Changing the system date kills KAV dead

Discussion in 'other anti-virus software' started by solcroft, Mar 4, 2007.

Thread Status:
Not open for further replies.
  1. EASTER.2010

    EASTER.2010 Guest

    Yeah at that moment it was like being back at school again at lunchtime and your lunchbox turns up missing.

    I can imagine though all those unfortunate peeps over the years and especially on 98/Me who had their program collections completely wiped away in an instant of time from some destroyer virus like that. I was luckier in that i kept those samples on that old lappy.
     
  2. Seer

    Seer Registered Member

    Joined:
    Feb 12, 2007
    Posts:
    2,068
    Location:
    Serbia
    :D :D :D (more, please) In fact I had probably similar expression on a similiar occasion a few years ago on a Win98 system. I believe most people here on Wilders have a horror tale or two to tell.
     
  3. Firefighter

    Firefighter Registered Member

    Joined:
    Oct 28, 2002
    Posts:
    1,670
    Location:
    Finland
    It's KAV's HIPS. Sure it needs urgent improvement, because it's prevention rate tested so far was only 99 %/100 %, when the best antivirus competitors are already too close with about 53 % detection by their heuristics. :rolleyes: ;) You can get the test results from here behind the "Comparatives" selection line.

    Best regards,
    Firefighter!
     

    Attached Files:

  4. solcroft

    solcroft Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    1,639
    Wow. That's impressive. I just hope it performs as well when it's rendered inactive by a system date change.
     
  5. TonyW

    TonyW Registered Member

    Joined:
    Oct 12, 2005
    Posts:
    2,741
    Location:
    UK
    Just out of curiousity, who here has had a virus in recent times that has affected the system date?
     
  6. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    I willing to bet that nobody here has had it happen, and it may not be so easy to achieve as is being suggested. If KAV could be knocked out that easily I'm pretty sure something would be done to remedy the situation.

    As for those Reg keys, I only mentioned them 'cos another poster talked of Reg protection, I think it would only be a partial solution at best to add them because it would depend how the attack was implemented. One of the Keys for example determines the server from which you get synchronization of your clock (by default it should be time.windows.com), so if it was changed to a hostile site I'm guessing that it might be possible to set the clock back that way, but I don't know how practical that would be.
     
  7. Seer

    Seer Registered Member

    Joined:
    Feb 12, 2007
    Posts:
    2,068
    Location:
    Serbia
    If you set the clock back that way and render KAV's defenses off as suggested by solcroft that could be very practical indeed.
     
  8. pugmug

    pugmug Registered Member

    Joined:
    Oct 23, 2006
    Posts:
    413
    Damn,even I can read the time and date on a computer,lol.
     
  9. RejZoR

    RejZoR Lurker

    Joined:
    May 31, 2004
    Posts:
    6,426
    Well, directy attacking KAV6 would trigger PDM and Self-Defense, but tricking system date this way is an indirec attack and as such it would go undetected...
     
  10. Seer

    Seer Registered Member

    Joined:
    Feb 12, 2007
    Posts:
    2,068
    Location:
    Serbia
    Hello RejZoR:

    Yes. By KAV's engines. But this thread seems to have point as a good advice on using a decent third party behaviour blocker with KAV in the end.
     
  11. dah145

    dah145 Registered Member

    Joined:
    Jul 3, 2006
    Posts:
    262
    Location:
    n/a
    IMO there is no need for a third party behavior blocker, KAV/KIS has already the best designed one (IMO) and is not at is full potential atm according to KAV devs. :thumb:
     
  12. Seer

    Seer Registered Member

    Joined:
    Feb 12, 2007
    Posts:
    2,068
    Location:
    Serbia
    OK, possibly my bad. As I stated in my post #25, I don't have much interest in KAV/KIS and I can't confirm that, so I respect YO.

    Cheers :thumb:
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.