Question Which AV are you using and why did you choose this one ??

Please provide comments and solutions that are helpful to the author of this topic.
No matter which AV u use EDR killers are a big threat!
Esentire tracking a new EDR killer using a #BYOVD driver that isn't in Microsoft's block lists / #LOLDrivers and enumerates 140+ security products, including: Crowdstrike, SentinelOne, Microsoft Defender / Sentinel, Carbon Black, Cybereason, Cylance, Symantec, Sophos, FortiEDR, Elastic, Kaspersky, ESET, Avast / AVG, Bitdefender, McAfee / Trellix, Malwarebytes, Webroot, Trend Micro, Avira, Dr. Web, F-Protect / F-Secure, G-Data, Panda Security, and more.
It only activates if the payload being loaded contains ScreenConnect-related strings, uses IOCTL control code 0x2205c0, and passes each security product PID to terminate via input buffer to the driver via DeviceIOControl, which terminates the specified PID via ZwTerminateProcess.
 
Last edited by a moderator:
Why would you change AV all the time? The efficacy of most of them is similar, some are almost the same bar for the GUI? I feel find a decent solution whatever that be & use it, that is now my MO, chopping & changing unless you revert to a golden image will always leave some junk behind, & little if anything will be gained.
I understand him though. As I said, I was the same. I kept reading those articles in media how new scary malware was found or how hackers stole a billion dollars from a company. I'm not afraid to admit how dumb I was. Along typical antivirus software, I also had installed 3rd party firewall, various 3rd party anti-exploit, anti-malware tools. You should have seen startup list on my PC. If PC had 50 program installed, at least half of them was related to security in some kind of way.

This all changed when I grew older. When I learned that all those articles aren't false, but written to get as much as clicks as possible, because what sells better than the fear. I realized that chances of me getting the new scary malware were equal as chances of me winning Eurojackpot and that all these security programs were there just sitting, using up resources doing nothing. Then I started to remove them one-by-one and eventually did a clean installation with one security solution and one anti-malware scanner for on-demand scanning. Not only did my Windows became way faster than it used to be, but I didn't need to reinstall Windows on a yearly basis.

For that reason, I can only recommend sticking with Defender, adjusting its settings as you wish, using some kind of ad blocking DNS system-wide, ad blocker in the browser and some kind of extension for blocking malicious sites—that is it. Antivirus software on your PC is last line of defense either way and the goal is to stop malware before it reaches your antivirus software.
AV's dig deep into your system its a likely cause of instability when drivers are left behind, that based on my personal empirical evidence not conjecture, maybe thats why my systems are stable, who knows??
This is what I've been trying to tell everyone. I'm not defending Microsoft nor Defender. All I'm saying 3rd party antiviruses aren't really necessary and may not provide better protection than what Defender offers. It's stuck with people Defender bad, 3rd party good because the situation was like this ever since they started using PCs. Times change and sometimes for the better, sometimes for worse. This is a case where times changed for the better as you finally don't have to spend money in order to be properly protected. Before anyone stars throwing pitchforks again "it's free because it collects data". With commercial antivirus software, you pay for it and it still collects data. So at least this way, I never paid them to spy on me. 😅

If Microsoft's product works okay, doesn't cause me any issues and does all I want it to do, I have no reason to use anything else and I stick to that. If Microsoft products isn't working great, is causing me issues or generally doesn't do everything I want it to do, then I'll find an alternative.

So... yeah, you don't have issues because you're not messing around with 3rd party software much, you don't install preview updates and you're not using various 3rd party tools to modify system settings. I also don't do any of those thing and I never have any issues with my PC as well. Ironic, considering before I used to have problems all the times. In a lot of cases, the less is actually the better.

Btw Bot doesn't understand allegory and sarcasm. 😂
In my experience, it is possible to remove all the leftovers from antiviruses, if you use an installer which monitors the changes made when installing it, so it has a record of every file and registry key it needs to delete. However, if you're just using an uninstaller, without having records of this, then it won't find and remove every leftover. As you've noted, even the official uninstall tools provided by antivirus vendors sometimes don't remove every leftover.

This is a good reason to stick with Windows Defender, rather than using third party antiviruses. Although, as I've mentioned before I don't use it myself.
Unfortunately, even with Revo, I found many leftovers. Revo only searches registry entries by name of the software as well as %appdata% and %programdata%;, it doesn't touch drivers, scheduled tasks and etc.

There were times when I thoroughly went in hunt for leftovers because it was annoying for me that every software warned me some 3rd party antivirus software was installed despite being removed 6 months ago. Even after deleting everything I could, it still somehow found what software I had installed before. Then clean installation became my only solution.
 
Last edited:
Unfortunately, even with Revo, I found many leftovers. Revo only searches registry entries by name of the software as well as %appdata% and %programdata%;, it doesn't touch drivers, scheduled tasks and etc.
It will if you it use it in the standard way, of just letting it scan for leftovers after uninstalling apps, where it does its best to find file and registry keys that belong to that app. But what I was talking about was using the snapshot mode, which is offered in the Pro version of Revo, as well as some other uninstallers, including the free HiBit Uninstaller. When installing an app, they take before and after snapshots, so they they have a record of very file and registry key that was added or changed during the install. Then they have a record of exactly what needs to deleted after uninstalling an app, rather than making educated guesses. However, by creating before and after snapshots, they have a record of every single change that happened when installing the app, rather than just the changes made when installing that app. Personally I use Install Monitor, which automatically monitors any changes made when installing apps, without requiring any user action.
 
Last edited:
There were times when I thoroughly went in hunt for leftovers because it was annoying for me that every software warned me some 3rd party antivirus software was installed despite being removed 6 months ago. Even after deleting everything I could, it still somehow found what software I had installed before. Then clean installation became my only solution.
As someone who used registry cleaners to check my system out of curiosity, I always found entries related to antivirus software that had previously been installed. However, after using "FRST" for the first time, I made the decision to use it instead of registry cleaners for my regular cleaning tasks. Here is a helpful post about using it.