64bit anti virus solutions?

Venustus

Level 59
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
Are there any native 64bit anti virus solutions available?
For example kaspersky is a 32bit application compatible in a 64bit environment.

But In the release notes it states some features unavailable under a 64 bit system!
Can someone clarify?
CONTROL APPLICATION ACTIVITY ON THE COMPUTER AND ON THE
NETWORK
Application Control prevents applications from performing actions that may be dangerous for the system and ensures
control of access to operating system resources and your personal data.
Application Control tracks actions performed in the system by applications installed on the computer and regulates them
based on rules. These rules regulate potentially dangerous activity of applications, including applications' access to
protected resources, such as files and folders, registry keys, and network addresses.
When working under 64-bit operating systems, applications' rights to configuration of the following actions are
unavailable:
 Direct access to physical memory
 Printer driver management
 Service creation
 Service reading
 Service editing
 Service reconfiguration
 Service management
 Service start
 Service removal
 Access to internal browser data
 Access to critical system objects
 Access to password storage
 Debugger rights setup
 Use of system interfaces
 Use of system interfaces (DNS).

When working under 64-bit Microsoft Windows 8, applications' rights to configuration of the following actions are also
unavailable:

 Sending of window messages to other processes
 Suspicious operations
 Installation of interceptors
 Interception of inbound stream events
 Making of screenshots.
 
Last edited:

Venustus

Level 59
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
How do you mean native? Majority of anti-virus products are working on 64-bit machines...
I edited my post above.
In the release notes for KIS,some functions are unavailable when using 64bit.
 
D

Deleted member 178

Comodo is native as well as webroot.

In fact any software that has its installation folder in Program File and not Progeram Filex86 (on 64bits windows) is considered as 64 bits native.
 
  • Like
Reactions: Venustus

Venustus

Level 59
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
Comodo is native as well as webroot.

In fact any software that has its installation folder in Program File and not Progeram Filex86 (on 64bits windows) is considered as 64 bits native.
Ok thanks!
I see kaspersky is in Progeram Filex86,and the user manual states the above functions are unavailable when using 64bit.
Does this imply that security wise the program may not perform optimally?
Ps:Just asking out of curiosity:)
 
D

Deleted member 178

in a sens yes, to be very simple , the x64 kernel patch proterction (also known as PatchGuard) forbid the kernel modification so some solutions components mostly HIPS, sandboxes and co are not so effective in a 64 bits system than a 32 bits (developpers need to find a workaround reducing the component effectiveness)

the best example is Defensewall ; an awesome 32bits HIPS/sandbox unavailable in 64bits system due to this Patchguard.
 
Last edited by a moderator:
  • Like
Reactions: Venustus

Venustus

Level 59
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
Thank you for the clarification Umbra!:)
 
D

Deleted member 178

i suggest you to google what is Patchguard , its pros (for us users) and cons (for AV vendors), really interesting
 
  • Like
Reactions: Venustus

Venustus

Level 59
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
i suggest you to google what is Patchguard , its pros (for us users) and cons (for AV vendors), really interesting
Will do!

Cheers

PS:I found this:
Some computer security software, such as McAfee's McAfee VirusScan and Symantec's Norton AntiVirus,

works by patching the kernel[citation needed]. Additionally, anti-virus software authored by Kaspersky Lab

has been known to make extensive use of kernel code patching on x86 editions of Windows.[15] This kind

of antivirus software will not work on computers running x64 editions of Windows because of Kernel

Patch Protection.[16] Because of this, McAfee called for Microsoft to either remove KPP from Windows

entirely or make exceptions for software made by trusted companies such as themselves.[3]

Interestingly, Symantec's corporate antivirus software[17] and Norton 2010 range and beyond [18] does

work on x64 editions of Windows despite KPP's restrictions. Antivirus software made by competitors

ESET,[19] Trend Micro,[20] Grisoft AVG,[21] avast!, Avira Anti-Vir and Sophos do not patch the kernel in

default configurations, but may patch the kernel when features such as "advanced process protection" or

"prevent unauthorized termination of processes" are enabled. Sophos publicly stated that it does not feel

KPP limits the effectiveness of its software.[22][23]
 
  • Like
Reactions: Deleted member 178

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top