4 ms·
Just kernel drivers. To know what is inside, you can disassemble them with https://github.com/NationalSecurityAgency/ghidra https://github.com/NationalSecurityA
by novaRom 2y ago
Just kernel drivers. To know what is inside, you can disassemble them with https://github.com/NationalSecurityAgency/ghidra https://github.com/NationalSecurityAgency/ghidra
- stefan_ 2y agoThese files are apparently just definitions/input for the actual CrowdStroke driver, that presumably someone named .sys so it sounds more scary and important. Peak irony then that you can just delete them. Surely an antivirus should recognize when its being rollbacked?
- petesergeant 2y ago> that you can just delete them Don't you have to be in recovery mode, with it switched off, to do that?