Vista’s Protected Processes Not So Protected
- 2
- Add a Comment
Security Researcher Alex Lonescu has found a way to bypass Microsoft Vista’s Protected Processes. This can allow users to disable DRM but it also can allow virus authors to create more dangerous malware that is even harder to detect and remove.
Malware authors can use this bypass to protect any process they want, including viruses, keyloggers, adware, or worms. They can also use it to unprotect any process that you actually want running like anti-virus programs and firewalls.
While Lonescu hasn’t released the source code it’s only a matter of time before malware authors duplicate his methods and we start to see malware using these techniques in the wild.
Don’t downgrade to Vista, buy a Mac or try Ubuntu.
[Why Protected Processes Are A Bad Idea]
[tags]Microsoft Vista, Windows Vista, Microsoft Windows Vista, Vista, Microsoft, Mac, ubuntu, malware, drm, protected processes[/tags]

2 Comments
subwolf
April 12th, 2007
at 12:44pm
Why. Am. I. Not. Surprised.
When will they learn DRM will never win.
rlpeel
May 27th, 2007
at 2:20pm
This article sounds about right. Take something that someone else has been using and doing right for years mess it up. I swear Microcrap could screw up a wet dream.