... deleting the KEY and/or ID in HKLM-Software-MBAM.
Hi,
Following the discution with Arthur Wilkinson (GT500) I decided to give MBAM another try. I noticed that if I manually delete the KEY or ID in HKLM-Software-MBAM, the real time protection of MBAM is dissabled on the next start-up.
I am wondering if is possible for a virus/malware to do the same...I mean to delete the key and dissable MBAM.
Claudiu
Toronto,Canada
MBAM real time protection easily dissabled by....
Started by Guest_claudiubotezatu_*, Jan 08 2009 11:44 PM
#1
Guest_claudiubotezatu_*
Posted 08 January 2009 - 11:44 PM
Guest_claudiubotezatu_*
#2
Posted 09 January 2009 - 12:26 AM
claudiubotezatu, on Jan 8 2009, 06:44 PM, said:
I am wondering if is possible for a virus/malware to do the same...I mean to delete the key and dissable MBAM.
Most likely, and I think there are plans to protect those settings in later editions.
Right now it's not a huge deal. Most malware is more interested in trying to prevent MBAM from running altogether.
Quote
For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...
#3
Posted 09 January 2009 - 03:09 AM
claudiubotezatu, on Jan 8 2009, 06:44 PM, said:
... deleting the KEY and/or ID in HKLM-Software-MBAM.
Hi,
Following the discution with Arthur Wilkinson (GT500) I decided to give MBAM another try. I noticed that if I manually delete the KEY or ID in HKLM-Software-MBAM, the real time protection of MBAM is dissabled on the next start-up.
I am wondering if is possible for a virus/malware to do the same...I mean to delete the key and dissable MBAM.
Hi,
Following the discution with Arthur Wilkinson (GT500) I decided to give MBAM another try. I noticed that if I manually delete the KEY or ID in HKLM-Software-MBAM, the real time protection of MBAM is dissabled on the next start-up.
I am wondering if is possible for a virus/malware to do the same...I mean to delete the key and dissable MBAM.
Technically, your reverting MBAM back to unregistered mode. RealTime protection would be disabled in unregistered mode.
We may in the future change the location of user registration information. But so far, malware we've seen seems much more interested in keeping us from running in the first place. Resident or otherwise. If your intent on a targeted attack against XYZ program, there isn't much that's really going to stop you.
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account
Back to top










