Hacker News new | past | comments | ask | show | jobs | submit login

The problem is that some viruses may run in the kernel mode, so an AV has to do the same, or it will be powerless against such viruses.



If a virus got that far, you're already in trouble. What stops them from attacking the anti-virus?


If you think AV cannot stop viruses in the same privilege level, then that is more reason for AV to run in the kernel mode. Because by your logic, an AV in user mode cannot stop a virus in user mode.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: