Hi,
Most of us would have been infected atleast once by a A threat that say would have terminated the security apps
and also prevented us access to security sites. .
Well I wanna know if a threat terminates a security suite by terminating specified process like ccsvchost.exe or Nav32 or similar.
Means the virus is coded to end all the following process names.
McAfee stinger apps recommends that if system is infected to change the download name of the exe from stinger to something else as it may work
So is it pssible to do the same for NIS OR NAV OR N360 like changing the name of the scanner autoprotect.exe is it possible????(I know may be a dumb question )
well the threat tends to terminate the av process at start up to so if we change the name of the start up exe
It may not recognize it as a security suite(or may be the threat even check the registry entry?)
Setup of suites get terminated on infected comps is it possible or of any use changing the setup name or stuff like that???
and also for eg ppl recommend create an autorun.inf file to prevent pen drives to be infected by W32.USb.worm(common name for autorun worm )
So is it possible to do something like that with the host file to. To my knowledge the threat modifies the Host file to prevent access to security sites.So is it possible to do something in prevention of it.