Skip to main content

New exploit uses antivirus software to help spread malware

Hacker
hamburg_berlin/Shutterstock
One of the most basic rules of safe web browsing is to use antivirus software in order to keep your computer safe. While it’s a good idea to make use of such software, but a recently discovered exploit proves that even the best antivirus software is not fool proof.

Nicknamed AVGater by Austria-based security consultant Florian Bogner, the exploit takes advantage of the “restore from quarantine” function found on many antivirus programs. The concept behind the exploit is fairly simple one. It allows a user to move a piece of malware from the quarantined folder to somewhere else on the victim’s computer, allowing the malware to be executed.

Recommended Videos

Bogner uploaded a video that provides more information on how the exploit works.

Please enable Javascript to view this content

Under normal circumstances, the restore from quarantine function would not allow a non-administrator to write a file to the computer’s C:\Program Files or C:\Windows folders, but this attack takes advantage of Windows’ NTFS function to grant the user access to these folders.

As impressive as this all sounds, there is one major flaw which will drastically limit the scope of this exploit. In order to do any of this, the hacker in question must physically be at the computer they wish to infect. Given that most malware is spread via the internet, it is unlikely that this exploit will cause major problems.

Enterprise computers could be the devices most at risk to this sort of attack. While we don’t see it being a widespread problem, it’s feasible that a disgruntled employee could decide to get a little revenge, though such cases are rather limited in nature; most people won’t risk their jobs or prison for such a stunt. That being said, Bogner offered a simple fix to this problem by simply disabling the remove from quarantine feature on enterprise computers.

In terms of antivirus programs, Bogner has notified the vendors of the various software which contain this flaw and many have already rolled out patches to fix this issue.

Exploits such as this are found from time-to-time, but that shouldn’t dissuade users from installing antivirus software as it remains one of the best, though not unquestioned, ways to keep a computer safe from malware and other issues.

Eric Brackett
Former Digital Trends Contributor
This new threat proves that Macs aren’t immune from malware
A concept image of a hacker at work in a dark room.

Despite constant warnings, many Mac users have come to believe their computers are safe from malware attacks. A new threat targeting Mac users called Banshee Stealer, however, refutes that notion. As reported on by security firm Elastic Labs, Banshee Stealer targets popular browsers and crypto wallets and even attempts to steal data from iCloud Keychain passwords and Notes.

"Banshee Stealer targets a wide range of browsers, cryptocurrency wallets, and around 100 browser extensions, making it a highly versatile and dangerous threat," Elastic Security Labs said in a report on Thursday.

Read more
As a reviewer, here’s why I recommend Norton over McAfee for most people
The McAfee and Norton websites are open in a split-view on a PC monitor.

McAfee and Norton are among the best antivirus software solutions. Since they share similar features and pricing, it can be hard to know which to pick to keep your computer safe from the ongoing threat from hackers.

I recently reviewed Norton 360 Deluxe and McAfee+ Premium antivirus, so I can share some insights about ease-of-use, functionality, and customer service to help you decide which antivirus app works best for your needs and budget.
Tiers and pricing

Read more
This is the one password manager I recommend using over 1Password
Keeper and 1Password websites appear in a split-screen view on a PC monitor.

The best password managers simplify sign-ins while keeping your account information secure. Two of the best solutions come from Keeper and 1Password.

I recently reviewed both solutions, comparing login organization and sharing features, support responsiveness, and overall ease of use to find out which offers the best value for you.
Tiers and pricing
Prices for Keeper and 1Password are shown above in a split-screen view. Digital Trends

Read more