Advice Request Must have features in your Antivirus

Please provide comments and solutions that are helpful to the author of this topic.

tim one

Level 21
Verified
Honorary Member
Top Poster
Malware Hunter
Jul 31, 2014
1,086
Let's say that I am quite surprised that in 2018 still there are AVs that don't detect DLL injection on Windows 64bit using well documented APIs.

We know that MS in the last years, starting from Windows Vista, has developed a system protection at kernel level, which provides, to the running processes an integrity level (WIC).
The primary goal of WIC is to ensure that only objects with an integrity level equal or greater than the target object can interact with it.
Even when a process has administrative privileges, if this has a lower WIC level of the process target, it can't interact because the permissions of the NTFS files are ignored and are considered the ones of WIC.

But many malware use the injection technique by using an injector which has a level of execution equal or greater than the target process.
Simply they use some APIs to execute code in the context of another process. This code will modify, into the same process in which it is injected, the structure of some portions of memory by installing, for example, a monitor that intercepts the call to some APIs (hooking).
Thus, it is possible to intercept a series of activities. (for example network activity, disk activity, activity with peripheral devices, data used etc....). This depends on what the malware wants to monitor.
 
Last edited:

Dhruv2193

Level 10
Verified
Well-known
Nov 7, 2016
468
1) Good detection rates(both signatures and behavior blocker)
2) Easy to navigate the program and clean interface
3) Good Support
4) Respects Privacy
 
Last edited:

uninfected1

Level 11
Verified
Top Poster
Well-known
Jan 28, 2016
525
Just would like to mention sandboxing components and a clean uninstall feature that won`t totally screw-up your machine would be appreciated.

Regards Eck:)
Totally agree with your second point but for some strange reason this doesn't seem to bother Comodo fans (and yes, I learnt the hard way - never again!).
 
  • Like
Reactions: Behold Eck

Behold Eck

Level 15
Verified
Top Poster
Well-known
Jun 22, 2014
724
Totally agree with your second point but for some strange reason this doesn't seem to bother Comodo fans (and yes, I learnt the hard way - never again!).

Actually it was Comodo that I had in mind. Maybe the fans have yet to try and uninstall it ?

To be fair it`s only happened once or twice over the years but as you mentioned that was enough.(y)

Regards Eck:)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top