Hello and welcome to P C Security Intermediate course
This video I will be talking about
how to make sure that how to protect your anti Melber solution Andre Ware software, so to make sure it's always working. So what about killing the anti wires?
There are small mile wears
that when they start on your PC, the first thing they do is they stopped the process or processes off tomorrow. Software. So basically, they killed a we
so that they can do the things they are planning to do. So, um,
the before that they're not doing anything that a we can them
detectives a suspicious behavior. But from that point on,
they can do whatever they want because they know the A is done
and there are a couple ways to prevent it. So the 1st 1
is a mix of defender 80 p,
and it's something called temper protection.
Eso. It's essentially preventing anybody to from tempering with important security features.
And it's part of Windows security settings,
Um, and it actually essentially protects and time our from being stopped. The Ben thing is that the only anti member that it's actually protecting his windows defender and them over. So the built in and time our that is in Windows
is what is actually being protected with this. Uh huh,
Optioning in Windows security settings.
So if you're using some other on Tim over,
yes, it is stated in the in Windows security settings as a current anti malware solution. So when there's one complained because Microsoft ah anti malware solution is not working,
but then you cannot use this
If you decide to work with the built in Microsoft anti malware solution, then you're okay. So then you can use this.
If not, then you have to choose some other way. So the second thing is to find the way to launch your anti virus or anti mull over as a critical process.
So in Windows, when you stop the critical process,
what happened is that basically your windows locks,
so you get this blue screen.
The Colonel Windows kernel will will essentially stop your system. You'll get this blue screen, and then your machine cannot go on. So, essentially what happens is that you're in the Mallory's stopped in the in its first tracks.
It doesn't mean that you have killed the anti Mauer But it at least it has prevented and time Arab buyer softer from being stopped.
And then the next time you start your machine, it might try to do the same thing again. But then it will go just in the loop or football screens,
so at least you'll know that something very wrong with your system.
the problem with this is that sometimes there is, Ah,
it's really difficult to start your A B is a critical process and really depends on I vis a VI solution that you're choosing. So one of the things that you can put on the list of criteria when choosing anti malware is
can it be launched? There's a critical process. If it can, then it's cool,
Okay? And the third way to do it is to use third party solution. Eso.
There are few third party solutions on the market that do this
on. There are some I, Reese oceans that have something like this built in there. Let's a
Um, I will talk about one solution because I had the experience working in it, but I'm not saying that this is the only one or the best one.
So it's HP sure run, and it comes basically free with the Ole HP pieces that are off the circum level and above. So all those that have the sure start I was talking about before, Uh, most of them, they have sure run.
So sure, Ron is basically a piece of software that's it's
very high in prayer. Italy stuff Windows,
and it is monitoring whatever on type wires are anti mulberry solution you have
in your set up in your Windows security settings as currently turned on anti wire, softer.
So if you look at the window security set up screen here on the on screen, you see that, for example, on my machine, I have a vast antivirus says as a antivirus solution set up in Windows security
and when those defender anti virus system duff. So this is my set up, and then the Iran is there to act and restart whatever process is set up as the anti wires in the Windows security settings.
So if this process goes down, it will simply restarted in. But it started again,
and the good thing about the whole HB set up is that the show Ron is also protected by the shore Start So So essentially, if somebody tries to disable show Ron process
uh, it will be detected by harder cheap on the on your mother board. So it is really
Ah, really good solution. The only problem is that we dissolution. You are bound to use the certain harbor it cannot be used on any other is vendors BC
So we're here at the end of from
the this video and the question for you is just to remind you of what you have been learned. These how can you prevent anti members suffer from being stopped
and the possible answer ours to launch. It is a critical process
to launch it with highest privileges or to launch it is a service, and the correct answer is
to launch it as a critical process. If you remember, if you stopped critical process, the whole machine goes to blue screen mode. So it
telling this video you have learned about three ways to protect your anti malware process for Bill being killed by Malbert. And in next lesson, I'm goingto pay short attention to firewalls on a PC