Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Windows 8 contains malware improvements, antivirus researcher says

'Early Launch Anti-Malware' architecture means anti-malware drivers get there first in boot process

Article comments

Microsoft is taking a distinctly different - and likely far better - approach with Windows 8 to how anti-malware will run in comparison to earlier versions of Windows, according to ESET antivirus researcher Aryeh Goretsky.

Microsoft's approach, called "Early Launch Anti-Malware," basically means the first software driver to be loaded into the Windows 8 OS upon its use will be the driver of the user's anti-malware software. This is a major change because "before, it was a 'no-man's land'," says Goretsky, meaning loading driver software on the user's machine was random and "a malicious device driver" could get there first, allowing the malware to trump the anti-malware and maybe turn it off.

Microsoft has put in some protections to ensure that anti-malware from vendors that have gone through Microsoft's digital-signing review process will be loaded up first to check to see if a system is clean before continuing the boot process, says Goretsky. There is one wrinkle in all this in that Microsoft itself is shipping its own anti-malware software with Windows 8 called Windows Defender.

So unless the user has Windows Defender uninstalled, this will be the first antivirus software to load up. Since some computer suppliers make money through partnerships with the larger anti-malware vendors such as Symantec and McAfee, they may uninstall it before the Windows 8-based computer makes it to the consumer, Goretsky notes. But in the uninstalling of antivirus software - whether it's Microsoft's or another vendor's - Microsoft has also made huge progress in Windows 8, according to Goretsky.

That because for the first time, Microsoft's requirements make it clear how security software packages have to neatly be removed at command off Windows 8 when that's the user request. The dirty little secret of the industry has been that anti-malware software has long been known to make registry changes and other modifications to the OS that basically make it hard to return to its previous state, says Goretsky. He says often there's a mess of device drivers and services left running after an anti-malware package has in theory been uninstalled. This makes the OS not as simple for the next anti-malware software to deal with. "We're as guilty of this as anyone else," says Goretsky.

There are other aspects of Windows 8 security to be appreciated, he points out. One big one is what's called the "Unified Extensible Firmware Interface" that requires digitally signed firmware to be used in booting up to prevent a rootkit from making it in. This secure boot process is supported through the UEFI industry standard. The National Institute of Standards and Technology has been a strong proponent of this secure-boot process.


More from Techworld

More relevant IT news


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *