{"id":84401,"date":"2017-06-13T19:59:05","date_gmt":"2017-06-13T14:29:05","guid":{"rendered":"https:\/\/blogs_admin.quickheal.com\/?p=84401"},"modified":"2017-06-13T20:05:38","modified_gmt":"2017-06-13T14:35:38","slug":"certlock-trojan-can-disable-antivirus-software","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/certlock-trojan-can-disable-antivirus-software\/","title":{"rendered":"CertLock Trojan can disable your antivirus software"},"content":{"rendered":"<p>An antivirus software keeps your computer safe from malware, viruses, online threats, and suspicious or harmful elements. Although bypassing this protective guard is a difficult task for attackers, they never stop trying to do so. Recently, we came across a malware that is designed to interfere with the infected system\u2019s security software by disallowing its certificate. This malware is called CertLock.<\/p>\n<p><strong>The Infection Chain<\/strong><\/p>\n<p>CertLock enters into the victim\u2019s system by bundling itself with other free software. On an infected system, when the user tries to access their installed security software, they come across an error message saying that the access is blocked by Windows. The malware also blocks new installation of security programs in infected systems. Without any security, these systems are left defenseless and hence stay completely at the mercy of the attacker.<\/p>\n<p>CertLock manipulates the Windows feature of system certificates. These certificates are trusted by the operating system and can be used by applications to make themselves trustworthy. In this case, the attacker added certificates of the security software to a special registry of Windows, which prevents programs signed with that certificate from getting executed on the system.<\/p>\n<p>These certificates are added under the below registry entry:<\/p>\n<ul>\n<li>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates<\/li>\n<\/ul>\n<p>A certificate&#8217;s key is added to the above registry with a certificate value in a blob.<\/p>\n<p>Any software with certificates registered under the above key is not recognized as a trusted publisher and this prevents its installation or execution in the infected machine.<\/p>\n<figure id=\"attachment_84403\" aria-describedby=\"caption-attachment-84403\" style=\"width: 618px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-84403\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/06\/CertLock.jpg\" alt=\"Fig 1: Added security vendor\u2019s certificates\" width=\"618\" height=\"658\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/06\/CertLock.jpg 770w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/06\/CertLock-282x300.jpg 282w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/06\/CertLock-768x818.jpg 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/06\/CertLock-366x390.jpg 366w\" sizes=\"(max-width: 618px) 100vw, 618px\" \/><figcaption id=\"caption-attachment-84403\" class=\"wp-caption-text\">Fig 1. Added security vendor\u2019s certificates<\/figcaption><\/figure>\n<p><strong>Quick Heal Detection<\/strong><\/p>\n<p>CertLock does not affect the functioning of an installed Quick Heal product in a computer nor can it block any new installations.<\/p>\n<p>Quick Heal&#8217;s <strong>Behavior Detection System<\/strong> successfully detects and blocks CertLock from affecting your computer.<\/p>\n<figure id=\"attachment_84402\" aria-describedby=\"caption-attachment-84402\" style=\"width: 459px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-84402 size-full\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/06\/CertLock1.jpg\" alt=\"certlock1\" width=\"459\" height=\"264\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/06\/CertLock1.jpg 459w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/06\/CertLock1-300x173.jpg 300w\" sizes=\"(max-width: 459px) 100vw, 459px\" \/><figcaption id=\"caption-attachment-84402\" class=\"wp-caption-text\">Fig 2. Quick Heal Behavior Detection System detection for CertLock<\/figcaption><\/figure>\n<p><a href=\"https:\/\/www.quickheal.co.in\/home-users\/quick-heal-total-security\" target=\"_blank\">Quick Heal Virus Protection<\/a> detects the malicious files of CertLock malware with signature-based detection as &#8216;Trojan.CertLock&#8217;.<\/p>\n<p><strong>Steps to stay safe against malware such as CertLock<\/strong><\/p>\n<ul>\n<li>Free software, especially those with unverified publishers are usually used by attackers to spread malware. Always go for genuine and licensed software.<\/li>\n<\/ul>\n<ul>\n<li>Use a security software that offers multilayered protection. Keep the software updated to stay safe from the latest and emerging threats.<\/li>\n<\/ul>\n<ul>\n<li>Always keep your Operating System and programs patched with the latest updates.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Acknowledgement<\/strong><\/p>\n<p>Subject Matter Expert<\/p>\n<ul>\n<li>Prashil Moon | Quick Heal Security Labs<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An antivirus software keeps your computer safe from malware, viruses, online threats, and suspicious or harmful elements. Although bypassing this protective guard is a difficult task for attackers, they never stop trying to do so. Recently, we came across a malware that is designed to interfere with the infected system\u2019s security software by disallowing its [&hellip;]<\/p>\n","protected":false},"author":29,"featured_media":84404,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[289,24,5],"tags":[1459,1458,40],"class_list":["post-84401","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-safety","category-malware","category-security","tag-certlock","tag-certloock","tag-trojan"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/84401"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=84401"}],"version-history":[{"count":4,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/84401\/revisions"}],"predecessor-version":[{"id":84408,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/84401\/revisions\/84408"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/84404"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=84401"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=84401"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=84401"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}