QUOTE(kbnet @ Feb 17 2005, 09:09 AM)
Thank you both for your posts. Downloading Process Guard now. Interesting program you have written tibbar, going to have a good play around with that.
Im thinking if a virus was capable of detecting which antivirus process was trying to terminate it then it would be able to launch an attack on the AV process. For example if the virus detected that "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\KAV.exe" was attempting to terminate it then the virus could try and attack that directory by trying to remove files and also scanning the registry and removing any keys which belong to the product. This would obviously then be generic for any security software attempting to remove the virus. Therefore, hardcoding security products into a virus would no longer be required as the virus can find what to attack by itself.
might be fun if windows kills an service because it didn't reply 'correctly' to an service.. and then you see your prog remove all those files in the win dir and in the reg.. hope this won't happen.. but it just suddenly came in my mind..
Serhat