EP_X0FF wrote:They always carried about self-protection bypass. No matter what company and what they speak on public. Of course on official forums and maybe blogs they will tell "no problem" and "who need AV termination" and other kind of 'see no evil'. It is typical marketing lie. There are a lot of malwares successfully terminating AV while its work. So having enough strength and armored self-protection is required option for any modern AV product. What about "thanks" etc, I don't care :) Prevx self-protection is weak and requires a lot of work to fix numerous termination possibilities.Some AV Vendors just need to learn how to run simple tools.
about two years ago I tested some av tools using this simple process termination tool.
in fact the older versions of rku were disabled by this tool.
I believe the command was spt rkupid 10 -f
check it:
Attachments
Simple Process Termination(command line)
(26.69 KiB) Downloaded 55 times
(26.69 KiB) Downloaded 55 times