menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Technology News

>

Avast secu...
source image

Tech Radar

1M

read

22

img
dot

Image Credit: Tech Radar

Avast security tools hijacked in order to crack antivirus protection

  • Hackers are using a legitimate Avast Anti-Rootkit driver to disguise their malware and turn off antivirus protection.
  • The malware belongs to the AV Killer family and uses a vector known as bring-your-own-vulnerable-driver (BYOVD) to infect systems.
  • The malware places a vulnerable driver named 'ntfs.bin' into the default Windows user folder and uses the 'aswArPot.sys' service to register the driver.
  • The malware includes a hardcoded list of processes used by common security products and uses the 'DeviceIoControl' API to end the process, disabling antivirus detection.

Read Full Article

like

1 Like

For uninterrupted reading, download the app