IP Library Granted Patent US 7,533,131
Granted Patent B2
US 7,533,131 · App. 10/956,574 · Granted May 12, 2009

System and method for pestware detection and removal

Assignee: Webroot Software, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,533,131
App. No.
10/956,574
Granted
May 12, 2009
Kind
B2
Abstract

Systems and methods for managing pestware are described. One system includes a pestware shield configured to detect pestware activity on a protected computer; a heuristics engine configured to identify repeat pestware activity; a drive scan module configured to scan files stored on the storage device and to identify pestware in the scanned files; a program memory scan module configured to scan programs running in the program memory of the protected computer and to identify pestware in the scanned programs; a registry scan module configured to identify any attempts to change data in the registry file; and a quarantine module configured to quarantine the pestware identified by either the drive scan module or the program memory module.

Claims (49)

1. A method of managing pestware on a protected computer, the method comprising:

receiving a plurality of definitions corresponding to pestware;

scanning the storage systems of the protected computer for files corresponding to any of the plurality of definitions;

responsive to determining that one of the files matches one of the plurality of definitions, preventing the file from operating;

detecting an initial pestware activity on the protected computer based on at least one of comparing data with a predetermined pestware definition and identifying pestware-related behavior on the protected computer;

blocking the initial pestware activity;

detecting a second pestware activity on the protected computer based on at least one of comparing data with a predetermined pestware definition and identifying pestware-related behavior on the protected computer;

determining that the second pestware activity is similar to the initial pestware activity;

responsive to determining that the second pestware activity is similar to the initial pestware activity, sending data about the protected computer and the second pestware activity to a host system;

receiving a new definition from the host system, the new definition corresponding to the second pestware activity and generated using the sent data about the protected computer and the second pestware activity;

scanning the storage systems of the protected computer for files corresponding to the new definition; and

taking corrective action to protect the protected computer from at least one detected file corresponding to the new definition.

2. The method of claim 1 , wherein scanning the storage systems of the protected computer for files corresponding to the new definition comprises:

scanning the program memory of the protected computer.

3. The method of claim 1 , wherein scanning the storage systems of the protected computer for files corresponding to the new definition comprises:

scanning the registry file of the protected computer.

4. The method of claim 1 , wherein the data about the protected computer and the second pestware activity includes information from the registry file of the protected computer.

5. The method of claim 1 , wherein the data about the protected computer and the second pestware activity includes information about the state of the protected computer.

6. The method of claim 1 , wherein the data about the protected computer and the second pestware activity includes configuration data corresponding to the protected computer.

7. A computer system, comprising:

a processor;

one or more storage systems; and

a memory containing a plurality of program instructions configured to cause the processor to:

receive a plurality of definitions corresponding to pestware;

scan the storage systems of the protected computer for files corresponding to any of the plurality of definitions;

prevent a file from operating, responsive to determining that the file matches one of the plurality of definitions;

detect an initial pestware activity on the protected computer based on at least one of comparing data with a predetermined pestware definition and identifying pestware-related behavior on the protected computer;

block the initial pestware activity;

detect a second pestware activity on the protected computer based on at least one of comparing data with a predetermined pestware definition and identifying pestware-related behavior on the protected computer;

determine that the second pestware activity is similar to the initial pestware activity;

send data about the protected computer and the second pestware activity to a host system, responsive to determining that the second pestware activity is similar to the initial pestware activity;

receive a new definition from the host system, the new definition corresponding to the second pestware activity and generated using the sent data about the protected computer and the second pestware activity;

scan the storage systems of the protected computer for files corresponding to the new definition; and

take corrective action to protect the protected computer from at least one detected file corresponding to the new definition.

8. A computer-readable storage medium containing a plurality of program instructions executable by a processor for managing pestware on a protected computer, the plurality of program instructions comprising:

a first instruction segment configured to receive a plurality of definitions corresponding to pestware;

a second instruction segment configured to scan the storage systems of the protected computer for files corresponding to any of the plurality of definitions;

a third instruction segment configured to prevent a file from operating, responsive to determining that the file matches one of the plurality of definitions;

a fourth instruction segment configured to detect an initial pestware activity on the protected computer based on at least one of comparing data with a predetermined pestware definition and identifying pestware-related behavior on the protected computer;

a fifth instruction segment configured to block the initial pestware activity;

a sixth instruction segment configured to detect a second pestware activity on the protected computer based on at least one of comparing data with a predetermined pestware definition and identifying pestware-related behavior on the protected computer;

a seventh instruction segment configured to determine that the second pestware activity is similar to the initial pestware activity;

an eighth instruction segment configured to send data about the protected computer and the second pestware activity to a host system, responsive to determining that the second pestware activity is similar to the initial pestware activity;

a ninth instruction segment configured to receive a new definition from the host system, the new definition corresponding to the second pestware activity and generated using the sent data about the protected computer and the second pestware activity;

a tenth instruction segment configured to scan the storage systems of the protected computer for files corresponding to the new definition; and

an eleventh instruction segment configured to take corrective action to protect the protected computer from at least one detected file corresponding to the new definition.

9. The computer-readable storage medium of claim 8 , wherein the data about the protected computer and the second pestware activity includes information from the registry file of the protected computer.

10. The computer-readable storage medium of claim 8 , wherein the data about the protected computer and the second pestware activity includes information about the state of the protected computer.

11. The computer-readable storage medium of claim 8 , wherein the data about the protected computer and the second pestware activity includes configuration data corresponding to the protected computer.

Assignments (10)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
RELEASE OF SECURITY INTEREST Recorded Mar 22, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: WEBROOT INC.
Reel/Frame 050454/0102 →
SECURITY INTEREST Recorded Jan 6, 2015
From: WEBROOT INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 034742/0085 →
CHANGE OF NAME Recorded Sep 13, 2012
From: WEBROOT SOFTWARE, INC.
To: WEBROOT INC.
Reel/Frame 028953/0917 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDRESS OF THE ASSIGNEE FROM 2650 55TH STREET, SUITE 300, BOULDER, CO 80301 TO 2560 55TH STREET, SUITE 300, BOULDER, CO 80301 PREVIOUSLY RECORDED ON REEL 016076 FRAME 0469. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 26, 2008
From: THOMAS, STEVE; STOWERS, BRADLEY D.; BARTON, KEVIN; HERMAN, JEFFREY
To: WEBROOT SOFTWARE, INC.
Reel/Frame 020706/0179 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2004
From: THOMAS, STEVE; STOWERS, BRADLEY D.; BARTON, KEVIN; HERMAN, JEFFREY
To: WEBROOT SOFTWARE, INC.
Reel/Frame 016076/0469 →
Continuity (1)
Related Publication 20060074896A1 · Apr 6, 2006