A new, completely transparent method of deactivating/reactivating VSAFE

After just a few minutes of analysis several months ago, I discovered a way to bypass VSAFE which is far less detectable than the usual deinstallation. The total removal of VSAFE by a virus would arouse suspicion and would be incredibly obvious if some other TSR had been installed after VSAFE, since VSAFE displays an alert box in such a case warning that VSAFE cannot be removed.

