Re: Antivirus override

From: MowGreen (mowgreen_at_nowandzen.com)
Date: 09/26/05


Date: Sun, 25 Sep 2005 18:38:28 -0700

David H. Lipman wrote:
> From: "MowGreen" <mowgreen@nowandzen.com>
>
> | David,
> |
> | Are you certain that's not a malware value ? AntiVirusOverride!=dword:0
> | with the exclamation point isn't in any DWord names on any of my XP
> | systems.
> | Without the exclamation point, it is.
> |
> | MowGreen [MVP 2003-2005]
> | ===============
> | * 343 * FDNY
> | Never Forgotten
> | ===============
> |
>
> Interesting point.
>
> However if if the OS does not read the "AntiVirusOverride!" but reads "AntiVirusOverride"
> then it would be ignored by the OS and I can't see how malware could use this altered value
> to change the Security Center.
>
> Am I certain ? -- No.
>
> Nor could I find further info in the Knowledge Base or TechNet.
>

Perhaps someone from MS will see this thread and give us privy to such
knowledge ?
I'll ask around in the meantime, David.

MowGreen [MVP 2003-2005]
===============
  *-343-* FDNY
Never Forgotten
===============



Relevant Pages

  • Re: Message Box Questions
    ... > question and the icon must be an exclamation. ... For those to whom this is new information, David is referring to the comment ...
    (microsoft.public.vb.general.discussion)
  • Re: Language Features Id Like To See
    ... > David had to work with. ... yeah, I followed the flow ... ... I thought the exclamation point ...
    (borland.public.delphi.non-technical)
  • Re: Antivirus override
    ... | with the exclamation point isn't in any DWord names on any of my XP ... then it would be ignored by the OS and I can't see how malware could use this altered value ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Antivirus override
    ... Check my reply to the original post. ... The added exclamation point does ... David H. Lipman wrote: ...
    (microsoft.public.windowsxp.security_admin)
  • Re: BYTE and DWORD
    ... >> David - thanks for your help. ... >> initial startup problem. ... >> typedef DWORD ... > Is a DWORD signed or unsigned? ...
    (comp.sys.mac.programmer.help)