of the latest malicious code clean-up scripts at the location to copy and run;

the script copying module is further adapted to automatically copy each determined latest malicious code clean-up script from the location; and

the script running module is further adapted to automatically run each determined latest malicious code clean-up script in the computer memory of the target computer.

18. The computer system of claim 16 , further comprising:

a scanning module communicatively coupled to the script copying module, and to the script running module; and wherein:

the script copying module is further adapted to automatically copy the scanning module from a location; and

the script running module is further adapted to automatically run the scanning module in the computer memory of the target computer to identify the malicious code that has infected the target computer.

19. The computer system of claim 16 , 17 or 18 wherein:

the location comprises a remote server computer.

20. The computer system of claim 16 , 17 or 18 wherein:

the location comprises a removable computer media.

Assignments (5)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jun 18, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 053306/0878 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2003
From: ANDERSON, W. KYLE; BONHAUS, DARYL
To: SYMANTEC CORPORATION
Reel/Frame 013893/0015 →
Continuity (1)
Related Publication 20040187010A1 · Sep 23, 2004