Recently, security tools such as SSDT have been removed from the virus epidemic. So far, the SSDT recovery of these viruses is basically achieved by loading a virus driver. sys. As long as the virus driver is not loaded, it is much easier to process it even if it is done. Therefore, how to properly manage system drivers without leaving loopholes for such viruses is a concern for every user.
Here, I will use the "Software Restriction Policy" and rising's "active defense" settings to deal with such viruses. The sys Solution and Its Protection effects are described as follows:
1. Set "Software Restriction Policy" to treat system. sys and non-system. sys differently.
2. Protect files in the drivers directory from changes.
3. Special case handling-IceSword operation problems.
4. Rising's own protection problems.
5. The above scheme protects against the two popular virus samples. sys. This solution is only designed to prevent virus driver loading,
Protection against virus files other than. sys is not covered in this post.
6. Supplementary Note: by default, the "assigned file type" in the "Software Restriction Policy" does not include SYS. You must add the following files on your own:
7. Additional instructions: Prohibit malicious programs from deleting group policy settings