Can DeepGuard block writing to disk by sending SCSI IRP?

Homecomings Posts: 1 New Member

I tested several MBRKiller samples and I found one that bypassed DeepGuard. It seems that the sample writes to disk by sending SCSI IRP to disk driver to write MBR directly.

Will DeepGuard block this behavior in the future?

Here is the sample: