Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem is that some viruses may run in the kernel mode, so an AV has to do the same, or it will be powerless against such viruses.



If a virus got that far, you're already in trouble. What stops them from attacking the anti-virus?


If you think AV cannot stop viruses in the same privilege level, then that is more reason for AV to run in the kernel mode. Because by your logic, an AV in user mode cannot stop a virus in user mode.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: