CN103123675A - Method and device for scanning computer virus - Google Patents

Method and device for scanning computer virus Download PDF

Info

Publication number
CN103123675A
CN103123675A CN2013100275796A CN201310027579A CN103123675A CN 103123675 A CN103123675 A CN 103123675A CN 2013100275796 A CN2013100275796 A CN 2013100275796A CN 201310027579 A CN201310027579 A CN 201310027579A CN 103123675 A CN103123675 A CN 103123675A
Authority
CN
China
Prior art keywords
file
catalogue
scanning
computer virus
virus
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN2013100275796A
Other languages
Chinese (zh)
Other versions
CN103123675B (en
Inventor
宋得明
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Qihoo Technology Co Ltd
Original Assignee
Beijing Qihoo Technology Co Ltd
Qizhi Software Beijing Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Qihoo Technology Co Ltd, Qizhi Software Beijing Co Ltd filed Critical Beijing Qihoo Technology Co Ltd
Priority to CN201310027579.6A priority Critical patent/CN103123675B/en
Publication of CN103123675A publication Critical patent/CN103123675A/en
Application granted granted Critical
Publication of CN103123675B publication Critical patent/CN103123675B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

The invention discloses a method and a device for scanning computer virus. The method includes the following steps: searching a catalogue and/or a file needing computer virus scanning; recording to the catalogue and/or the file into a configuration file; and carrying out scanning according to information of the catalogue and/or the file recorded in the configuration file when the computer virus scanning is carried out under a specific mode. According to the method and the device for scanning the computer virus, a user can purposefully choose the catalogue and/or the file which is related to computer use habit of the user and does not have universality for computer virus scanning, and compared with a quick scanning mode in the prior art, the scanning has pertinence and can scan the catalogue and/or the file which can not be scanned by the quick scanning mode and are/is stored by the user according to the computer use habit of the user. Compared with an overall scanning mode in the prior art, scanning efficiency is greatly improved.

Description

The method and apparatus of scanning computer virus
Technical field
The present invention relates to computer technology, relate in particular to a kind of method and apparatus of scanning computer virus.
Background technology
Computer virus is the data of establishment or the destruction computer function that inserts in computer program, its can affect computing machine normal use and can self-replacation, the form with one group of computer instruction or program code presents usually.Computer virus has destructiveness, replicability and communicable characteristics.Computer virus is a recapitulative term, refers to that any intentional establishment is used for carrying out without permission and the software program of harmful act normally.Infectious virus, backdoor programs, Key Logger, password are stolen taker, Word and excel macro virus, leading viruses, script virus (batch, windows shell, java etc.), wooden horse, crime software, spyware and ad ware etc., be all some examples that can be referred to as computer virus.
, need to scan system by antivirus software, in order to find and remove these viruses during by virus infections when the file in computer system.Along with popularizing of computing machine, antivirus software all has been installed on subscriber computer basically, be used for the file in computing machine is carried out virus scan and removing.
When antivirus software scans, need a large amount of CPU(Central Processing Unit, CPU (central processing unit)) computing and disk operating, make scanning process very long, and affect system speed.Existing virus scan patterns comprises scan full hard disk and rapid scanning, and the former scans for the All Files in all disks of computing machine, scans the most comprehensive, but consuming time the longest; The latter is only scanned for the catalogue of easily infected virus and/or file etc., and is consuming time shorter, but can't be according to user's needs scanning directory and/or file.The custom of different users storage file when the operation computing machine differs very different, and this causes above-mentioned existing virus scan patterns can not satisfy the needs of different user.
Summary of the invention
In view of the above problems, the present invention has been proposed, in order to a kind of database manipulation request distribution method, equipment and system that overcomes the problems referred to above or address the above problem at least in part is provided.
According to one aspect of the present invention, a kind of method of scanning computer virus is provided, comprise step: catalogue and/or the file of inquiring about pending computer virus scanning; With the information recording/of described catalogue and/or file in configuration file; And when the virus of scanning computer under AD HOC, according to the described catalogue that records in described configuration file and/or the information of file, carry out scanning.
Alternatively, the method for scanning computer virus also comprises according to an embodiment of the invention: whether inquiry has changed catalogue and/or the file of pending computer virus scanning; In the situation that have change, the catalogue after the utilization change and/or the described configuration file of information updating of file.
Alternatively, in the method for scanning computer virus according to an embodiment of the invention, inquiring about the catalogue of pending computer virus scanning and/or the step of file comprises: provide catalogue and/or listed files, to select for catalogue and/or the file of pending computer virus scanning; And the information of preserving selected catalogue and/or file.
Alternatively, in the method for scanning computer virus according to an embodiment of the invention, the step of the described catalogue that records in when scanning computer under AD HOC when virus, according to described configuration file and/or the information and executing scanning of file comprises: in the situation that select with AD HOC scanning computer virus, provide the described catalogue that records in the described configuration file of direct scanning and/or the first shortcut of file; In response to the selection for described the first shortcut, for described catalogue and/or the virus scan of file object computer.
Alternatively, in the method for scanning computer virus according to an embodiment of the invention, the step of the described catalogue that records in when the virus of scanning computer under AD HOC, according to described configuration file and/or the information and executing scanning of file also comprises: in the situation that select with AD HOC scanning computer virus, provide one or more second shortcuts of direct scanning particular category and/or file; In response to the selection for described one or more the second shortcuts, for described particular category and/or the virus scan of file object computer.
Alternatively, in the method for scanning computer virus according to an embodiment of the invention, file, executable file, document files, web page files that described particular category and/or file comprise the desktop catalogue, operating system catalogue, file catalogue, download directory, external drive catalogue of computer operating system, receive by Instant Messenger (IM) software and/or Email.
Alternatively, in the method for scanning computer virus according to an embodiment of the invention, described AD HOC comprises rapid scanning pattern, custom scan pattern.
Alternatively, the method for scanning computer virus also comprises according to an embodiment of the invention: in the situation that scan computer virus, provide the option of removing for computer virus; And in response to the selection for described option, remove for computer virus.
According to another aspect of the present invention, a kind of device of scanning computer virus also is provided, comprising: interface module is suitable for inquiring about catalogue and/or the file that pending computer virus scans; The information recording/module is suitable for information recording/with described catalogue and/or file in configuration file; And the computer virus scan module, be suitable for according to the described catalogue that records in described configuration file and/or the information of file, carrying out scanning when the virus of scanning computer under AD HOC.
Alternatively, in the device of scanning computer virus according to an embodiment of the invention, described interface module also is suitable for inquiring about catalogue and/or the file of whether having changed pending computer virus scanning, described device also comprises: the configuration file update module, be suitable in the situation that have change, the catalogue after the utilization change and/or the described configuration file of information updating of file.
Alternatively, in the device of scanning computer virus according to an embodiment of the invention, interface module is suitable for providing catalogue and/or listed files, to select for catalogue and/or the file of pending computer virus scanning; And be suitable for preserving the information of selected catalogue and/or file.
Alternatively, in the device of scanning computer virus according to an embodiment of the invention, the computer virus scan module is suitable in the situation that select with AD HOC scanning computer virus, and the described catalogue that records in the described configuration file of direct scanning and/or the first shortcut of file are provided; And be suitable in response to the selection for described the first shortcut, for described catalogue and/or the virus scan of file object computer.
Alternatively, in the device of scanning computer virus according to an embodiment of the invention, computer virus scan module 205 also is suitable for providing one or more second shortcuts of direct scanning particular category and/or file in the situation that select with AD HOC scanning computer virus; And be suitable in response to the selection for described one or more the second shortcuts, for described particular category and/or the virus scan of file object computer.
Alternatively, in the device of scanning computer virus according to an embodiment of the invention, file, executable file, document files, web page files that described particular category and/or file comprise the desktop catalogue, operating system catalogue, file catalogue, download directory, external drive catalogue of computer operating system, receive by Instant Messenger (IM) software and/or Email.
Alternatively, in the device of scanning computer virus according to an embodiment of the invention, described AD HOC comprises rapid scanning pattern, custom scan pattern.
Alternatively, the device of scanning computer virus also comprises the computer virus clean-ing module according to an embodiment of the invention, be suitable in the situation that the computer virus scan module scans computer virus, the option of removing for computer virus is provided, and in response to the selection for described option, remove for computer virus.
The invention provides the method and apparatus of above-mentioned scanning computer virus.According to embodiments of the invention, can inquire about the catalogue of pending computer virus scanning and/or file and with its information recording/in configuration file, when the virus of scanning computer under AD HOC, just can carry out scanning according to the described catalogue that records in described configuration file and/or the information of file.According to the present invention, the user can select targetedly that the computing machine use habit to this user is relevant, catalogue that do not have universality and/or file carry out computer virus scanning, such scanning is compared with the rapid scanning pattern of prior art, more targeted, can scan catalogue and/or file that the rapid scanning pattern can't scan, that the user preserves according to the computing machine use habit of oneself; And compare with the scan full hard disk pattern of prior art, saved again and scanned unessential, as not to be subject to computer virus infection catalogue and/or a large amount of sweep times of file, greatly improved scan efficiency.Simultaneously, utilize the approach of shortcut, catalogue and/or file and/or the particular category that is subject to computer virus infection and/or the file that can also need to scan for the user carry out computer virus scanning quickly and easily.
Above-mentioned explanation is only the general introduction of technical solution of the present invention, for can clearer understanding technological means of the present invention, and can be implemented according to the content of instructions, and for above and other objects of the present invention, feature and advantage can be become apparent, below especially exemplified by the specific embodiment of the present invention.
Description of drawings
By reading hereinafter detailed description of the preferred embodiment, various other advantage and benefits will become cheer and bright for those of ordinary skills.Accompanying drawing only is used for the purpose of preferred implementation is shown, and does not think limitation of the present invention.And in whole accompanying drawing, represent identical parts with identical reference symbol.In the accompanying drawings:
Fig. 1 is the process flow diagram of the method for scanning computer virus according to an embodiment of the invention;
Fig. 2 is the schematic diagram at the interface of scanning computer virus according to an embodiment of the invention; And
Fig. 3 is the block diagram of the device of scanning computer virus according to an embodiment of the invention.
Embodiment
Exemplary embodiment of the present disclosure is described below with reference to accompanying drawings in more detail.Although shown exemplary embodiment of the present disclosure in accompanying drawing, yet should be appreciated that and to realize the disclosure and the embodiment that should do not set forth limits here with various forms.On the contrary, it is in order to understand the disclosure more thoroughly that these embodiment are provided, and can with the scope of the present disclosure complete convey to those skilled in the art.
Hereinafter, all types of viruses (comprising virus of nonspecific infection venereal disease poison, Word and excel macro virus, leading viruses, script virus, wooden horse, backdoor programs, Key Logger, password robber taker, mobile device operation system (such as iOS, Android etc.) etc.) are referred to as " computer virus ", describe with convenient.It will be understood by those skilled in the art that hereinafter " computer virus " can be the virus of any type of computing machine/electronic equipment.
Principle of the present invention is applicable to any computer operating system with graphic user interface, including, but not limited to Windows, Linux, Mac OS, Unix etc., principle of the present invention is equally applicable to the operating system of mobile device, including, but not limited to iOS, Android, Windows Phone, Symbian etc.Hereinafter, will take Windows operating system as example, exemplarily describe for principle of the present invention.Yet scope of the present invention is not limited to this, but goes for equally other computer operating system and mobile device operation system.
Fig. 1 schematically illustrates the process flow diagram of the method 100 of scanning computer virus according to an embodiment of the invention.As shown in Figure 1, method 100 starts from step S101, wherein, inquires about catalogue and/or the file of pending computer virus scanning.
According to embodiments of the invention, above-mentioned steps S101 can comprise substep S101a and substep S101b.In substep S101a, can provide catalogue and/or listed files, to select for catalogue and/or the file of pending computer virus scanning.For example, in Windows operating system, the list (such as tree-shaped list etc.) of computer disk catalogue can be provided in graphic user interface, the user can launch list by using input equipment (for example keyboard, mouse, trace ball, touch-screen etc.), finds each catalogue and/or file under each disk.
At this moment, the user just can select (such as by the mode such as choose in list) its required catalogue and/or file that carries out computer virus scanning.Such catalogue and/or file can comprise that the computing machine use habit to this user is relevant, catalogue and/or file that do not have universality.
For example, the e-mail attachment that the user will need to preserve all has been saved in " D :/e-mail attachment " this catalogue, to all be saved in from the software of the Internet download " E :/software installation file " this catalogue, the document of editing all has been saved in " F :/important documents " this catalogue.Above-mentioned catalogue all belongs to the catalogue of user oneself definition, do not have universality, unless carry out scan full hard disk, otherwise antivirus software all can not scan separately for such catalogue, but the file of preserving in above-mentioned catalogue comprises e-mail attachment, from the software of the Internet download and editor's document, the file type that all belongs to easily infected virus especially needs to carry out emphasis scanning.
Again for example, the user has preserved a large amount of web page files in each disk, the web page files of forms such as suffix htm, html by name, mht, these web page files are scattered in a plurality of catalogues in each disk of computing machine, unless carry out scan full hard disk, otherwise antivirus software all can not scan separately for such catalogue, but above-mentioned web page files belongs to the file type of easily infected virus, especially needs to carry out emphasis scanning.
according to embodiments of the invention, in substep S101a, just can select above-mentioned " D :/e-mail attachment ", " E :/software installation file ", " F :/important documents " these catalogues that need to scan, also can select file (the suffix htm by name for example of particular type, html, the web page files of the forms such as mht), the file of particular file size (for example file in a certain file size scope), the file of particular file name (file that for example comprises special key words in filename), the file of particular community (for example file of attribute for hiding), the file of specific creation-time, the file of specific modification time, file of specific access time etc., in order to carry out targetedly computer virus scanning.
The description of above-mentioned catalogue and file characteristic is only example, is used for helping the reader more easily to understand principle of the present invention, but not is used for limiting the scope of the invention.Scope of the present invention is not limited to this, but can be applied to various catalogues and file.
After substep S101a, carry out substep S101b, the information that wherein can preserve selected catalogue and/or file.For example, the information such as the path of selected catalogue and/or file and filename temporarily can be kept in internal memory.
According to embodiments of the invention, and as shown in Figure 1, after step S101, execution in step S103, wherein, with the information recording/of described catalogue and/or file in configuration file.For example, can be with information recording /s such as the above-mentioned path that temporarily is kept at selected catalogue in internal memory and/or file and filenames in configuration file, the type of this configuration file is including, but not limited to text, this configuration file can be kept at the nonsystematic mounting disc, perhaps obtaining the end of uploading onto the server under the prerequisite that the user allows, can also realize in the situation of losing in order to the user side configuration file above-mentionedly scanning targetedly.
According to embodiments of the invention, and as shown in Figure 1, after step S103, execution in step S105 wherein when the virus of scanning computer under AD HOC, according to the described catalogue that records in described configuration file and/or the information of file, carries out scanning.
Alternatively, described AD HOC can comprise rapid scanning pattern, custom scan pattern.In rapid scanning pattern in the prior art, as mentioned above, general only scan for the catalogue of the easily infected virus with universality and/or file etc., consuming time shorter, but can't come scanning directory and/or file according to the demand of user individual.And according to embodiments of the invention, according to the described catalogue that records in described configuration file and/or the information of file, just can not only scan catalogue and/or the file of the easily infected virus with universality, can also scan the catalogue that does not have universality and/or file that the user need to be scanned, make the sweep limit of rapid scanning pattern have more specific aim, and can not increase too much sweep time.In the custom scan pattern of prior art, all need the user to select voluntarily to carry out the path of virus scan at every turn.And according to embodiments of the invention, in the custom scan pattern, can carry out scanning according to the described catalogue that records in described configuration file and/or the information of file, the catalogue that only records in scan profile and/or file, to realize scanning targetedly, also can also scan simultaneously other self-defining catalogue and/or file, for example operating system catalogue, executable file etc.
According to one embodiment of present invention, step S105 can comprise substep S105a and substep S105b.Wherein, in substep S105a, in the situation that select with AD HOC scanning computer virus, provide the described catalogue that records in the described configuration file of direct scanning and/or the first shortcut of file.Describe particularly for substep S105a below with reference to Fig. 2.
Fig. 2 schematically illustrates the schematic diagram at the interface of scanning computer virus according to an embodiment of the invention.Referring to Fig. 2, in the interface of scanning computer virus, three kinds of scan patterns are provided: scan full hard disk pattern, rapid scanning pattern, custom scan pattern.As mentioned above, according to embodiments of the invention, described AD HOC can comprise rapid scanning pattern, custom scan pattern.In substep S105a, the user can select rapid scanning pattern or custom scan pattern, and wherein, the user can be accomplished in several ways above-mentioned selection.For example, the user can use sensing equipment (for example mouse, trace ball, touch-screen) to click the icon of rapid scanning pattern or custom scan pattern, perhaps by the directionkeys on keyboard with cursor movement to the icon of rapid scanning pattern or custom scan pattern and press enter key; In addition, according to one embodiment of present invention, the user can also use sensing equipment or keyboard with cursor movement to the icon of rapid scanning pattern or custom scan pattern or near icon, at this moment, (for example will show the icon of the first shortcut and/or word on this icon or around icon, " my scanning "), be used for directly scanning described catalogue and/or the file that described configuration file records.When the user for example clicks the icon of this first shortcut and/or word by sensing equipment, can carry out substep S105b, wherein, in response to the selection for described the first shortcut, for described catalogue and/or the virus scan of file object computer.Thereby, can facilitate and carry out quickly computer virus scanning targetedly.
According to another embodiment of the invention, step S105 can comprise substep S105a ' and substep S105b '.In substep S105a ', in the situation that select with AD HOC scanning computer virus, provide one or more second shortcuts of direct scanning particular category and/or file.Alternatively, described particular category and/or the file file, executable file, document files, the web page files that comprise the desktop catalogue, operating system catalogue, file catalogue, download directory, external drive catalogue of computer operating system, receive by Instant Messenger (IM) software and/or Email.Above-mentioned catalogue and file all are subject to computer virus and disturb, and can provide respectively second shortcut for above-mentioned various catalogues and file.The routing information of the file that receives for download directory, by Instant Messenger (IM) software and/or Email can obtain from the configuration file of related software.And for the routing information of external drive catalogue, can obtain by the inquiry of the external drive being initiated by application programming interface (API) function of operating system be connected with computing machine.
Similar with above-mentioned substep S105a, in substep S105a ', the user can select rapid scanning pattern or custom scan pattern, wherein, the user can be accomplished in several ways above-mentioned selection, for example can use sensing equipment to click the icon of rapid scanning pattern or custom scan pattern, perhaps by the directionkeys on keyboard with cursor movement to the icon of rapid scanning pattern or custom scan pattern and press enter key; In addition, according to one embodiment of present invention, the user can also use sensing equipment or keyboard with cursor movement to the icon of rapid scanning pattern or custom scan pattern or near icon, at this moment, icon and/or the word that will show one or more the second shortcuts on this icon or around icon are used for directly scanning above-mentioned particular category and/or the file corresponding with these one or more the second shortcuts.When the user for example clicks the icon of this second shortcut and/or word by sensing equipment, can carry out substep S105b ', in response to the selection for described one or more the second shortcuts, for described particular category and/or the virus scan of file object computer.Like this, just can realize for the convenience of the particular category that is subject to computer virus infection and/or file and scanning efficiently.
In addition, according to embodiments of the invention, can in step S105, above-mentioned substep S105a and S105b have both been carried out, carry out again above-mentioned substep S105a ' and S105b ', scanning when realizing the catalogue that need to scan for the user and/or file and easy infected catalogue and/or file.
According to embodiments of the invention, alternatively, method 100 can also comprise step S107 and S109.In step S107, can inquire about catalogue and/or the file of whether having changed pending computer virus scanning.For example, can with the similar mode of step S101, namely, catalogue and/or listed files can be provided, for example, in Windows operating system, the list (such as tree-shaped list etc.) of computer disk catalogue can be provided in graphic user interface, the user can launch list by using input equipment, find each catalogue and/or file under each disk, and can see and select which catalogue and/or file, and therefrom cancel and select some catalogue and/or file, perhaps increase and select some catalogue and/or file.Afterwards, can execution in step S109, wherein, in the situation that there is above-mentioned change, can utilize catalogue after change and/or the described configuration file of information updating of file.For example, utilize in internal memory catalogue after temporary transient change of preserving and/or the described configuration file of information updating of file.
According to embodiments of the invention, alternatively, method 100 can also comprise step S111 and S113.In step S111, can in the situation that scan computer virus, provide the option of removing for computer virus.For example, in Windows operating system, can provide the list of the file of infected by computer virus in graphic user interface, choose for the user.Afterwards, can execution in step S113, in response to the selection for described option, remove for computer virus.The processing of for example, removing for computer virus for example can comprise following one or more processing: revise the described entry point address that contains virus document; To the described specific region writing data blocks that contains virus document, namely data block is carried out in the specific region and fill; Contain copied chunks in virus document described; Delete the described specific file section that contains virus document, and the described form that contains virus document is adjusted; Delete the described data that contain the specific size of virus document head and/or afterbody; The described size that contains virus document is set.
The invention discloses a kind of method of scanning computer virus.According to embodiments of the invention, can inquire about the catalogue of pending computer virus scanning and/or file and with its information recording/in configuration file, when the virus of scanning computer under AD HOC, just can carry out scanning according to the described catalogue that records in described configuration file and/or the information of file.According to the present invention, the user can select targetedly that the computing machine use habit to this user is relevant, catalogue that do not have universality and/or file carry out computer virus scanning, such scanning is compared with the rapid scanning pattern of prior art, more targeted, can scan catalogue and/or file that the rapid scanning pattern can't scan, that the user preserves according to the computing machine use habit of oneself; And compare with the scan full hard disk pattern of prior art, saved again and scanned unessential, as not to be subject to computer virus infection catalogue and/or a large amount of sweep times of file, greatly improved scan efficiency.Simultaneously, utilize the approach of shortcut, catalogue and/or file and/or the particular category that is subject to computer virus infection and/or the file that can also need to scan for the user carry out computer virus scanning quickly and easily.
Corresponding with said method 100, the present invention also provides a kind of device 200 of scanning computer virus.Fig. 3 schematically illustrates the block diagram of the device 200 of scanning computer virus according to an embodiment of the invention.
As shown in Figure 3, device 200 mainly comprises subscriber interface module 201, information recording/module 203 and computer virus scan module 205.
According to the present invention, subscriber interface module 201 is suitable for inquiring about catalogue and/or the file that user to be inquired expects to carry out computer virus scanning, information recording/module 203 is suitable for information recording/with described catalogue and/or file in configuration file, computer virus scan module 205 is suitable for when the virus of scanning computer under AD HOC, according to the described catalogue that records in described configuration file and/or the information of file, carry out scanning.Above-mentioned subscriber interface module 201, information recording/module 203 and computer virus scan module 205 can be respectively used to carry out step S101, S103 and the S105 in the method 100 of above-mentioned scanning computer virus.
According to embodiments of the invention, subscriber interface module 201 is suitable for providing catalogue and/or listed files, select to expect to select for catalogue and/or the file of pending computer virus scanning with the user, and be suitable for preserving user-selected catalogue and/or the information of file.Wherein subscriber interface module 201 can provide catalogue and/or listed files, to select for catalogue and/or the file of pending computer virus scanning.For example, in Windows operating system, subscriber interface module 201 can provide the list (such as tree-shaped list etc.) of computer disk catalogue in graphic user interface, the user can launch list by using input equipment (for example keyboard, mouse, trace ball, touch-screen etc.), finds each catalogue and/or file under each disk.At this moment, the user just can select (such as by the mode such as choose in list) its required catalogue and/or file that carries out computer virus scanning.Such catalogue and/or file can comprise that the computing machine use habit to this user is relevant, catalogue and/or file that do not have universality.For example, above-mentioned for the described catalogue of method 100 " D :/e-mail attachment ", " E :/software installation file ", " F :/important documents " and web page files etc.Subsequently, subscriber interface module 201 is such as the information such as the path of selected catalogue and/or file and filename temporarily being kept in internal memory.
Afterwards, information recording/module 203 with the information recording/of described catalogue and/or file in configuration file.For example, information recording/module 203 can be with information recording /s such as the above-mentioned path that temporarily is kept at selected catalogue in internal memory and/or file and filenames in configuration file, the type of this configuration file is including, but not limited to text, this configuration file can be kept at the nonsystematic mounting disc, perhaps obtaining the end of uploading onto the server under the prerequisite that the user allows, can also realize in the situation of losing in order to the user side configuration file above-mentionedly scanning targetedly.
Then, when the virus of scanning computer under AD HOC, computer virus scan module 205 is carried out scanning according to the described catalogue that records in described configuration file and/or the information of file.Alternatively, described AD HOC can comprise rapid scanning pattern, custom scan pattern.In rapid scanning pattern in the prior art, as mentioned above, general only scan for the catalogue of the easily infected virus with universality and/or file etc., consuming time shorter, but can't come scanning directory and/or file according to the demand of user individual.And according to embodiments of the invention, according to the described catalogue that records in described configuration file and/or the information of file, just can not only scan catalogue and/or the file of the easily infected virus with universality, can also scan the catalogue that does not have universality and/or file that the user need to be scanned, make the sweep limit of rapid scanning pattern have more specific aim, and can not increase too much sweep time.In the custom scan pattern of prior art, all need the user to select voluntarily to carry out the path of virus scan at every turn.And according to embodiments of the invention, in the custom scan pattern, can carry out scanning according to the described catalogue that records in described configuration file and/or the information of file, the catalogue that only records in scan profile and/or file, to realize scanning targetedly, also can also scan simultaneously other self-defining catalogue and/or file, for example operating system catalogue, executable file etc.
According to one embodiment of present invention, computer virus scan module 205 provides the described catalogue that records in the described configuration file of direct scanning and/or the first shortcut of file in the situation that the user selects with AD HOC scanning computer virus; And in response to the selection of user for described the first shortcut, for described catalogue and/or the virus scan of file object computer.Still referring to Fig. 2, in the interface of scanning computer virus, three kinds of scan patterns are provided: scan full hard disk pattern, rapid scanning pattern, custom scan pattern.The user can select rapid scanning pattern or custom scan pattern, and wherein, the user can be accomplished in several ways above-mentioned selection.For example, the user can use sensing equipment (for example mouse, trace ball, touch-screen) to click the icon of rapid scanning pattern or custom scan pattern, perhaps by the directionkeys on keyboard with cursor movement to the icon of rapid scanning pattern or custom scan pattern and press enter key; In addition, according to one embodiment of present invention, the user can also use sensing equipment or keyboard with cursor movement to the icon of rapid scanning pattern or custom scan pattern or near icon, at this moment, computer virus scan module 205 (for example shows the icon of the first shortcut and/or word on this icon or around icon, " my scanning "), be used for directly scanning described catalogue and/or the file that described configuration file records.When the user for example clicked the icon of this first shortcut and/or word by sensing equipment, computer virus scan module 205 was in response to the selection for described the first shortcut, for described catalogue and/or the virus scan of file object computer.Thereby, can facilitate and carry out quickly computer virus scanning targetedly.
According to another embodiment of the invention, computer virus scan module 205 provides one or more second shortcuts of direct scanning particular category and/or file in the situation that the user selects with AD HOC scanning computer virus; And in response to the selection of user for described one or more the second shortcuts, for described particular category and/or the virus scan of file object computer.In the situation that select with AD HOC scanning computer virus, computer virus scan module 205 provides one or more second shortcuts of direct scanning particular category and/or file.Alternatively, described particular category and/or the file file, executable file, document files, the web page files that comprise the desktop catalogue, operating system catalogue, file catalogue, download directory, external drive catalogue of computer operating system, receive by Instant Messenger (IM) software and/or Email.Above-mentioned catalogue and file all are subject to computer virus and disturb, and can provide respectively second shortcut for above-mentioned various catalogues and file.The routing information of the file that receives for download directory, by Instant Messenger (IM) software and/or Email can obtain from the configuration file of related software.And for the routing information of external drive catalogue, can obtain by the inquiry of the external drive being initiated by application programming interface (API) function of operating system be connected with computing machine.The second shortcut and similar for mode and a upper embodiment that particular category and/or file scan in response to the selection to it is provided in this embodiment, does not repeat them here.In addition, computer virus scan module 205 can be according to these two embodiment, scanning when realizing the catalogue that need to scan for the user and/or file and easy infected catalogue and/or file.
According to embodiments of the invention, described subscriber interface module 201 is suitable for also inquiring that the user inquires about whether has changed catalogue and/or the file of expecting pending computer virus scanning.In addition, described device can also comprise configuration file update module 207, is suitable in the situation that have change, the catalogue after the utilization change and/or the described configuration file of information updating of file.
According to embodiments of the invention, alternatively, described device 200 can also comprise computer virus clean-ing module 209, and it can in the situation that computer virus scan module 205 scans computer virus, provide the option of removing for computer virus.For example, in Windows operating system, computer virus clean-ing module 209 can provide the list of the file of infected by computer virus in graphic user interface, choose for the user.Afterwards, computer virus clean-ing module 209 can in response to the selection for described option, be removed for computer virus.For example, computer virus clean-ing module 209 can be carried out following one or more processing: revise the described entry point address that contains virus document; To the described specific region writing data blocks that contains virus document, namely data block is carried out in the specific region and fill; Contain copied chunks in virus document described; Delete the described specific file section that contains virus document, and the described form that contains virus document is adjusted; Delete the described data that contain the specific size of virus document head and/or afterbody; The described size that contains virus document is set.
Because above-mentioned each apparatus embodiments is corresponding with aforementioned approaches method embodiment, therefore no longer each apparatus embodiments is described in detail.
Intrinsic not relevant to any certain computer, virtual system or miscellaneous equipment with demonstration at this algorithm that provides.Various general-purpose systems also can with based on using together with this teaching.According to top description, it is apparent constructing the desired structure of this type systematic.In addition, the present invention is not also for any certain programmed language.Should be understood that and to utilize various programming languages to realize content of the present invention described here, and the top description that language-specific is done is in order to disclose preferred forms of the present invention.
In the instructions that provides herein, a large amount of details have been described.Yet, can understand, embodiments of the invention can be in the situation that do not have these details to put into practice.In some instances, be not shown specifically known method, structure and technology, so that not fuzzy understanding of this description.
Similarly, be to be understood that, in order to simplify the disclosure and to help to understand one or more in each inventive aspect, in the description to exemplary embodiment of the present invention, each feature of the present invention is grouped together in single embodiment, figure or the description to it sometimes in the above.Yet the method for the disclosure should be construed to the following intention of reflection: namely the present invention for required protection requires the more feature of feature clearly put down in writing than institute in each claim.Or rather, as following claims reflected, inventive aspect was to be less than all features of the disclosed single embodiment in front.Therefore, follow claims of embodiment and incorporate clearly thus this embodiment into, wherein each claim itself is as independent embodiment of the present invention.
Those skilled in the art are appreciated that and can adaptively change and they are arranged in one or more devices different from this embodiment the module in the device in embodiment.Can become the some module combinations in embodiment a module or unit or assembly, and can put them into a plurality of submodules or subelement or sub-component in addition.At least some in such feature and/or process or module are mutually repelling, and can adopt any combination to disclosed all features in this instructions (comprising claim, summary and the accompanying drawing followed) and so all processes or the unit of disclosed any method or equipment make up.Unless clearly statement in addition, in this instructions (comprising claim, summary and the accompanying drawing followed), disclosed each feature can be by providing identical, being equal to or similar purpose alternative features replaces.
In addition, those skilled in the art can understand, although embodiment more described herein comprise some feature rather than further feature included in other embodiment, the combination of the feature of different embodiment mean be in scope of the present invention within and form different embodiment.For example, in claims, the one of any of embodiment required for protection can be used with array mode arbitrarily.
Each device embodiment of the present invention can realize with hardware, perhaps realizes with the software module of moving on one or more processor, and perhaps the combination with them realizes.It will be understood by those of skill in the art that and to use in practice microprocessor or digital signal processor (DSP) to realize according to some or all some or repertoire of modules in the device of the embodiment of the present invention.The present invention can also be embodied as be used to part or all the device program (for example, computer program and computer program) of carrying out method as described herein.The program of the present invention that realizes like this can be stored on computer-readable medium, perhaps can have the form of one or more signal.Such signal can be downloaded from internet website and obtain, and perhaps provides on carrier signal, perhaps provides with any other form.
It should be noted above-described embodiment the present invention will be described rather than limit the invention, and those skilled in the art can design alternative embodiment in the situation that do not break away from the scope of claims.In the claims, any reference symbol between bracket should be configured to limitations on claims.Word " comprises " not to be got rid of existence and is not listed in element or step in claim.Being positioned at word " " before element or " one " does not get rid of and has a plurality of such elements.The present invention can realize by means of the hardware that includes some different elements and by means of the computing machine of suitably programming.In having enumerated the unit claim of some devices, several in these devices can be to come imbody by same hardware branch.The use of word first, second and C grade does not represent any order.Can be title with these word explanations.

Claims (16)

1. the method for a scanning computer virus (100) comprises step:
Inquire about catalogue and/or the file (S101) of pending computer virus scanning;
Information recording/(S103) in configuration file with described catalogue and/or file; And
When the virus of scanning computer under AD HOC, according to the described catalogue that records in described configuration file and/or the information of file, carry out scanning (S105).
2. the method for claim 1 also comprises:
Whether inquiry has changed catalogue and/or the file (S107) of pending computer virus scanning;
In the situation that have change, the catalogue after the utilization change and/or the described configuration file of information updating (S109) of file.
3. the method for claim 1, wherein inquire about the catalogue of pending computer virus scanning and/or the step (S101) of file and comprise:
Provide catalogue and/or listed files, to select (S101a) for catalogue and/or the file of pending computer virus scanning; And
Preserve the information (S101b) of selected catalogue and/or file.
4. method as described in any one in claims 1 to 3, wherein when the virus of scanning computer under AD HOC, the step (S105) of the information and executing scanning of the described catalogue that records according to described configuration file and/or file comprises:
In the situation that select with AD HOC scanning computer virus, provide the described catalogue that records in the described configuration file of direct scanning and/or first shortcut (S105a) of file;
In response to the selection for described the first shortcut, for described catalogue and/or file object computer virus scan (S105b).
5. method as claimed in claim 4, wherein when the virus of scanning computer under AD HOC, the step (S105) of the information and executing scanning of the described catalogue that records according to described configuration file and/or file also comprises:
In the situation that select with AD HOC scanning computer virus, provide one or more second shortcuts (S105a ') of direct scanning particular category and/or file;
In response to the selection for described one or more the second shortcuts, for described particular category and/or the virus scan of file object computer (S105b ').
6. file, executable file, document files, web page files that method as claimed in claim 5, wherein said particular category and/or file comprise the desktop catalogue, operating system catalogue, file catalogue, download directory, external drive catalogue of computer operating system, receive by Instant Messenger (IM) software and/or Email.
7. method as described in any one in claims 1 to 3, wherein said AD HOC comprises rapid scanning pattern, custom scan pattern.
8. method as described in any one in claims 1 to 3 also comprises:
In the situation that scan computer virus, provide the option of removing for computer virus (S111); And
In response to the selection for described option, remove (S113) for computer virus.
9. the device of a scanning computer virus (200) comprising:
Interface module (201) is suitable for inquiring about catalogue and/or the file that pending computer virus scans;
Information recording/module (203) is suitable for information recording/with described catalogue and/or file in configuration file; And
Computer virus scan module (205) is suitable for according to the described catalogue that records in described configuration file and/or the information of file, carrying out scanning when the virus of scanning computer under AD HOC.
10. device as claimed in claim 9, wherein said interface module (201) also are suitable for inquiring about catalogue and/or the file of whether having changed pending computer virus scanning, and described device also comprises:
Configuration file update module (207) is suitable in the situation that have change, the catalogue after the utilization change and/or the described configuration file of information updating of file.
11. device as claimed in claim 9, wherein interface module (201) is suitable for providing catalogue and/or listed files, to select for catalogue and/or the file of pending computer virus scanning; And be suitable for preserving the information of selected catalogue and/or file.
12. device as described in any one in claim 9 to 11, wherein computer virus scan module (205) is suitable in the situation that select with AD HOC scanning computer virus, and the described catalogue that records in the described configuration file of direct scanning and/or the first shortcut of file are provided; And be suitable in response to the selection for described the first shortcut, for described catalogue and/or the virus scan of file object computer.
13. device as claimed in claim 12, wherein computer virus scan module (205) also is suitable for providing one or more second shortcuts of direct scanning particular category and/or file in the situation that select with AD HOC scanning computer virus; And be suitable in response to the selection for described one or more the second shortcuts, for described particular category and/or the virus scan of file object computer.
14. file, executable file, document files, web page files that device as claimed in claim 13, wherein said particular category and/or file comprise the desktop catalogue, operating system catalogue, file catalogue, download directory, external drive catalogue of computer operating system, receive by Instant Messenger (IM) software and/or Email.
15. device as described in any one in claim 9 to 11, wherein said AD HOC comprise rapid scanning pattern, custom scan pattern.
16. device as described in any one in claim 9 to 11 also comprises:
Computer virus clean-ing module (209), be suitable in the situation that computer virus scan module (205) scans computer virus, the option of removing for computer virus is provided, and in response to the selection for described option, removes for computer virus.
CN201310027579.6A 2013-01-24 2013-01-24 The method and apparatus of scanning computer virus Active CN103123675B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201310027579.6A CN103123675B (en) 2013-01-24 2013-01-24 The method and apparatus of scanning computer virus

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201310027579.6A CN103123675B (en) 2013-01-24 2013-01-24 The method and apparatus of scanning computer virus

Publications (2)

Publication Number Publication Date
CN103123675A true CN103123675A (en) 2013-05-29
CN103123675B CN103123675B (en) 2016-01-13

Family

ID=48454650

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201310027579.6A Active CN103123675B (en) 2013-01-24 2013-01-24 The method and apparatus of scanning computer virus

Country Status (1)

Country Link
CN (1) CN103123675B (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103905421A (en) * 2013-12-17 2014-07-02 哈尔滨安天科技股份有限公司 Suspicious event detection method and system based on URL heterogeneity
CN109145602A (en) * 2018-07-06 2019-01-04 成都亚信网络安全产业技术研究院有限公司 A kind of means of defence and device for extorting software attacks
CN109274580A (en) * 2018-09-15 2019-01-25 江苏博智软件科技股份有限公司 A kind of local mail deep analysis technology
CN110941478A (en) * 2018-09-21 2020-03-31 北京奇虎科技有限公司 File scanning task execution method and device and computing equipment

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101127061A (en) * 2006-08-16 2008-02-20 珠海金山软件股份有限公司 Device preventing and treating computer virus capable of pre-estimating schedule and schedule pre-estimation method
CN102073815A (en) * 2010-12-27 2011-05-25 奇瑞汽车股份有限公司 Vehicle-mounted antivirus system and antivirus method
US20110197279A1 (en) * 2009-05-29 2011-08-11 Hitachi, Ltd. Management methods of storage system and file system
CN102867147A (en) * 2012-08-24 2013-01-09 北京奇虎科技有限公司 File scanning method and device

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101127061A (en) * 2006-08-16 2008-02-20 珠海金山软件股份有限公司 Device preventing and treating computer virus capable of pre-estimating schedule and schedule pre-estimation method
US20110197279A1 (en) * 2009-05-29 2011-08-11 Hitachi, Ltd. Management methods of storage system and file system
CN102073815A (en) * 2010-12-27 2011-05-25 奇瑞汽车股份有限公司 Vehicle-mounted antivirus system and antivirus method
CN102867147A (en) * 2012-08-24 2013-01-09 北京奇虎科技有限公司 File scanning method and device

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103905421A (en) * 2013-12-17 2014-07-02 哈尔滨安天科技股份有限公司 Suspicious event detection method and system based on URL heterogeneity
CN109145602A (en) * 2018-07-06 2019-01-04 成都亚信网络安全产业技术研究院有限公司 A kind of means of defence and device for extorting software attacks
CN109145602B (en) * 2018-07-06 2020-06-02 成都亚信网络安全产业技术研究院有限公司 Lesso software attack protection method and device
CN109274580A (en) * 2018-09-15 2019-01-25 江苏博智软件科技股份有限公司 A kind of local mail deep analysis technology
CN110941478A (en) * 2018-09-21 2020-03-31 北京奇虎科技有限公司 File scanning task execution method and device and computing equipment
CN110941478B (en) * 2018-09-21 2024-03-01 北京奇虎科技有限公司 Execution method and device of file scanning task and computing equipment

Also Published As

Publication number Publication date
CN103123675B (en) 2016-01-13

Similar Documents

Publication Publication Date Title
EP3316166B1 (en) File-modifying malware detection
CN102662741B (en) Method, device and system for realizing virtual desktop
JP6644001B2 (en) Virus processing method, apparatus, system, device, and computer storage medium
EP2831798B1 (en) Systems and methods for using property tables to perform non-iterative malware scans
EP3756121B1 (en) Anti-ransomware systems and methods using a sinkhole at an electronic device
KR101260028B1 (en) Automatic management system for group and mutant information of malicious code
CN102867147B (en) A kind of method and apparatus of file scan
US9087194B2 (en) Providing information to a security application
US11120147B2 (en) Operating system garbage-collection with integrated clearing of sensitive data
US9898603B2 (en) Offline extraction of configuration data
CN103473501A (en) Malware tracking method based on cloud safety
US20100115619A1 (en) Method and system for scanning a computer storage device for malware incorporating predictive prefetching of data
CN103123675B (en) The method and apparatus of scanning computer virus
CN105389509A (en) Document scanning method and apparatus
US10467190B2 (en) Tracking access pattern of inodes and pre-fetching inodes
CN102929733B (en) Method and device for processing error files and client-side equipment
WO2018064319A1 (en) Tracking access pattern of inodes and pre-fetching inodes
CN102929732B (en) Method and device for calling file by application program and client-side equipment
CN102902921A (en) Method and device for detecting and eliminating computer viruses
CN102915359A (en) File management method and device
KR20130002692A (en) Optimization method, optimization server and computer readable recording medium for providing service with vaccine and optimization functions
CN102930209B (en) The document handling method of movable storage device and document handling apparatus
CN112507346A (en) Vulnerability scanning system
CN102306254A (en) Method and system for defending viruses or malicious programs

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
TR01 Transfer of patent right
TR01 Transfer of patent right

Effective date of registration: 20220719

Address after: Room 801, 8th floor, No. 104, floors 1-19, building 2, yard 6, Jiuxianqiao Road, Chaoyang District, Beijing 100015

Patentee after: BEIJING QIHOO TECHNOLOGY Co.,Ltd.

Address before: 100088 room 112, block D, 28 new street, new street, Xicheng District, Beijing (Desheng Park)

Patentee before: BEIJING QIHOO TECHNOLOGY Co.,Ltd.

Patentee before: Qizhi software (Beijing) Co.,Ltd.