View Full Version : Stopping virii from shutting down AV
cfp999
August 3rd, 2002, 07:03 AM
A couple of months ago I was hit by the "Klez" virus because a family member opened an attachement in Outlook. I had F-Prot 3.12 running, but "Klez" simply shut it down, and ruined the executable. Which antivirus programs can handle attempts by virii to shut them down ('cause F-Prot certainly cannot)? I mean, they are not to much use if that can happen. Furthermore, is it possible to use Windows 2000 permissions to protect Antivirus applications? Suggestions are welcome.
wizard
August 3rd, 2002, 07:36 AM
Theorectically there is no way to protect AV (or AT software) against attacks from running malware. The princip is simple: what runs first, strikes first.
wizard
DrSeltsam
August 3rd, 2002, 07:40 AM
There is a way ;o). ANTS 3.0 can block process manipulations ;o).
Paul Wilders
August 3rd, 2002, 07:59 AM
-{ Quote: " quoting: Andreas Haak link=board=24;threadid=2793;start=0#18870 date=1028374829]
There is a way ;o). ANTS 3.0 can block process manipulations ;o).
" }-
Andreas, correction: there will be a way - as soon as ANTS v3.0 is out of RC1 and ready for use 8)
regards.
paul
cfp999
August 3rd, 2002, 09:08 AM
I think there's an option to password protect processes in AVP as well but I kind of hate the newer versions so I haven't tried it. What is ANTS 3.0 ??
Paul Wilders
August 3rd, 2002, 09:37 AM
Hi cpf999,
-{ Quote: "I think there's an option to password protect processes in AVP as well" }-
Most good AVs do have this option implemented nowadays. I would not rely on these blindly, though.
-{ Quote: "What is ANTS 3.0 ??" }-
Have a look over on the "other anti-trojan software" forum. You'll find the info needed over there.
regards.
paul
cfp999
August 3rd, 2002, 09:56 AM
Thanks!
Paul Wilders
August 3rd, 2002, 09:57 AM
My pleasure ;)
regards.
paul
DrSeltsam
August 3rd, 2002, 10:08 AM
>Andreas, correction: there will be a way - as soon as ANTS v3.0 is out of RC1 and
>ready for use 8)
The current beta is able to block process manipulations, too ;o).
Paul Wilders
August 3rd, 2002, 10:29 AM
-{ Quote: "The current beta is able to block process manipulations, too" }-
Good to hear so. Nevertheless, a fully tested RC1, followed by the Official release, will prevent "common users" from using an app that's not completely "ironed-out" as far as possibly bugs and incompabilities is concerned. There are Beta's and RC's for good reasons, don't you agree? ;)
regards.
paul
DrSeltsam
August 3rd, 2002, 10:30 AM
of cause i agree.
Paul Wilders
August 3rd, 2002, 10:33 AM
-{ Quote: " quoting: Andreas Haak link=board=24;threadid=2793;start=0#18889 date=1028385040]
of cause i agree.
" }-
Seems we have an understanding; I do agree with your statement above as well ;D ;D
regards.
paul
spy1
August 3rd, 2002, 10:38 AM
;D How many does it take to make a quorum again? Pete
controler
August 3rd, 2002, 10:46 AM
Spy 1 did you get your copy of ANTS 3.0 RC1 yet?
I tried the scan engine and then never saw anymore updates to it. All I got it the scan engine , not a full RC1.
When running the update all I get is the same Sig file.
spy1
August 3rd, 2002, 10:52 AM
Hey, controler! Nope, not yet! Pete
Technodrome
August 3rd, 2002, 11:36 AM
Sophos AV is almost impossible to shut down from memory process. Virii (if trying from MP)won't be able to shut it down unless sophos directory is completely deleted!
Technodrome
DrSeltsam
August 3rd, 2002, 01:19 PM
put the thread into debug mode and terminate it - where is the problem? *fg*
root
August 3rd, 2002, 08:08 PM
RegRun is a nice little program that will keep processes from being terminated, or at least warn you if it is. ;)
DrSeltsam
August 4th, 2002, 10:52 AM
does it prevent the termination or does it only warn and restart the process?
root
August 4th, 2002, 05:48 PM
Hi Andreas. You know, I really haven't dug into that yet. I have several files that are watched, but have never had any of them messed with.
I do know that with watchdog enabled, whenever certain changes are made to the registry, I get a popup notifying me and asking if I want to keep the change.
Regrun has a forum at Beckys.
DrSeltsam
August 4th, 2002, 06:15 PM
ok - but warns it if your kav was kicked out of your memory? ;o) ANTS 3.0 does it - and it doesn't only warn, it PREVENTS it. Only if you say, yes, its ok if this process will be modified/terminated you can get access ;o).
Gavin - DiamondCS
August 6th, 2002, 03:49 AM
TDS4 products will include process protection
For now, JUST RENAME all your AV products' EXE files and their reg keys and you wont have a problem :)
DrSeltsam
August 6th, 2002, 08:02 AM
No - thats partly wrong. Do you know Next Generation Killer? If not i will send you. It detects the process using class and window names :-). It won't help if you simply "rename" the file.
vBulletin® Copyright ©2000-2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums