UAC Bypassable or not?

since it is a registry key , you just have to restore a backup of an old registry and you are good or you delete the key manually.
 
  • Like
Reactions: Venustus
what do you mean by "gone"? uninstalled? no more services and folders?
 
what do you mean by "gone"? uninstalled? no more services and folders?
In that case zero control on my PC no task manager nothing, the virus took full control on the pc, it run even in safe mode.
the only thing that it didn't delete is sys restore.
so i don't know, there was no icon. it was easy to get rid of it just sys restore from boot cd.

cheers
 
Well you might of lost your data now? But it's very risky using same OS when infected!

In that case zero control on my PC no task manager nothing, the virus took full control on the pc, it run even in safe mode.
the only thing that it didn't delete is sys restore.
so i don't know, there was no icon. it was easy to get rid of it just sys restore from boot cd.

cheers
 
The ZeroAccess rootkit was capable of effectively "killing" AVs by infecting their kernel modules when they scan the rootkit thus calling the "ExitProcess" function on them. Once it's gone, it also changes the permissions needed to run the program, so the user becomes unable to even open it again.

Though it wasn't foolproof, for example HitmanPro managed to find and delete it.

Edit: Source: http://www.webroot.com/blog/2011/07/08/zeroaccess-rootkit-guards-itself-with-a-tripwire/
 
You know your stuff, what an expert. Nice to meet you Mateotis! I also agree with you on the Comodo Firewall HIPS, but I also think some Antiviruses still have the power as well say Comodo Antivirus with Windows Firewall Controller!

Some still do, but today it's the firewalls that provide such protection (e.g Comodo).



Yes, I love it too, especially the second. :)
 
  • Like
Reactions: Mateotis
I think Avira, AVG, MSE do also lack in security features including Zer0-day attacks!

Every AV is somewhat vulnerable to zero-day malware, it's up to their heuristics to detect them.

And also, that's why we are here, to submit such samples to them. :)
 
  • Like
Reactions: kaddy