Security News CertLock Trojan Blocks Security Programs by Disallowing Their Certificates

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Feb 4, 2016
2,516
15,625
3,578
53
Germany / Poland

important note/quote from the article above:

How to remove Certificates Disallowed by CertLock
ToolsLib.com co-administrator and Malwarebytes AdwCleaner developer Jérôme.B has created a tool called AVCertClean that will scan the Disallowed registry key for legitimate blocked keys and remove them. To use the tool, simply download and execute it. The program will then automatically remove blocked certificates



...some other quotes from the article above:

A new trend in adware and unwanted program purveyors is to install protection software that makes it more difficult for Windows users to run their security programs and clean infections. This was seen with the SmartService rootkit that blocked AV software from running and now with a protection program being called CertLock.

Since the end of May, security forum helpers have noticed reports that people are not able to install and run security programs on their infected computers. When they try to run the programs, they are greeted with an alert that states that the publisher has been blocked from running on the computer.

It turns out that this is being caused by CertLock disallowing a security vendor's certificate on the affected computer so that Windows does not allow the program to run.


CertLock disallows security vendor certificates
Being commonly detected as Ceram or Wdfload by anti-virus vendors, CertLock is distributed by unwanted programs bundles, such as miners. Once installed, CertLock will block a security vendor's certificate by adding them to a special Windows registry key. This causes Windows to not execute any programs that are signed with that certificate.

If a certificate is added to the Disallowed list, when a user tries to run a program that is signed by this certificate they will be greeted with an error that states "The publisher has been blocked from running software on your machine".
 
Last edited:
can we see manually through regedit where these disallowed certificates would be stored?
and if so, are they easily identifiable to see which companies are disallowed?

//edit
nvm, just read the article after posting lol
HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\
thats where those disallowed certificates are being written to
 
Thanks for sharing :)

That's the first time I heard malware uses this method to block security apps.
I just remember Sality used a DLL that tried to close any kind of process with possible associations with different security products, by terminating also the task manager and UAC.
 
  • Like
Reactions: LASER_oneXM