Author Topic: Protecting avast! services  (Read 10067 times)

0 Members and 1 Guest are viewing this topic.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89164
  • No support PMs thanks
Re: Protecting avast! services
« Reply #15 on: April 18, 2005, 09:11:36 PM »
I think that it was Vlk that said in a previous post along similar lines about protecting processes, that if someone wanted to disable something then they could no matter what we do to protect it.

One of the things that help virus/malware writers is our insistence in browsing with Admin privileges (XP) as once the virus/malware gets past our defences, then it also has admin privileges and can reap havoc.

I use MS DropMyRights on all Browsers and email clients, so you are still logged on as a user with admin privileges, but your on-line activity hasn't. It is quick and easy to close the browser and open the link that has full privileges should you need it, such as for windows update.
« Last Edit: April 18, 2005, 09:13:22 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Protecting avast! services
« Reply #16 on: April 18, 2005, 09:43:55 PM »
ZoneLabs manage to protect their "vsmon" service w/o any extras.
This has to something you can set in Windows (w/o any extra program).
Lars, it's a good idea but as discussed a lot in the past, with administration privileges no way... the process could be terminated as they say.
I don't know how, just they say that it's possible. Listen what David posted.

If you write that over at Wilders, they'll propably shoot you  ;D
When I post in Wilders I'm always shot!  ;D
Probably tECHNODROME won't agree with me but as much I post there more I get fired...
Maybe I do not found the right way.

Well, I'd stay away from ProcessGuard... I've seen way too many (hard-to-track) problems with this program. Just my €0.02 worth. ;)
It could bring a lot of trouble indeed. As much you 'close' its settings and the computer starts to crash... BSODs are frequently.

Stupid colaboration:
Will the option PassThrough=0 into avast4.ini file (section [MailScanner]), will it work? Or only if you use 127.0.0.1 (old method)?
Does the Trust value change this behavior?
The best things in life are free.

Offline Lars-Erik

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 394
    • Lars-Erik Østerud
Re: Protecting avast! services
« Reply #17 on: April 18, 2005, 10:00:56 PM »
Sure?  I have admin priviledge, and I cannot stop the "vsmon" service (just says "access denied" or something like that). So they got to have disabled somthing (anyone know WHERE I can change that, I'd like to change some settings on the "vsmon" service, but ain't allowed :-)
www.osterud.name - ICQ: 7297605 - AIM/Yahoo/Facebook/Skype/Astra: LarsErikOsterud

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Protecting avast! services
« Reply #18 on: April 18, 2005, 11:01:12 PM »
Sure? I have admin priviledge, and I cannot stop the "vsmon" service (just says "access denied" or something like that).
You can test it with Advanced Process Termination: http://www.diamondcs.com.au/index.php?page=apt
It provides nine (9) different process termination techniques. Won't any of them be able to kill 'vsmon'?
The best things in life are free.