Security News CertLock Trojan Blocks Security Programs by Disallowing Their Certificates

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520

important note/quote from the article above:

How to remove Certificates Disallowed by CertLock
ToolsLib.com co-administrator and Malwarebytes AdwCleaner developer Jérôme.B has created a tool called AVCertClean that will scan the Disallowed registry key for legitimate blocked keys and remove them. To use the tool, simply download and execute it. The program will then automatically remove blocked certificates



...some other quotes from the article above:

A new trend in adware and unwanted program purveyors is to install protection software that makes it more difficult for Windows users to run their security programs and clean infections. This was seen with the SmartService rootkit that blocked AV software from running and now with a protection program being called CertLock.

Since the end of May, security forum helpers have noticed reports that people are not able to install and run security programs on their infected computers. When they try to run the programs, they are greeted with an alert that states that the publisher has been blocked from running on the computer.

It turns out that this is being caused by CertLock disallowing a security vendor's certificate on the affected computer so that Windows does not allow the program to run.


CertLock disallows security vendor certificates
Being commonly detected as Ceram or Wdfload by anti-virus vendors, CertLock is distributed by unwanted programs bundles, such as miners. Once installed, CertLock will block a security vendor's certificate by adding them to a special Windows registry key. This causes Windows to not execute any programs that are signed with that certificate.

If a certificate is added to the Disallowed list, when a user tries to run a program that is signed by this certificate they will be greeted with an error that states "The publisher has been blocked from running software on your machine".
 
Last edited:

kamla5abi

Level 4
Verified
May 15, 2017
178
can we see manually through regedit where these disallowed certificates would be stored?
and if so, are they easily identifiable to see which companies are disallowed?

//edit
nvm, just read the article after posting lol
HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\
thats where those disallowed certificates are being written to
 

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
Thanks for sharing :)

That's the first time I heard malware uses this method to block security apps.
I just remember Sality used a DLL that tried to close any kind of process with possible associations with different security products, by terminating also the task manager and UAC.
 
  • Like
Reactions: LASER_oneXM

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top