![]() |
KAV7 vs Kernel Mode Patch |
Post Reply
|
| Author | |
SystemPro
Senior Member
Joined: 26 April 2007 Location: Germany Online Status: Offline Posts: 504 |
Post Options
Quote Reply
Topic: KAV7 vs Kernel Mode PatchPosted: 05 September 2007 at 7:46am |
Thanks for info! This looks indeed perverted. *LoL* |
|
![]() |
|
EP_X0FF
Senior Member
Joined: 08 March 2006 Location: Russian Federation Online Status: Offline Posts: 4753 |
Post Options
Quote Reply
Posted: 04 September 2007 at 8:09pm |
Name of this kernel32.dll hooker - Kaspersky Antivirus. This is some kind of ring3-ring0 gate perversion created by Kaspersky developers. BTW on the earlier versions of KAV it can be exploited to execute some code with highest privileges. |
|
|
Ring0 - the source of inspiration
|
|
![]() |
|
SystemPro
Senior Member
Joined: 26 April 2007 Location: Germany Online Status: Offline Posts: 504 |
Post Options
Quote Reply
Posted: 04 September 2007 at 12:04pm |
|
I only searched the root of this kernel mode memory patch because procmon seemed to be unable to show a real path. I already uninstalled KAV7 testversion. I checked all kind of security suites some days ago.
So I am not that deep Kav user. But maybe you know the kernel32.dll hooker that RKUnhooker shows above, is that usual if KAV7 is installed? Edited by SystemPro - 04 September 2007 at 12:06pm |
|
![]() |
|
EP_X0FF
Senior Member
Joined: 08 March 2006 Location: Russian Federation Online Status: Offline Posts: 4753 |
Post Options
Quote Reply
Posted: 03 September 2007 at 9:49pm |
|
So what is the question? Maybe forum.kaspersky.com can help you?
|
|
|
Ring0 - the source of inspiration
|
|
![]() |
|
SystemPro
Senior Member
Joined: 26 April 2007 Location: Germany Online Status: Offline Posts: 504 |
Post Options
Quote Reply
Posted: 02 September 2007 at 5:21pm |
![]() Whereas 0x1 represents high likely svchost area. |
|
![]() |
|
SystemPro
Senior Member
Joined: 26 April 2007 Location: Germany Online Status: Offline Posts: 504 |
Post Options
Quote Reply
Posted: 02 September 2007 at 5:12pm |
|
Does any one have a clue why KAV7 is not able to stop this Action?
Looks like a error in KAV. ![]() |
|
![]() |
|
Post Reply
|
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |