UAC Bypassable or not?

D

Deleted member 178

since it is a registry key , you just have to restore a backup of an old registry and you are good or you delete the key manually.
 
  • Like
Reactions: Venustus
D

Deleted member 178

what do you mean by "gone"? uninstalled? no more services and folders?
 

nissimezra

Level 25
Verified
Apr 3, 2014
1,460
what do you mean by "gone"? uninstalled? no more services and folders?
In that case zero control on my PC no task manager nothing, the virus took full control on the pc, it run even in safe mode.
the only thing that it didn't delete is sys restore.
so i don't know, there was no icon. it was easy to get rid of it just sys restore from boot cd.

cheers
 

(BlackBox) Hacker

Level 2
Verified
Apr 21, 2014
179
Well you might of lost your data now? But it's very risky using same OS when infected!

In that case zero control on my PC no task manager nothing, the virus took full control on the pc, it run even in safe mode.
the only thing that it didn't delete is sys restore.
so i don't know, there was no icon. it was easy to get rid of it just sys restore from boot cd.

cheers
 

Mateotis

Level 10
Verified
Well-known
Mar 28, 2014
497
The ZeroAccess rootkit was capable of effectively "killing" AVs by infecting their kernel modules when they scan the rootkit thus calling the "ExitProcess" function on them. Once it's gone, it also changes the permissions needed to run the program, so the user becomes unable to even open it again.

Though it wasn't foolproof, for example HitmanPro managed to find and delete it.

Edit: Source: http://www.webroot.com/blog/2011/07/08/zeroaccess-rootkit-guards-itself-with-a-tripwire/
 

(BlackBox) Hacker

Level 2
Verified
Apr 21, 2014
179
You know your stuff, what an expert. Nice to meet you Mateotis! I also agree with you on the Comodo Firewall HIPS, but I also think some Antiviruses still have the power as well say Comodo Antivirus with Windows Firewall Controller!

Some still do, but today it's the firewalls that provide such protection (e.g Comodo).



Yes, I love it too, especially the second. :)
 
  • Like
Reactions: Mateotis

Mateotis

Level 10
Verified
Well-known
Mar 28, 2014
497
I think Avira, AVG, MSE do also lack in security features including Zer0-day attacks!

Every AV is somewhat vulnerable to zero-day malware, it's up to their heuristics to detect them.

And also, that's why we are here, to submit such samples to them. :)
 
  • Like
Reactions: kaddy

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top