just some general methods which are more than well known to publicAgreed, That was my very first question :D
Is this a PoC or the code is known?
A forum for reverse engineering, OS internals and malware analysis
just some general methods which are more than well known to publicAgreed, That was my very first question :D
Is this a PoC or the code is known?
Version = 2.0.0.783
Unable to create DevObj for KLCR. err = c0000035
EP_X0FF wrote: I approve topic starter poc. It indeed terminates Kaspersky 2012 from user mode. All instances terminates without any warnings (default from the box configuration). This is not GUI-based attack. It uses generic flaw in Kaspersky self-protection. Additionally slightly modified this code can totally block Kaspersky from loading. Tested on Windows XP SP3 with Kaspersky v12.0.0.374Неужто и тут PG? ;) (is it PG case again?)