Home » A spoof antivirus makes Windows Defender disable security scans

A spoof antivirus makes Windows Defender disable security scans

by Wikdaily
0 comments
Finger pressing windows button


This wasn’t an easy feat as Windows has checks to ensure the antivirus is real, involving registry names and signed binaries. The researcher used tools like dnSpy, Process Monitor, and manual inspection to see how legitimate antivirus tools behaved when registering with WSC.

“From my last year’s courtesy, I knew that WSC was somehow validating the process that calls these APIs, my guess was that they are validating the signatures, which was indeed a correct guess,” es3n1n added.

es3n1n’s earlier project, no-defender, was removed from GitHub following a DMCA takedown request by the software vendor.

You may also like

Leave a Comment

Welcome to WikDaily, your trusted source for the latest news, trends, and insights across the globe. We are a dynamic blog-style news platform committed to delivering fast, accurate, and engaging content across a variety of topics—from breaking headlines to deep dives into tech, business, entertainment, travel, sports, and more.

Edtior's Picks

Latest Articles