F
ForgottenSeer 109138
Hopefully they are not a in your face kinda hacker then and do that while you watch going wth.This cannot be done without informing the user about the AV uninstallation. The AV vendors provided special protection to prevent the malware running with high privileges from tampering with some services and drivers. As it can be seen those protections can be bypassed. In the case of Symantec Endpoint Protection, I invalidated 5 drivers, but the user and AV show only a general error. The user still does not know what happened. Is it a temporary error with services? Is it a conflict with the Windows Update? There is no sign of malicious actions.
Fair point but route of infection still exists, how did the system get compromised. What kind of delivery method would you use to bypass the already in place security. Such as Norton here for example, the endpoint solution, how would you wrap your gift and send it down the pike to send on the machine unnoticed.