Hacker News new | ask | show | jobs
by clowd 1621 days ago
> There should be nothing that TaskMgr can't kill

Except Defender/Malware Protection...

2 comments

>Except Defender/Malware Protection...

I just checked and it can definitely kill malware protection so I don't know where you got that information but it's false.

And even without checking, being able to disable malware protection is a necessary feature in any OS, for SW development and debugging activities, so I would assume malware protection could be easily killed without a problem by the user with admin privileges.

Not sure which version of Windows you're on but a lot of things like this have been blocked in newer versions, here is a screencap from attempting this on 11: https://i.imgur.com/xY4dNVL.png

> And even without checking, being able to disable malware protection is a necessary feature in any OS, for SW development and debugging activities, so I would assume malware protection could be easily killed without a problem by the user with admin privileges.

Lol, one would assume wouldn't they... in 11 even setting the GPs for all of the antimalware stuff to off won't stop the processes from running. You can still get it to a decently "get out of my way" level though.

I was trying this a few weeks ago on a brand new Windows 10 install

I turn off the "realtime protection" in GPO/options... it's still there

I try killing "Antimalware Service Executable" (Msmpeng.exe), in taskmanager or try disable the service in the service control panel: Access Denied

I reboot into safe mode, disable the service, reboot and it's gone

.. but reboot again and it's back

I had to DELETE the service in safe mode and change the permissions on the executable so it couldn't be accessed/modified by anything

(borderline rootkit if you ask me)

And nowadays I don't think it can kill assistant/Cortana.
Come on, I get that everyone hates Cortana, but why spread such FUD? Of course it can kill Cortana as it's a regular user-space app.

The only Windows processes I see it can't kill are labeled System, System Interrupts, Secure System and Registry which I guess, are all kernel-space.

It would be ironic if you tried to kill Cortana and it said "I'm sorry, Dave. I'm afraid I can't do that."

But yes I don't see why it couldn't (or why MS would add such a high-level protection to Cortana)

I just killed Cortana on a windows 10 laptop and on a windows 11 workstation with it... why lie if you are proven wrong in about 10 seconds?
The person you are replying to used the phrase, "I don't think". That means they're not certain, which means they're not lying. Might wanna refrain from shooting from the hip in regards to the tone of your last sentence.
Being anal aside why spread FUD when you can easily test if your thought is true or not. Makes no sense no matter what when he can just be silent if he doesn't know if his statement is true or not but no better start shit stirring for no reason whatsoever.
>... why spread FUD when you can easily test if your thought is true or not.

First, how do you know they're in front of a Windows machine and not casually commenting from their phone only to have life get in the way and make them set their phone down before they can Google it?

Second, I argue that FUD isn't spread if you're commenting and saying "I don't think it does this". Were they to say, "You cannot do this," then they would be spreading FUD. They didn't, they were corrected publicly, and anybody reading this thread can see as much. Maybe they'll even edit their post after they see this, who knows!

Edit: Even if I'd agree that they're spreading FUD, it's so minor and innocuous that it's not even worth getting angry at them.

Edit 2: If it's as easy for them to test if it's true or not, then anybody else with a Windows machine who sees that comment should also have just as easy a time testing it themselves. IMO that only serves to make this less FUD-dy than people are suggesting.

You are making excuses for someone who didn't even take 2 minutes before talking about a subject matter he doesn't know anything about. He used "I think" like every other bad actor when spreading FUD. I don't even care anymore I call people out if they talk shit if you want to be the one making excuses for them so be it.
Try killing it from the "Details" view.