Does avast protect against malicious driver installation and win hooks attacks

Status
Not open for further replies.

Prayag

Level 4
Thread author
Verified
Well-known
Mar 27, 2017
160
Does avast protects against malicious driver installations and the attacks that use hooks to infect the system.
Further, how is avast's bb at detecting process hollowing attempts and protecting COM components and important registry keys?
 

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
It is impossible to give definitive answers, it would mean that an AV is always 100% effective.

Advanced malware can install themselves by completely replacing the contents of a random system driver, to get the stealth by creating its own corrupt DEVICE_OBJECT and changing DeviceExtension pointer. In this way, the system, and also antivirus, see the infected driver as it was clean.

Some malware implement self-protection system: if the AV is trying to analyze its features, active in the system, it is immediately terminated, and also the executable file is made inaccessible.
Malicious drivers, in these cases (for example if you open a handle to the process or device used to usermode communication) changes the ACL (Access Control Lists are lists of access of an object that determine who can access the object and what they can do with it) of the executable file of the process in such a way to block access, and finally provides at the end of the current process, an APC routine.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top