Can DeepGuard block writing to disk by sending SCSI IRP?

Homecomings
Posts: 1 New Member
I tested several MBRKiller samples and I found one that bypassed DeepGuard. It seems that the sample writes to disk by sending SCSI IRP to disk driver to write MBR directly.
Will DeepGuard block this behavior in the future?
Here is the sample:
0 Like
Answers
-
Hello @Homecomings
Thanks for your feedback. Could you please upload this file here: https://www.f-secure.com/en/business/support-and-downloads/submit-a-sample?
And also please don't attach malware or malware samples like this in the future. Please use this link instead.
Best Wishes.
3 3Like