Self protection in task manager?

Discussion in 'NOD32 version 2 Forum' started by psych1610, Jul 3, 2007.

Thread Status:
Not open for further replies.
  1. psych1610

    psych1610 Registered Member

    Joined:
    Jun 16, 2007
    Posts:
    62
    Location:
    Redneckville, FL .. originally Newburgh, NY!!!!
    Hi all, I'm running the latest version (or what I hope is the latest version) of NOD32 in the US 2.70.39 as the free trial. So far I love it, it frees up my system resources and appears to protect me fairly well.

    One thing I've discovered is that it doesn't seem to protect itself from getting shut down by malware from the task manager. Near as I can tell both processes nod32kui.exe and nod32krn.exe are both able to be shut down just by going to end process.

    If I can do it so easily, can't some sort of virus or other malware?

    Is there an option I can check to enable it, short of installing a separate program that would do just that? (i'm trying to keep my running processes and CPU usage low)

    I think I will keep nod32 regardless of what the answer is, but I'm thinking that could be an added benefit (as I'm sure someone has mentioned before). I'm using Comodo Firewall and I've noticed that can't be shut down from the task manager, at least not so simply (there might be another way, but as somewhat of a novice I'm clueless).


    Thanks

    psych
     
  2. ASpace

    ASpace Guest

    Hi !

    NOD32 runs as a service (nod32krn.exe) and it cannot be totally stopped . Normally , when you press the "End Process" button , nod32krn.exe immediately regenerates so malware cannot stop it that way .

    NOD32 is known to catch (either by signatures or with its powerful heuristics) all threats that have ever tried to disable it so if you don't turn it off manually you'll be OK .

    Other vendors flaunts with their techniques of self-defence . NOD32 does have self-defence but it is not so special because no matter what kind of "self-protection" a softwate may have , any user that runs as admin or software with admin rights can disable or eliminate the programs . So "self-defence" is more marketing than real feauture , I believe .

    As I said , no known threats that can disable NOD32 and remain live :thumb:
     
  3. psych1610

    psych1610 Registered Member

    Joined:
    Jun 16, 2007
    Posts:
    62
    Location:
    Redneckville, FL .. originally Newburgh, NY!!!!
    Hey, I appreciate the quick response HiTech_boy. That answered my current question and then some.

    Completely separate question, but does anyone know of any places where I can just throw fake viruses or something to see if Nod actually does stop them.. I just always like to be sure. I've already seen eicar but I can't dig up anything else.

    Psych1610
     
  4. cupez80

    cupez80 Registered Member

    Joined:
    Jun 28, 2005
    Posts:
    617
    Location:
    Surabaya Indonesia
  5. De Hollander

    De Hollander Registered Member

    Joined:
    Sep 10, 2005
    Posts:
    718
    Location:
    Windmills and cows
  6. Cpt. Sparrow

    Cpt. Sparrow Registered Member

    Joined:
    May 22, 2006
    Posts:
    37
    Guys, I think he's not looking for an online scanner, but for "demo" malware like the Eicar test.

    Kaspersky has a few samples which include some malware-like beahvoiur at http://tav.kaspersky.fr/.

    They're all detected by IMON using the Nod32 heuristics.
     
  7. ASpace

    ASpace Guest

  8. psych1610

    psych1610 Registered Member

    Joined:
    Jun 16, 2007
    Posts:
    62
    Location:
    Redneckville, FL .. originally Newburgh, NY!!!!
    Cpt. Sparrow, you're exactly right I was looking for "demo" malware like what you mentioned I just couldn't think of the right way to say it. I apologize for the lack of clarity there. Appreciate all the responses.

    psych1610
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.