Hacker News new | ask | show | jobs
by blibble 1621 days ago
I was trying this a few weeks ago on a brand new Windows 10 install

I turn off the "realtime protection" in GPO/options... it's still there

I try killing "Antimalware Service Executable" (Msmpeng.exe), in taskmanager or try disable the service in the service control panel: Access Denied

I reboot into safe mode, disable the service, reboot and it's gone

.. but reboot again and it's back

I had to DELETE the service in safe mode and change the permissions on the executable so it couldn't be accessed/modified by anything

(borderline rootkit if you ask me)