Rogue AV uses legitimate uninstallers to cripple computers
Posted on 20.08.2010
The fact that some rogue AV solutions try to prevent the real ones from doing their job is widely known in the security community, but CoreGuard Antivirus - a "popular" fake AV solution - has been spotted utilizing legitimate software uninstallers to trick users into uninstalling their legitimate security software.

When the malicious file is executed, a message box like this one opens up:


Clicking on the "OK" button - or even on the "Close" button - starts the installer of the antivirus in question. Symantec researchers reveal that the fake solution searches for uninstaller information in the Windows registry and launches the right uninstaller for certain legitimate AV solution installed on the system, such as products from Microsoft, AVG, Symantec, Spyware Doctor, and Zone Labs.

It then tries to download "AnVi Antivirus", another rogue AV that is actually a clone of CoreGuard Antivirus.






Spotlight

The evolution of backup and disaster recovery

Posted on 25 July 2014.  |  Amanda Strassle, IT Senior Director of Data Center Service Delivery at Seagate Technology, talks about enterprise backup issues, illustrates how the cloud shaping an IT department's approach to backup and disaster recovery, and more.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Mon, Jul 28th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //