Security News Chinese AV Rising spreads Sality Virus via Signature update

Der.Reisende

Level 45
Thread author
Honorary Member
Top Poster
Content Creator
Malware Hunter
Dec 27, 2014
3,423
Note: The English in the article below is not good, but I did not find a better source.

So in short, if you use the English language version of RISING AV, uninstall it and check your system with an 2nd opinion scanner like HitmanPro or Zemana Anti Malware for possible infection related to an signature update of above mentioned antivirus product.

-------------------------------------------

An update of the virus scanner Rising helps, by an infected file, to spread the Sality virus .

Rising, a free virus scanner should be uninstalled fastest, the current update discharged the Salty virus on the system.

The anti-fours test lab AV-Test has found on their test systems strange activities that were infected by an update of the Rising scanner.
This was caused by an update of the virus scanner conscan.exe was then infected with the Sality virus.

Unfortunately, bringing not only updates new virus signatures but also new code with itself.
The Chinese manufacturer has now confirmed that advises and currently it to use from the scanner.

From Who guards are monitored?
Concern is of course the antivirus software offer this option because there is unfortunately before a real protection not.

Now, the obvious question whether or what updates are really needed, because the virus scanner Rising would actually have recognizable self.

Since this scanner is probably not as widespread in Germany, the problem should not be so overpowering.
The manufacturer has also worldwide sales recently hired.

Affected systems should be rapidly re-installed because some system files are also affected, and thus a stable operation cannot be derived even after adjustment by a different virus scanners.

The Original German article by HEISE Security can be found here:

Virenscanner infiziert Systeme mit Sality-Virus | heise Security
 

Der.Reisende

Level 45
Thread author
Honorary Member
Top Poster
Content Creator
Malware Hunter
Dec 27, 2014
3,423
Well that is different an AV spreading a Virus. :eek:
I would love to know how this can be, probably social engineering, making code injection possible. The Original source (HEISE) so far only states that RISING is a aware of the issue and suggests what I stated above.
@Kate_L thanks for letting me / us know, not aware of another incident.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Way back I've remembered that NetQin Antivirus for mobile is in hot water long time before for having malicious behavior on their product.

So Rising AV and its representation where a region is known for some sophisticated tactics, must aware for that warning.

Always read and check their backgrounds of a company.
 

conceptualclarity

Level 21
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 23, 2013
1,076
Who does use this AV anyway :p

For what it's worth, they have made it into some of the AV testing.

I think this is such a huge embarrassment for an AV company I don't know how they'd recover. But I think something like this happened to Combofix a few years ago, didn't it?
 
  • Like
Reactions: Der.Reisende

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
@Av Gurus: The English version of Rising AV is already dormant and dead.

However the local version isn't, so of course active only in the specific region compare to Qihoo which already international acclaimed product.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top