Microsoft because it does not allow Defender to be disabled

As we mentioned in previous publication Microsoft has removed the ability to disable Microsoft Defender from the Windows 10 Registry.

Από τα Windows Vista, οι χρήστες μπορούσαν να απενεργοποιήσουν πλήρως το Microsoft Defender και ενδεχομένως κάθε άλλου λογισμικού ασφαλείας με τη χρήση του “Turn off Microsoft Defender ” που υπάρχει στις of group policy.

When the policy is enabled, a “DisableAntiSpyware” registry value is created and set to 1 under the HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows Defender key, as shown below.

Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows Defender] "DisableAntiSpyware" = dword: 00000001

Once enabled, this key will disable "Microsoft Defender Antivirus and third-party antivirus software and applications."

At documentation of DisableAntiSpyware, Microsoft states that the DisableAntiSpyware value will be ignored and will no longer be used to disable antivirus software.

Microsoft also states that if a user removes the installed antivirus solution, Windows Defender will automatically activate to protect him / her.

"Consumers may choose to run another AV solution, but if for any reason the application is disabled, Microsoft Defender AV will be reactivated to ensure that there is no user protection gap. ”

Why

Just as Windows administrators know about group policy settings in DisableAntiSpyware, so do malware developers.

Lots of bad guys (TrickBot, Novter, Clop Ransomware, Ragnarok Ransomware, and AVCrypt Ransomware) that have abused this policy to try to disable Windows virus protection.

With the release of Windows 10 1903, Microsoft added a new feature called Tamper protection which prevents her των ρυθμίσεων του Windows Security και του Microsoft Defender από προγράμματα, εργαλεία γραμμής εντολών των Windows, αλλαγές στο μητρώο ή αλλαγές σε πολιτικές s.

So if malware added the DisableAntiSpyware value to the Registry and then restarted the computer, on reboot, Tamper Protection will remove the value.

So now that Microsoft Defender is completely ignoring the value of DisableAntiSpyware, Windows 10 users have much greater protection against threats trying to disable security software using this technique.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).