Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Yes—software labeled adware or a potentially unwanted program (PUP) can disable antivirus defenses. In March 2025, an update delivered through signed Dragon Boss Solutions LLC software installed a PowerShell payload that interfered with security tools, blocked their update domains, established persistence, and added Microsoft Defender exclusions. Huntress sinkholed unregistered update domains before another operator could control them. The investigation demonstrated a dangerous delivery capability, but it did not establish that this campaign deployed ransomware.

What happened in March 2025

Huntress began seeing alerts in managed environments on March 22, 2025. Investigators traced the activity to software signed by Dragon Boss Solutions LLC and using Advanced Installer’s automatic-update mechanism. The update installed a PowerShell script named ClockRemoval.ps1.

Huntress found unregistered domains in the update configuration. It registered those domains and pointed them to a sinkhole, allowing investigators to observe infected systems’ connection attempts instead of letting an unknown party operate the update endpoint. In a controlled lab, Huntress also supplied a test payload and confirmed that the silent update path could install it under the tested conditions.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the updater became an endpoint-security threat

Security-tool interference

The payload disabled or interfered with security applications and blocked domains used by security vendors for updates. That combination can leave a machine with weakened protection and stale detection components.

#1 Best Overall
Bitdefender Total Security 2026 – Complete Antivirus and Internet Security Suite – 5 Devices | 1 Year Subscription | PC/Mac | Activation Code by Mail
  • SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows (Windows 7 with Service Pack 1, Windows 8, Windows 8.1, Windows 10, and Windows 11), Mac OS (Yosemite 10.10 or later), iOS (11.2 or later), and Android (5.0 or later). Organize and keep your digital life safe from hackers
  • SAFE ONLINE BANKING: A unique, dedicated browser secures your online transactions; Our Total Security product also includes 200MB per day of our new and improved Bitdefender VPN
  • ADVANCED THREAT DEFENSE: Real-Time Data Protection, Multi-Layer Malware and Ransomware Protection, Social Network Protection, Game/Movie/Work Modes, Microphone Monitor, Webcam Protection, Anti-Tracker, Phishing, Fraud, and Spam Protection, File Shredder, Parental Controls, and more
  • ECO-FRIENDLY PACKAGING: Your product-specific code is printed on a card and shipped inside a protective cardboard sleeve. Simply open packaging and scratch off security ink on the card to reveal your activation code. No more bulky box or hard-to-recycle discs. PLEASE NOTE: Product packaging may vary from the images shown, however the product is the same.

Persistence through Windows components

Huntress observed Windows Management Instrumentation (WMI) event subscriptions and scheduled tasks designed to rerun the activity after system events, boots, logons, or at intervals.

Defender exclusions

The script added Microsoft Defender exclusions for directories associated with possible future payloads. An exclusion does not itself prove that a second payload was present, but it creates a location that routine scanning will skip.

Rank #2
Sale
Norton 360 Deluxe 2027 Antivirus, 5 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.

An exposed update path

Because the configured update domains were not registered, whoever controlled them could potentially have supplied arbitrary follow-on content. Huntress demonstrated that delivery capability in its lab; the public report does not prove that ransomware, a botnet, or another follow-on payload was delivered during this campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How widespread was the activity?

During a 24-hour observation period, Huntress recorded connections from 23,565 unique IP addresses. This is an observed IP count, not a confirmed count of people or a census of every infected computer. The addresses came from 124 countries and all continents, according to Huntress.

Rank #3
Sale
Norton 360 Premium 2027 Antivirus, 10 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 10 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
Location or network category Observed count Share or detail
United States 12,697 53.9%
France 2,803 11.9%
Canada 2,380 10.1%
United Kingdom 2,223 9.4%
Germany 2,045 8.7%
High-value target networks 324 221 universities and colleges; 41 operational-technology networks; 35 government entities; 24 primary and secondary schools; 3 healthcare organizations

Huntress also observed infections in multiple Fortune 500 company networks. These classifications were based on the networks associated with observed IP addresses, so they should not be read as a precise count of affected organizations.

What to check for on a Windows computer

Huntress published investigation leads. None is a universal signature or conclusive proof by itself; examine timing, parent processes, network activity, and other evidence around each finding.

Rank #4
Sale
McAfee Total Protection 2027 Antivirus Software for 3 Devices | Auto-Renews
  • THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
  • PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
  • SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
  • GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
  • MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
  • WMI event subscriptions with consumer names containing MbRemoval or MbSetup.
  • Scheduled tasks that reference WMILoad directories or ClockRemoval scripts.
  • Task names such as ClockSetupWmiAtBoot, DisableClockServicesFirst, DisableClockAtStartup, RemoveClockAtLogon, and RemoveClockPeriodic.
  • Processes or binaries signed by Dragon Boss Solutions LLC.
  • Windows hosts-file entries that block security-vendor domains.
  • Unexpected Defender exclusions for %LOCALAPPDATA%DGoogle, %LOCALAPPDATA%EMicrosoft, %LOCALAPPDATA%DDapps, %ProgramData%Chromnius, or %ProgramData%ChromniusEdge.

What administrators should do if they find indicators

  1. Contain the host. Isolate a suspected computer from the network using your organization’s incident-response procedure, while preserving relevant forensic data.
  2. Confirm the surrounding activity. Review WMI subscriptions, scheduled-task creation, PowerShell execution, Defender configuration changes, hosts-file edits, and outbound connections rather than treating one artifact as definitive.
  3. Search broadly. Hunt the listed artifacts and Dragon Boss-signed binaries across endpoints, servers, and management systems; include systems that reported a PUP alert.
  4. Restore security controls safely. Remove unauthorized persistence and exclusions only under a documented response plan, then verify that security services and update connectivity work normally.
  5. Escalate when necessary. If security tools were disabled or administrative credentials may have been exposed, involve your incident-response or managed-detection team and follow your organization’s credential-reset and recovery procedures.

Can a software updater deliver malware?

Yes. An updater is a privileged software-delivery channel, so its trust depends on the signing, update configuration, domain ownership, transport, and validation controls behind it. A signed application can still become dangerous if its update path points to an unregistered or otherwise hijackable domain. This incident shows why endpoint monitoring should watch updater behavior, persistence creation, security-service changes, and Defender exclusions—not just the original product’s marketing label.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this incident does—and does not—prove

  • Established: a Dragon Boss-signed application delivered a PowerShell payload; Huntress observed antivirus interference, blocked security-update domains, WMI and scheduled-task persistence, and Defender exclusions.
  • Demonstrated in a lab: the silent update mechanism could install a supplied payload under the tested conditions.
  • Observed at scale: 23,565 unique IP addresses contacted Huntress’s sinkhole during 24 hours, spanning 124 countries.
  • Not established by the cited reporting: that this campaign delivered ransomware, a botnet, or another specific follow-on payload.

The Bottom Line

Adware and PUP labels describe classification or consent, not a safety guarantee. The Dragon Boss incident turned a routine-looking signed updater into a mechanism that could weaken antivirus defenses and persist on Windows systems; investigate the published artifacts as a potential security incident, while keeping the documented capability distinct from unproven ransomware claims.

Best Value
Sale
Webroot Antivirus Software 2026 | 3 Device | 1 Year Download for PC/Mac
  • POWERFUL, LIGHTNING-FAST ANTIVIRUS: Protects your computer from viruses and malware through the cloud; Webroot scans faster, uses fewer system resources and safeguards your devices in real-time by identifying and blocking new threats
  • IDENTITY THEFT PROTECTION: Protects your usernames, account numbers and other personal information against keyloggers, spyware and other online threats targeting valuable personal data
  • REAL-TIME ANTI-PHISHING: Proactively scans websites, emails and other communications and warns you of potential danger before you click to effectively stop malicious attempts to steal your personal information
  • ALWAYS UP TO DATE: Webroot scours 95% of the Internet three times per day including billions of web pages, files and apps to determine what is safe online and enhances the software automatically without time-consuming updates

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.