IP Library Granted Patent US 7,971,249
Granted Patent B2
US 7,971,249 · App. 12/559,434 · Granted Jun 28, 2011

System and method for scanning memory for pestware offset signatures

Assignee: Webroot Software, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,971,249
App. No.
12/559,434
Granted
Jun 28, 2011
Kind
B2
Abstract

Systems and methods for managing pestware processes on a protected computer are described. In one implementation, a reference point in the executable memory that is associated with a process running in the executable memory is located. A first and second sets of information from corresponding first and second portions of the executable memory are then retrieved. The first and second portions of the executable memory are separated by a defined offset, and each of the first and second portions of the executable memory are offset from the reference point. The process is identifiable as a particular type of pestware when the first and second sets of information each include information previously found to be separated by the defined offset in other processes that are of the particular type of pestware. In some variations, the reference point is a starting address and/or an API implementation in the process.

Claims (45)

1. A method for scanning executable memory of a protected system for pestware comprising:

locating a reference point in the executable memory that is associated with a process being executed by a computer via the executable memory;

retrieving a first set of information from a first portion of the executable memory and a second set of information from a second portion of the executable memory, wherein the first and second portions of the executable memory are separated by a defined offset based on a predetermined type of pestware, and wherein each of the first and second portions of the executable memory are offset from the reference point; and

identifying the process as the predetermined type of pestware when the first and second sets of information each include information previously found to be separated by the defined offset in other processes that are specific to the predetermined type of pestware wherein the second set of information is derived from the first set of information upon execution of the first set of information in the executable memory.

2. The method of claim 1 , wherein the locating the reference point includes locating a starting address of the process.

3. The method of claim 1 , wherein the locating the reference point includes locating an API implementation in the process.

4. The method of claim 1 , wherein the retrieving includes retrieving op code from the first and second portions of the executable memory.

5. The method according to claim 1 , wherein

the defined offset is based on the predetermined type of pestware, and

the process is identified as the predetermined type of pestware when the first and second sets of information each include information previously found to be separated by the defined offset in other processes that are specific to the predetermined type of pestware.

6. The method according to claim 1 , further comprising:

analyzing the first set of information;

identifying the first set of information as being associated with the predetermined type of pestware; and

selecting the defined offset based on the analyzed first set of information.

7. A system for managing pestware comprising:

a protected computer;

a pestware removal module configured to remove pestware on the protected computer, the protected computer including at least one file storage device and an executable memory; and

a pestware detection module configured to:

locate a reference point in the executable memory that is associated with a process being executed by the protected computer via the executable memory;

retrieve a first set of information from a first portion of the executable memory and a second set of information from a second portion of the executable memory, wherein the first and second portions of the executable memory are separated by a defined offset based on a predetermined type of pestware, and wherein each of the first and second portions of the executable memory are offset from the reference point; and

identify the process as the predetermined type of pestware when the first and second sets of information each include information previously found to be separated by the defined offset in other processes that are specific to the predetermined type of pestware, wherein the second set of information is derived from the first set of information upon execution of the first set of information in the executable memory.

8. The system of claim 7 , wherein the pestware detection module is configured to locate a starting address as the reference point.

9. The system of claim 7 , wherein the pestware detection module is configured to locate an API implementation as the reference point.

10. The system of claim 7 , wherein the pestware detection module is configured to retrieve op code from the first and second portions of the executable memory.

11. The system according to claim 7 , wherein

the defined offset is based on the predetermined type of pestware, and

the process is identified as the predetermined type of pestware when the first and second sets of information each include information previously found to be separated by the defined offset in other processes that are specific to the predetermined type of pestware.

12. The system according to claim 7 , wherein the pestware detection module is further configured to:

analyze the first set of information;

identify the first set of information as being associated with the predetermined type of pestware; and

select the defined offset based on the analyzed first set of information.

13. A non-transitory computer readable storage medium storing instructions for scanning executable memory on a protected computer for pestware, the instructions including instructions for:

locating a reference point in the executable memory that is associated with a process being executed by the protected computer via the executable memory;

retrieving a first set of information from a first portion of the executable memory and a second set of information from a second portion of the executable memory, wherein the first and second portions of the executable memory are separated by a defined offset based on a predetermined type of pestware, and wherein each of the first and second portions of the executable memory are offset from the reference point; and

identifying the process as the predetermined type of pestware when the first and second sets of information each include information previously found to be separated by the defined offset in other processes that are specific to the predetermined type of pestware wherein the second set of information is derived from the first set of information upon execution of the first set of information in the executable memory.

14. The non-transitory computer readable medium of claim 13 , wherein the instructions for locating the reference point include instructions for locating a starting address of the process.

15. The non-transitory computer readable medium of claim 13 , wherein the instructions for locating the reference point include instructions for locating an API implementation in the process.

16. The non-transitory computer readable medium of claim 13 , wherein the instructions for retrieving include instructions for retrieving op code from the first and second portions of the executable memory.

17. The non-transitory computer readable storage medium according to claim 13 , wherein

the defined offset is based on the predetermined type of pestware, and

the process is identified as the predetermined type of pestware when the first and second sets of information each include information previously found to be separated by the defined offset in other processes that are specific to the predetermined type of pestware.

18. The non-transitory computer readable storage medium according to claim 13 , wherein the instructions further include instructions for:

analyzing the first set of information;

identifying the first set of information as being associated with the predetermined type of pestware; and

selecting the defined offset based on the analyzed first set of information.

Assignments (9)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS RECORDED AT R/F 048723/0612 Recorded Dec 26, 2019
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: WEBROOT INC.
Reel/Frame 051418/0714 →
SECURITY INTEREST Recorded Mar 28, 2019
From: WEBROOT INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 048723/0612 →
RELEASE OF SECURITY INTEREST Recorded Mar 22, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: WEBROOT INC.
Reel/Frame 050454/0102 →
SECURITY INTEREST Recorded Jan 6, 2015
From: WEBROOT INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 034742/0085 →
CHANGE OF NAME Recorded Jan 30, 2013
From: WEBROOT SOFTWARE, INC.
To: WEBROOT INC.
Reel/Frame 029725/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2009
From: HORNE, JEFFERSON DELK
To: WEBROOT SOFTWARE, INC.
Reel/Frame 023232/0469 →
Continuity (2)
Continuation 11105977 · Apr 14, 2005
Related Publication 20100005530A1 · Jan 7, 2010