by Cool_Fire » Fri Jun 08, 2012 10:07 am
It's possible to disable antivirus with a lot of tools. The catch is that you have to get into the machine in order to install and run them, so you need an initial way in and a payload that isn't detected by antivirus.
Alternatively, you could try an old-fashioned zip bomb by email or over some instant messenger file transfer. The idea there is to send a zip file containing so many layers of recursion and such volume when decompressed that the antivirus will be tied up for some time. Of course this is fairly noticeable for the user, and when an antivirus scanner is multi threaded it's of no use.