LWN.net Logo

Security quotes of the week

Security quotes of the week

Posted Jun 5, 2012 22:32 UTC (Tue) by Cyberax (✭ supporter ✭, #52523)
In reply to: Security quotes of the week by hummassa
Parent article: Security quotes of the week

Try it. Really, go on and try it with Kaspersky antivirus. Nothing will happen - you won't be able to kill antivirus' process. It's protected on the kernel mode level.

It also sets a lot of hooks and tries to monitor self-integrity, so even if you try to kill it by patching kernel process table or in any other obvious way - you'll simply trigger these hooks and either initiate a self-healing attempt or create a BSOD. It's possible to work around them, of course, but decidedly non-trivial. Even Flame malware doesn't try to do it - it simply stays under the radar.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds