False detection on file tcpip.sys
support.kaspersky.com
support.kaspersky.com
For those that are curious, you can use a tool distributed by Microsoft called Sigcheck to display signature information (http://technet.microsoft.com/en-us/sysinternals/bb897441.asp...).
I'm fairly good at distinguishing between what's a virus and what's not a virus. 99% of things are in the latter category care of fairly non-dubious web surfing habits.
The last time I got a virus was sometime back when Vista was the new kid on the block. I was searching high and low for a keygen for a really obscure program and I thought I'd finally found one.
Windows Defender was all up in my face like "don't run this, it's a virus!" and I was like "damnit Windows Defender, I want this key" so I ran it.
Lesson learned. Viruses don't infect PCs. People infect PCs.
I don't have much experience in this area, but shouldn't that be prevented by the kernel unless IE got specific permission to do so?
...unless you're alluding to security exploits that manage to subvert that mechanism.
On Windows, any programs sharing a desktop are within the same security boundary and are not protected from each other by design.
But until running mostly apps becomes the norm in a desktop system beware that not having admin privileges doesn't not mean you can NOT: load programs at startup, read most of registry settings, passwords, read memory of/close programs of same sec level. A malware doesnt need admin rights to do evil.
Still I believe AV products are useless even for inexperienced users.
If you want apps to be blocked from touching each other, they need individual user accounts or equivalent. Operating systems for phones do this, but this kind of system hasn't been ported to a normal desktop.
I've checked, and current versions of MSE will detect this in time, but it's fast approaching the point where Windows will be running in a snapshotted VM with no network access.
You're correct either way.
As for different versions, it doesn't seem like this should be a significant challenge to an organization which already has to maintain a test OS farm. The process of updating after a release is mostly automatic and if this acted solely as a guard against false positives, the consequences of missing a patch permutation are the current status quo.
If they assume that most users apply all "critical" Windows updates in the order that they're pushed, the anti-virus vendor could snapshot their reference PCs before each update and record the hashes of all Windows files. It's possible to determine which updates have already been installed on a machine (there's an option for this in the control panel, and the information is probably stored in the registry).
For bonus points, make the software realize that even if the file on the CD looks infected, it isn't actually infected, so make that file's SHA-256 sum a 'known good' profile. (If the file on the actual install CD really is infected, that falls into the category of "Problems The AV Can't Solve". At that point, the OS itself is controlled by Malign Forces Working To Destroy You and the game is over.)
For extra special bonus points, code compressed copies of those essential files into the AV software itself, so they can be replaced on the fly without prompting anyone. They can be updated along with the malware profile data, if they ever need to be.
2. You can't put compressed copies of essential files into the AV software itself for a couple for a couple of reasons:
- Microsoft will sue you for distributing their intellectual property without permission (and is not likely to grant such permission, since they can't control the quality of the third-party software).
- These files are not static: they could have been modified by any Windows update, and might be dependent on other updated files.
Keeping track of the hashes of "known good" files might work, but you'd have to account for files that were modified by Microsoft patches.
http://securitywatch.pcmag.com/hacking/317184-weaponized-ant...
It's amazing what kind of things slip by.