LNK Files – Shortcuts to Faster Infections

lnk_shortcuts_system_drive

Tags :- Avira Tech Support | Avira Support NumberAvira Refund.

These shortcut files are actually called Shell link files. Microsoft filename extension: “.LNK”

Let’s dig a little deeper and check the typical properties of an example LNK file. Just right click on the shortcut and then select “Properties. There are now several options which can be changed. In this case we will focus on the “Target” field which contains the path to the application or folder.

“C:\Program Files (x86)\Avira\Avira Antivirus\avcenter.exe”

Looks easy, right? When you click on the shortcut it performs the command specified here. In this case our trusted Avira Antivirus is being launched. This is actually what you can expect and want when clicking on a shortcut.

Unfortunately these shortcut files also have drawbacks since you don’t know exactly what hides behind them without explicitly looking. At Avira we are currently seeing a trend that more and more malware threats are using this kind of propagation method. You can follow this and more trends by visiting our Avira Threats Landscape.

Malware authors are starting to use this method because nowadays most novice users might know that clicking on a suspicious executable file might be dangerous for their systems. But clicking on a shortcut is normally not associated with bad behavior.

I like to show you how malware is actually misusing the usually helpful LNK files by giving an example of an actual in-the-wild malware detection named: VBS/LNK.Jenxsus.Gen

This variant uses LNK files to spread an infection via removable drives. The trick is very simple since it actually creates shortcuts to your files and folders stored on the USB stick and then hides the originals from you.

Let’s see what a folder structure looks like once the USB drive is infected.

Folder View of an infected USB drive:

Folder View of an infected USB drive

Nothing unusual here at first glance, right? Except maybe that the icons have all a small arrow in the bottom left corner which indicates that they are actual shortcut files. But you can still access all your files and folders when clicking on them.

We will now take a closer look at what actually is hidden behind the shortcut files by telling the Windows Explorer that we want to see all “Hidden system files”

Directory view with “Hidden System files” shown.

Directory view with “Hidden System files” shown.

When we focus on the “avira-logo” you can see there are actually two files there. One is the LNK file and the highlighted one is the actual “hidden” jpg image file.

This means when you click on a trusted file on the USB drive you are actually clicking on the shortcut which will execute the following command stored inside the LNK target instead of just opening the image.

C:\WINDOWS\system32\cmd.exe /c start dlbfbiicvg.vbs&start avira-logo.jpg&exit

Target path of an infected LNK file.

What this command does is silently execute the malicious “dlbfbiicvg.vbs” via cmd.exe and then use the “start avira-logo.jpg” to open the file you clicked on to avoid any suspicion.

Additionally the malware also adds Run-Key entries to the Registry to infect other USB drives if they are plugged into the system.  This makes also sure that the malware gets executed with each system boot.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] dlbfbiicvg”=”wscript.exe //B \”C:\\DOCUME~1\\USERNAME\\LOCALS~1\\Temp\\dlbfbiicvg.vbs\””

Example of a malicious Run-Key added by the malware.

The filename and the Registry value of the Run-Key are always randomly generated by the malware on an infected system.

At last the malware can also deploy a backdoor on your computer to send out information about the operating system, sites you visited and so on.

USB drives are still popular because there are very convenient way to transfer large files from one location to another especially if you have limited internet bandwidth available.

So if you want to share some data with a family member or friend, be very careful when you plug-in your USB drive into an unprotected computer. Your USB drive might get infected or vice versa you could spread the infection from your USB drive to his computer.

Of course nobody has the time to check every shortcut this closely before clicking on it.

One easy solution is to use our Avira product which automatically scans for malicious content and will protect you from this kind of malware threat.

Source : blog.avira.com

Avira Tech Support : Blog

Sharing and the fine art of stopping malware

stop_malware_using_avira

Tags :- Avira Tech Support | Avira Support NumberAvira Refund.

There are an array of technical and business issues that have to be solved: What format do the files need to be in? Who pays for the bandwidth? And the list goes on and on.

Regardless of these technical issues, there are a number of advantages to sharing – particularly for the average computer user. This user – let’s call him Joe Six-Pack – gets much faster and deeper information about any potential threats than if he kept news of his malware misadventures all to himself.

Just from the perspective of Avira, cooperation has its organizational costs – but brings clear benefits down the road.

Avira was one of a “Gang of Five” security companies that set up MUTE, the Malware URL Tracking and Exchange back in 2008.

Avira web developers were volunteered by the company and shared their expertise to set up the backend infrastructure for the group’s members to combine and share their collections of malicious web addresses. The initial outline of Avira’s system specs could be placed on four PDF slides. Today, the system is far more complex and requires a whopping 44 slides to describe its operations. And that is not all of the sharing. Avira also founded VIREX, a web-based application for helping security analysts organize their bits and pieces of malicious code, clean samples, and URLs. Yes, Avira is proud of its sharing efforts.

But you could still ask, what does Avira get out of its investment in sharing — addition to fresher bits of malware? I can think of two primary benefits.

1. Greater back-office expertise in coordinating data flows.
2. Experience in collaborative working outside of the company environment.

Put these two advantages together and there is a third one:

3. Avira expertise that can fit under the banner of other companies as an OEM product.

That is exactly what we have done with the recently announced Lavasoft deal. We’ve licensed our new  Avira URL Cloud (MURL) and program classification service (AUC) to Lavasoft and they’ll  use this to beef up the security levels in their Ad-Aware Web Companion.

Sharing is a good thing – whether in a real or a virtual sandbox.  It makes life a better, richer, and yes, more secure experience.

Source : blog.avira.com

Avira Tech Support : Blog

Infected Apps in AppStore: How safe is your iOS device?

avira-free-antivirus-for-mac-main-window

Tags :- Avira Tech Support | Avira Support NumberAvira Refund.

Recent discoveries which were made by security researchers from PaloAlto Networks and Fox-IT brought to light an important number of malicious applications available in AppStore.

In the last couple of months, Apple has repeatedly stated that its mobile OS is one of the safest (if it’s not even impenetrable) and that due to their rigorous approval process, no malicious app can be found on the App Store …. They couldn’t be more wrong.

Even if the applications which were discovered as being malicious were not necessarily containing viruses, they behaved either as spyware (by stealing passwords, capturing some sensitive device information etc.) or on a more serious note as ransomware as they could have received commands from attackers to inject the victim’s device clipboard with data, open specific URL’s or prompt fake alerts on the user’s screen.

Again, it looks like security on iOS devices is not perfect and even if malware in a traditional sense is not present there, the users of iDevices are vulnerable to having their private data stolen … This is the next area where security companies like Avira are striving to protect the users and protect their privacy at all costs.

Available for all iOS users,  Avira Mobile Security notifies you whether your email (and your contacts’ email addresses) have been breached and if your credentials were stolen (on various sites where the customer’s registered with them). Downloading it looks like a pretty great first step for those who want to start taking their iDevice security more seriously.

Source : blog.avira.com

Avira Tech Support : Blog

Serialization vulnerability: 6 in 10 Android devices can be hijacked

Tags :- Avira Tech Support | Avira Support NumberAvira Refund.

If one day, you were asked by your dearly trusted Facebook Messenger app to log in because your session had expired, would you do that? If the answer is yes, you might have just shared your Facebook credentials with an impostor app disguised in, otherwise legit, Facebook Messenger app. A group of researchers at IBM revealed a vulnerability in the Android OS that allows evil-witted guys to mischievously replace an application you trust with something that resembles it but is meant to cause you harm instead.

“In a nutshell, advanced attackers could exploit this arbitrary code execution vulnerability to give a malicious app with no privileges the ability to become a ‘super app’ and help the cyber criminals own the device,” IBM said. The ‘Serialization’ vulnerability is explained in great detail in the paper titled “One Class To Rule Them All“.

Google provided patches that address the exploit, but their way to the end users’ devices is gonna be slow-paced and toilsome, since there are device manufacturers in-between.

As mobile addiction continues to rise, we are paying less and less attention to the legitimacy of the apps we’re installing, while relying fully on the “need an app for this purpose now” impulse. Latest discoveries in terms of vulnerabilities and exploits, plus unfortunate examples of personal data leakage fortifies the need for an increase awareness in consumers rows.

To play it safe, we at Avira highly recommend to use an advanced mobile security solution, such as Avira Antivirus Security and only download applications from trusted sources.

Source : blog.avira.com

Avira Tech Support : Blog

Mac AV ready for OS X 10.11 alias El Capitan

Mac_Av_ElCapitan

Tags :- Avira Tech Support | Avira Support NumberAvira Refund.

 Codename: Made in California

Named after a vertical rock formation in Yosemite National Park, the latest version of operating system suggests that there are no major changes compared to the previous version of OS owing to the close geographical proximity of their names.

This is probably true, as long as you’re talking about the small changes to the design or the improvements to window management and the integrated apps. Lift the hood though, and you’ll see Apple has prepared an OS upgrade that is designed to offer stability and security with performance enhancements and Rootless mode, which protects system-critical files from being written to even by the root user.

Apple shows openness regarding update policy

Apple changed its update strategy right from OS X Mavericks and now issues its new OS X versions free each year. Ever since OS X Yosemite, the OS Developer Preview which accompanies Apple’s annual keynote has also been followed by a public beta which gives every  interested user access to the latest OS X version. This increases pressure on developers as nobody wants to deal with the shame of having a substandard program that attracts bad press.

At Avira, we not only follow the keynote on our screens with a huge amount of excitement – we also test the Developer Preview the very next day with our Mac AV product to give recommendations to the tech-savvy users of our products as soon as possible. Testing Developer Previews in good time is just as essential as resolving any issues. Precisely this needed to be done the last time OS X Yosemite was updated.

With this update, Apple made it mandatory to sign kernel extensions. The kernel extension of Mac AV was affected. This makes real-time protection possible, and it just refused to work. You’d think it’d be as easy as signing the kernel extension and sending it off to the customer, wouldn’t you? Well, it didn’t turn out to be as straightforward as that.

The development cycle

This is because quite a bit of time passes from the moment a developer starts to update the source code until an update is released to the customer. First, development takes place in a two-week rhythm. This results in an improved product that can pass the test-automation process – during which the product is really put through its paces. Following that, it is presented internally at Avira and handed over to the Avira Beta Center the very same day.

The Beta Center is a curious place where volunteers try out Avira’s latest products and provide qualitative feedback to support our developers in improving our product. If you’re interested in contributing toward improving Mac AV, please sign up – we’ll take all your feedback on board.

Following the two-week beta phase, we usually let the product rest for a further week before releasing it to the end customer at the end of the three-week development period. That’s the theory anyway. As we’re also still in a development phase, this period may extend to five weeks.

Talking about the current example of the public beta of OS X El Capitan, things are getting a bit tight. As the initial Developer Preview released on June 8 was followed four weeks later by the public beta, and as our Mac AV product entered beta testing on July 15, this meant a week had already passed since the public beta of El Capitan appeared until we were able to provide a copy of Mac AV to our tech-savvy users with a clear conscience that it also ran on Apple’s beta version. For everyone else, this version will be issued three weeks later on August 4.

Mac AV OS X 10.11

Ready for fall release

We are well prepared to deal with any eventuality in advance of this fall’s wide-scale roll out of OS X El Capitan . If you want to take part in Apple’s public beta or are interested in product development, we recommend joining the Beta Center to ensure maximum compatibility with Apple’s beta versions.

Source : blog.avira.com

Avira Tech Support : Blog

How safe are the apps on your Android ?

andriod-avira -security

Tags :- Avira Tech Support | Avira Support NumberAvira Refund.

Privacy Advisor

As the name suggests it, the newest feature offered by Avira Antivirus Security for Android allows registered users to increase the level of privacy on their smartphones and tablets by avoiding and potentially uninstalling high risk apps.

The apPrivacy advisor - android appsps that are most likely to be included in this category ask for very sensitive and personal data related permissions during the installation process.

In worst cases, malicious apps can take advantage of SMS permissions to send premium messages and register users for unwanted services, sometimes leading to financial losses.

Even if there are applications that may have an important impact on the users’ privacy, some of them have a high number of permissions related to personal data because their purpose of being demands them. These applications may either be trusted by Avira itself (e.g. Community Trusted applications) due to the developer’s reputation and/or high number of downloads or can be trusted by the user himself if he knows for a fact that the app is not a security risk.

Coming soon… on Android Optimizer

Three months after releasing its Android Optimizer app, we already helped almost 500.000 users optimize the overall speed and performance of their mobile devices. Following users’ feedback, the app has already been localized to three more languages (French, Italian and Portuguese), making it easier to use.

In order to make the app even better, our mobile development team will soon release a version that supports an always-on widget, enabling users to instantly optimize their devices, at the tap of the screen.

12 million downloads and numerous awards

Avira’s efforts of enhancing mobile security are paying off, as Avira Antivirus Security for Android excels in all Independent Labs Test results. Only last month, AV-Test nominated Avira as “The best antivirus software for Android”, with 100% detection rates and a total score of 6/6 on Protection and Usability. PCSL also awarded 5 Stars for Avira in the April edition of its Android Malware Detection Test.

More than that, 12 million users have already downloaded Avira Antivirus Security for Android, making this the best reward for the Product team.

“Avira users should feel safe and protected on every device they use to connect to the Internet. My team has the important mission of securing their mobile devices and preventing all types of attacks from happening. As private data becomes an easier target on smartphones and tablets, protecting the users’ privacy is a top priority for us. We strongly believe that a feature like “Privacy Advisor” will make it easier for people to know which app is interested in their personal information and gives them the power to decide if they agree to share it or not” said Corneliu Balaban, Mobile Development Manager at Avira.

The newest version of Avira Antivirus Security for Android (version 4.1.3643) was uploaded on the Google Play Store and can be downloaded for free.

Source : blog.avira.com

Avira Tech Support : Blog

Avira Threats Landscape: Visualizing threats for you

avira_threats_landscape

Tags :- Avira Tech Support | Avira Support NumberAvira Refund.

Every day, thousands of different malicious programs are trying to infect as many devices as possible. The goal is the same for all of them: Get your data and if possible your money as well.

We have always been the firsts to learn about the threats that loom over every owner of a PC, Mac, tablet, or smartphone, but us having all the insights is not enough. While studying threats, keeping an eye on where they appear, and adapting our programs accordingly makes sure we keep our users as safe as possible, it’s still complicated to explain to the rest of the world why being protected is that important.

Sure, one reads about the newest threats, but only other people are affected by them, right? Especially big companies or governmental institutions seem to be the targets, so why bother at all. And that is where people are wrong. While the media most often talks about high profile cases, everyone else is at risk just as well! Every day there are millions of threats which have only one goal, namely to infect your devices. Be it your smartphone, laptop, Mac or PC – each and every one of them is at risk. Just think about the latest iOS and OS X exploits or the different ways cyber criminals try to gain control over what’s on your computer.

In order to make our point we decided to share our insights with you in form of an interactive map. Our Avira Threats Landscape allows you to not only see which countries are the top targeted ones but also which threats are popping up the most and how many threats were detected in your country. Take a look at it, you won’t regret it. And when you see just how far reaching and widespread those threats are, make sure to warn your family and friends as well.  The most important thing though: Stay protected!

Source : blog.avira.com

Avira Tech Support : Blog

Give your PC some superpowers By Using Avira Antivirus

Avira-Antivirus-2017-Latest-Version-15.0.25

Tags :- Avira Tech Support | Avira Support NumberAvira Refund.

So now that I got this out of the way, here are two important observations by Captain Obvious:

1: This blog post is about shameless self-promotion.

2: You’ll be safer (and perhaps mildly amused) after having read it.

So here’s the newsflash: we’ve just launched a superhero campaign that’ll unleash your PC’s superpowers: www.avira.com/en/try-superpowers

The campaign offers our free Antivirus software, as well as free trials to premium software. Take a look at the short descriptions for your PC’s new superpowers:

Strength

Wield superior PC protection, forged deep within the A.V.I.R.A. labs. The process of forging summons otherworldly code, to withstand attacks from any breed of alien forces

Speed

Be one with an accurate, effective weapon – able to navigate and propel you with supersonic speed through cyberspace. Your PC will be faster, your boot up time—shorter, your streaming—smoother, your PC—cleaner and you’ll even free up space on your hard drive.

Stability

Control and stabilize your PC’s elements, with a driver updater tool that’s forged from the remnants of a star. Your hardware will run smoother, your gaming will be faster and it will help prevent system freezes and crashes.

And of course, the page gives you the option at the bottom to share it with your friends and family – just in case you don’t begrudge them your new-found superpowers.

Source : blog.avira.com

Avira Tech Support : Blog

Ex-NSA Guy Points to Mac Security Flaws

nsa-mac-security-flaws

Tags :- Avira Tech Support | Avira Support NumberAvira Refund.

Whereas Apple develops its iOS with security a part of the process, with OS X development security seems to be more of an afterthought. ‘Bug bounty’ programs are one direction suggested for Apple, but until there is a change in the current approach, the vulnerabilities remain open to any would-be hackers.

At the recent RSA Conference in San Francisco, Wardle gave a presentation titled “Writing Bad@ss OS X Malware,” in which he challenges Apple’s OS X developers to change their way of thinking – especially considering that the majority of the malware getting into Macs (now measuring hundreds of thousands) is “amateur, even basic,” according to Wardle.

More advanced Mac attacks, such as the ‘Rootpipe’ backdoor, have been difficult for Apple to patch, and failed ‘fixes’ have been covered by thehackernews.com, computerworld.com, securityweek.com, forbes.com, and others in the first half of 2015.

AV-Test, a leading independent computer security testing firm, recently tested 10 different Mac OS X security software packages (you can read the full report here), writing that:

“The legend that Mac OS X is supposedly invincible is not borne out by the facts. In the aftermath of major attacks by Flashback, the police Trojan Browlock or Shellshock, the number of assaults on Mac OS X continues to increase.”

In AV-Test’s analysis, Avira Free Antivirus for Mac earned a 100% detection score against 160 new Mac-specific viruses and malware. If you’re taking chances with no security on your Mac, do yourself a favor and take care of it right now.

Source : blog.avira.com

Avira Tech Support : Blog

Avira In Free Security Package By Deutsche Telekom

avira-rescue-system

Tags :- Avira Tech Support | Avira Support NumberAvira Refund.

At Ce Bit in Hanover, T-Systems CEO Reinhard Clemens said: “Customers are often unsure when it comes to security software. Since the Snowden revelations, they are also anxious and asking for a ‘made in Germany’ protection solution. Deutsche Telekom wants to make it easy for as many people as possible to secure their smartphones and computers. That is why we are expanding our existing offering to include an easy-to-install package version from Germany.”

Our very own Avira Antivirus will take care of the security part of said package and protect your Windows PCs and Macs, smartphones and tablets with the iOS and Android operating systems, and servers and networks against malware, using an integrated real-time scanner. Thanks to its cloud-based scanning Avira Antivirus achieves unparalleled security and lightning fast performance. Of course it also reliably scans your downloads, folders, and hard disks.

“Avira Browser Safety” will be included in the package as well. The browser extension protects personal information when surfing the internet and blocks malicious websites as well as tracking by advertising networks, so that they can no longer track what a user is searching for or purchasing online.

Source : blog.avira.com

Avira Tech Support : Blog