IP Library Granted Patent US 8,635,438
Granted Patent B2
US 8,635,438 · App. 13/413,391 · Granted Jan 21, 2014

Method and system of file manipulation during early boot time by accessing user-level data associated with a kernel-level function

Inventor: Min Wang (Broomfield, CO)
Assignee: Webroot Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,635,438
App. No.
13/413,391
Granted
Jan 21, 2014
Kind
B2
Abstract

A system and method that enables access to user-level data during a boot-time of a computer is described. One embodiment includes memory containing program instructions configured to cause a processor of computer system to access user-level data associated with a kernel-level function using a portable executable (PE) file. The memory includes program instructions configured to cause a processor to access the user-level data during a boot-time of a computer. In this embodiment, the memory also includes program instructions configured to cause the processor to access the PE file.

Claims (33)

1. A non-transitory computer-readable storage medium containing program instructions executable by at least one processor, the programming instructions comprising:

a first instruction set configured to cause the at least one processor to access, during a boot-time of a computer, user-level data associated with a kernel-level function using a portable executable (PE) file; and

a second instruction set configured to cause the at least one processor to access the PE file using the computer.

2. The non-transitory computer-readable storage medium of claim 1 , wherein the user-level data is associated with at least a portion of an index.

3. The non-transitory computer-readable storage medium of claim 2 , wherein the first instruction set is further configured to cause the at least one processor access an address and wherein the kernel-level function is an application program interface (API).

4. The non-transitory computer-readable storage medium of claim 1 , wherein the boot-time is an early boot-time.

5. The non-transitory computer-readable storage medium of claim 1 , wherein the PE file is loaded into a memory during the boot-time as a boot-file.

6. The non-transitory computer-readable storage medium of claim 1 , wherein:

the PE file is a first PE file; and

the first instruction set is further configured to cause the at least one processor to access from a second PE file using the first PE file.

7. The non-transitory computer-readable storage medium of claim 1 , wherein the PE file is a first PE file, and a second PE file that is loaded during the boot-time is linked to the first PE file.

8. The non-transitory computer-readable storage medium of claim 1 , wherein the PE file is a first PE file configured to patch a second PE file.

9. The non-transitory computer-readable storage medium of claim 1 , wherein the program instructions further comprise:

a third instruction set configured to cause the at least one processor to modify a boot-loader registry during an installation period to include a reference to the PE file, wherein the reference is used by an operating system (OS) during the boot-time to image the PE file into a memory.

10. The non-transitory computer-readable storage medium of claim 1 , wherein the PE file is a first PE file loaded into a memory during the boot-time, the first PE file is loaded before a second PE file containing the user-level data is loaded into the memory during the boot-time.

11. The non-transitory computer-readable storage medium of claim 1 , wherein the PE file is loaded into a memory during the boot-time at a first time and the PE file includes an instruction that prevents an operating system fault at a second time, wherein the second time is after the first time.

12. The non-transitory computer-readable storage medium of claim 1 , wherein the PE file is configured to write data associated with at least a portion of the user-level data to a location that can be accessed by a pestware monitor.

13. The non-transitory computer-readable storage medium of claim 1 , wherein the PE file is at least one of an index-containing PE file or a dummy driver.

14. The non-transitory computer-readable storage medium of claim 1 , wherein the PE file is at least one of an NTDLL.DLL file or a dummy kernel-mode DLL file.

15. A computing system, comprising:

at least one processor;

a memory containing a plurality of program instructions configured to cause the at least one processor to:

access, during a boot-time of the computing system, user-level data associated with a kernel-level function using a portable executable (PE) file; and

access the PE file.

16. The computing system of claim 15 , wherein the user-level data is associated with at least a portion of an index.

17. The computing system of claim 16 , wherein the memory containing the plurality of program instructions is further configured to cause the at least one processor to access an address and wherein the kernel-level function is an application program interface (API).

18. The system of claim 15 , wherein the boot-time is an early boot-time.

19. The system of claim 15 , wherein the PE file is loaded into a memory during the boot-time as a boot-file.

20. The system of claim 15 , wherein the memory containing the plurality of program instructions is further configured to cause the at least one processor to:

modify a boot-loader registry during an installation period to include a reference to the PE file, wherein the reference is used by an operating system (OS) during the boot-time to image the PE file into a memory.

21. The system of claim 15 , wherein the PE file is configured to write data associated with at least a portion of the user-level data to a location that can be accessed by a pestware monitor.

22. The system of claim 15 , wherein the PE file is at least one of an index-containing PE file or a dummy driver.

23. The system of claim 15 , wherein the PE file is at least one of an NTDLL.DLL file or a dummy kernel-mode DLL file.

Assignments (9)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
RELEASE OF SECURITY INTEREST Recorded Mar 22, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: WEBROOT INC.
Reel/Frame 050454/0102 →
SECURITY INTEREST Recorded Jan 6, 2015
From: WEBROOT INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 034742/0085 →
CHANGE OF NAME Recorded Feb 6, 2013
From: WEBROOT SOFTWARE, INC.
To: WEBROOT INC.
Reel/Frame 029768/0860 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2012
From: WANG, MIN
To: WEBROOT SOFTWARE, INC.
Reel/Frame 027815/0352 →
Continuity (3)
Continuation 12830021 · Jul 2, 2010
Division 11465680 · Aug 18, 2006
Related Publication 20120166782A1 · Jun 28, 2012