logoalt Hacker News

wolfi1today at 7:00 AM1 replyview on HN

if processes lock the file shouldn't AV refrain from reading or even writing it?


Replies

rcxdudetoday at 9:02 AM

Nope, AV hooks into the filesystem layer (the NT kernel has 'filesystem filters' for this) and intercepts all reads and writes on the system.