IP Library Granted Patent US 8,387,147
Granted Patent B2
US 8,387,147 · App. 13/184,925 · Granted Feb 26, 2013

Method and system for detecting and removing hidden pestware files

Inventor: Patrick Sprowls (Boulder, CO)
Assignee: Webroot Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,387,147
App. No.
13/184,925
Granted
Feb 26, 2013
Kind
B2
Abstract

A method and system for detecting and removing a hidden pestware file is described. One illustrative embodiment detects, using direct drive access, a file on a computer storage device; determines whether the file is also detectable by the operating system by attempting to access the file using a standard file Application-Program-Interface (API) function call of the operating system; identifies the file as a potential hidden pestware file, when the file is undetectable by the operating system; confirms through an automated pestware-signature scan of the potential hidden pestware file that the potential hidden pestware file is a hidden pestware file; and removes automatically, using direct drive access, the hidden pestware file from the storage device.

Claims (26)

1. A method for detecting a potential hidden pestware file on a storage device of a computer, the method comprising:

detecting, using direct drive access, a file on the storage device, the direct drive access bypassing a standard file Application-Program-Interface (API) function call of an operating system of the computer;

determining whether the file is detectable by the operating system by attempting to access the file using the standard file API function call of the operating system, the file being detectable by the operating system when the attempt to access the file using the standard file API function call is successful, the file being undetectable by the operating system when the attempt to access the file using the standard file API function call is unsuccessful;

identifying the file as a potential hidden pestware file, when the file is undetectable by the operating system; and

performing the following when the file has been identified as the potential hidden pestware file:

notifying a user that the file is the potential hidden pestware file;

presenting to the user an option to remove automatically the potential hidden pestware file from the storage device; and

removing, using direct drive access, the potential hidden pestware file from the storage device automatically in response to an input from the user.

2. The method of claim 1 , wherein the method is performed in conjunction with scanning a data-bearing portion of the storage device, the scanning being performed sequentially in sector order using direct drive access.

3. A system for detecting a potential hidden pestware file on a storage device of a computer, the system comprising:

a file-detection module configured to detect, using direct drive access, a file on the storage device, the direct drive access bypassing a standard file Application-Program-Interface (API) function call of an operating system of the computer;

a file-analysis module configured to determine whether the file is detectable by the operating system by attempting to access the file using the standard file API function call of the operating system, the file being detectable by the operating system when the attempt to access the file using the standard file API function call is successful, the file being undetectable by the operating system when the attempt to access the file using the standard file API function call is unsuccessful;

a file-classification module configured to flag the file as the potential hidden pestware file, when the file is undetectable by the operating system;

a notification module configured, when the file has been flagged as the potential hidden pestware file, to:

notify a user that the file has been flagged as the potential hidden pestware file; and

present to the user an option to remove automatically the potential hidden pestware file from the storage device; and

a pestware-removal module configured to remove automatically, using direct drive access, the potential hidden pestware file from the storage device in response to an input from the user.

4. The system of claim 3 , wherein the file-detection module is configured to scan a data-bearing portion of the storage device sequentially in sector order using direct drive access.

5. A non-transitory computer-readable storage medium containing program instructions executable by a processor to detect a potential hidden pestware file on a storage device of a computer, the program instructions comprising:

a first instruction segment configured to detect, using direct drive access, a file on the storage device, the direct drive access bypassing a standard file Application-Program-Interface (API) function call of an operating system of the computer;

a second instruction segment configured to determine whether the file is detectable by the operating system by attempting to access the file using the standard file API function call of the operating system, the file being detectable by the operating system when the attempt to access the file using the standard file API function call is successful, the file being undetectable by the operating system when the attempt to access the file using the standard file API function call is unsuccessful;

a third instruction segment configured to flag the file as the potential hidden pestware file, when the file is undetectable by the operating system;

a fourth instruction segment configured, when the file has been flagged as the potential hidden pestware file, to:

notify a user that the file has been flagged as the potential hidden pestware file; and

present to the user an option to remove automatically the potential hidden pestware file from the storage device; and

a fifth instruction segment configured to remove automatically, using direct drive access, the hidden pestware file from the storage device in response to an input from the user.

Assignments (9)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
RELEASE OF SECURITY INTEREST Recorded Mar 22, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: WEBROOT INC.
Reel/Frame 050454/0102 →
SECURITY INTEREST Recorded Jan 6, 2015
From: WEBROOT INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 034742/0085 →
CHANGE OF NAME Recorded Aug 24, 2012
From: WEBROOT SOFTWARE, INC.
To: WEBROOT INC.
Reel/Frame 028844/0138 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2011
From: SPROWLS, PATRICK
To: WEBROOT SOFTWARE, INC.
Reel/Frame 026723/0163 →
Continuity (2)
Division 11482903 · Jul 7, 2006
Related Publication 20110289587A1 · Nov 24, 2011