Invention Grant
- Patent Title: System and method for bypassing a malware infected driver
-
Application No.: US14331920Application Date: 2014-07-15
-
Publication No.: US10339313B2Publication Date: 2019-07-02
- Inventor: Marco Giuliani , Andrea Allievi
- Applicant: Webroot Inc.
- Applicant Address: US CO Broomfield
- Assignee: WEBROOT INC.
- Current Assignee: WEBROOT INC.
- Current Assignee Address: US CO Broomfield
- Agency: Merchant & Gould P.C.
- Main IPC: G06F21/56
- IPC: G06F21/56 ; H04L29/06

Abstract:
Aspects of the present disclosure relate to setting up an alternate communication path to a device, resource, file, etc., in order to avoid a potentially infected driver. New drivers may be established as part of the alternate communications path, thereby providing access to a device, resource, etc. using drivers that are known to be clean or, in other words, not infected by a rootkit. In doing so, a rootkit hunter, e.g., antivirus software, antimalware software, etc., may access an infected device, resource, etc. without alerting a rootkit, thereby avoiding activation of the rootkit's defensive mechanisms. In one aspect, an I/O request may be serviced by using the new communications path bypassing any potentially infected drivers while another request may be serviced using a previously established communications path. The responses (e.g., data returned, action performed, etc.) of the requests may then be compared.
Public/Granted literature
- US20150020202A1 SYSTEM AND METHOD FOR BYPASSING A MALWARE INFECTED DRIVER Public/Granted day:2015-01-15
Information query