Jump to content
  • Sign Up
×
×
  • Create New...

Recommended Posts

  • Diamond Member

This is the hidden content, please

Defendnot tool pitched as ‘an even funnier way’ to disable Windows Defender

There’s a new tool available for folk who want to disable Windows Defender without replacing it with a rival antivirus (AV) product. Developer and reverse engineer es3n1n released the new

This is the hidden content, please
recently. The software taps into an undocumented Windows Security Center (WSC) API to tell the OS there’s some other antivirus software turned on, thus gracefully giving Windows Defender the elbow.

In a blog post discussing

This is the hidden content, please
, es3n1n introduces the new tool by highlighting how it is a replacement for their no-defender tool from a year ago. Defendnot’s ancestor disabled Windows Defender by reusing third party code from an existing AV product. Not surprisingly, it was hit by a DCMA takedown request… Defendnot started as an attempt to create a “clean implementation” of the prior project, without any ‘donor’ AV. This wasn’t easy, as WSC isn’t (publicly) documented.

Leaning on prior experience, es3n1n correctly guessed how WSC validated calls made by genuine AV products. So, they injected code into this process, with immediately promising results. The blog shows a “fresh-new antivirus I registered,” and you can see it is arbitrarily named ‘hi2.’ In the screenshot below, from GitHub, you can also see it dubbed ‘hello readme:).’


You may like

Defendnot's fake AV app

(Image credit: es3n1n)

Many shenanigans later (about three days) es3n1n finessed their Defendnot tool by injecting the fake AV DLL into the already signed and trusted Windows Task Manager process (Taskmgr.exe). From there it can register the fake AV tool with any name. If you check

This is the hidden content, please
, their reporter made a fake AV dubbed the BleepingComputer Antivirus, using Defendnot, for even more fun.

With Defendnot injected and registered,

This is the hidden content, please
Defender will immediately shut itself down. As your Defendnot app isn’t actually an AV program, that will leave you exposed to viruses and similar malware, as you won’t have a real-time scanner enabled. To keep your new ‘AV’ and WSC implications live between reboots, Defendnot is added to Windows autorun.

This is the hidden content, please
classifies Defendnot as a *******

It is kind of scary how a legitimate AV program can be spoofed like this, but as a ‘research project’ it forewarns OS makers like

This is the hidden content, please
of potential vulnerabilities which may be exploited by bad actors. If you were to download the Defendnot tool today,
This is the hidden content, please
’s Defender has already started to detect and quarantine it as a ******* based on its machine learning algorithms.

Follow

This is the hidden content, please
to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button.

Get Tom’s Hardware’s best news and in-depth reviews, straight to your inbox.



This is the hidden content, please

#Defendnot #tool #pitched #funnier #disable #Windows #Defender

This is the hidden content, please

This is the hidden content, please

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Vote for the server

    To vote for this server you must login.

    Jim Carrey Flirting GIF

  • Recently Browsing   0 members

    • No registered users viewing this page.

Important Information

Privacy Notice: We utilize cookies to optimize your browsing experience and analyze website traffic. By consenting, you acknowledge and agree to our Cookie Policy, ensuring your privacy preferences are respected.