Showing posts with label Avast. Show all posts
Showing posts with label Avast. Show all posts

Sunday, 11 March 2018

Avast: Attackers CCleaner Also Wanted To Install keylogger



The attackers who hacked software company Piriform last year and added a backdoor to the popular CCleaner tool were also likely to install a keylogger on infected systems, according to anti-virus company Avast , which is the owner of CCleaner.

Last September, Avast announced that attackers had hacked CCleaner developer Piriform and added malware to the official version. This infected version was downloaded by 2.27 million users. The malware was added to the Piriform development platform between 11 March and 4 July 2017. The software company was acquired by Avast two weeks later on 18 July.

The first phase of the malware was to gather information about CCleaner users, such as the name of the computer, installed software and active processes. The second phase consisted of downloading additional malware. However, this was done with a select number of machines. Eventually, 40 computers received this additional malware. These included systems from major tech companies such as Intel, Samsung, Sony, Asus, NEC and the South Korean telecom provider Chunghwa Telecom.

There is no evidence that a third step has been carried out, but Avast has now found information indicating that it may have been planned. During the investigation into the hacked Piriform infrastructure, early versions of the first and second phase of the malware were discovered, as well as a tool called ShadowPad. ShadowPad is used by cyber criminals to control computers remotely. The tool was installed on four Piriform computers on April 12, while the second phase of the malware was already installed on March 12.

The older version of the second phase malware connected to a command & control server. The servers were no longer active at the time Avast analyzed the computers, so it is unknown what was downloaded, but given the time window it was probably ShadowPad. The Avast researchers also discovered ShadowPad log files with keystrokes from a keylogger installed on the computers. The keylogger had been active since 12 April and had stored keystrokes of all kinds of programs. The encountered version of ShadowPad appeared to have been specially made. Avast thinks that the attackers who had adapted especially for Piriform.

In addition to the keylogger, the attackers also installed a password builder and tools to install other software. According to Avast, there are no indications that ShadowPad is installed on the computers of CCleaner users. The virus fighter does state that it was the third phase of the attack. It is not known whether the attackers wanted to install the keylogger on all 40 attacked computers in the second phase, or just a few or not at all, this is still in under investigation.

Saturday, 14 November 2015

Leak In Smart TVs Vizio Gave Attacker Access To Home Network


More and more TVs equipped with so-called 'smart' functionality, but sometimes at the expense of security and privacy, so researchers at anti-virus company Avast investigated. The researchers looked at a smart television manufacturer Vizio, which recently due to transmission of the viewing habits came from users in the news.

During the study, there are several security issues with the television discovered. So the TV will connect to the domain control.tvinteractive.tv, but in doing so does not check the offered certificate. The researchers were thus able to perform a man-in-the-middle attack. Ultimately, they know how to physically examine the device to gain root access.

This ultimately gives enough information to send via the man-in-the-middle-server commands to the television, which then the home network can be attacked. It also appears that the television transmits information on viewer behavior, regardless of whether users with the terms of use and privacy policies are agreed at the time that the television was first established. After being informed by Avast Vizio has corrected the vulnerability. In addition, users can transmit their viewing via an option in the menu off.

Sunday, 1 November 2015

Lost Smartphones Often Cleared Through Factory Reset



Lost smartphones are often deleted from the factory reset and not be returned to the rightful owner, according to research by anti-virus company Avast. Five months ago the virus fighter intentionally 20 Android smartphones behind in New York City and San Francisco.

The aircraft were the Avast Anti-theft app, Lookout and Clean Master installed. Also, each smartphone contact information was provided. Four phones were returned, but 15 phones were deleted from the factory reset. 11 of the phones were more than 24 hours online after they were "lost" and seven of the phones did Avast follow some months. At the moment that Avast the data published, there were 4 out of lost phones, and in-line use. The virus fighter could monitor usage because the own app survived the factory reset.

Monday, 5 October 2015

AV-Test Lab: Linux User Without Virus


The amount of malware for Linux is still very limited, especially compared to Windows. Nevertheless, even Linux systems with malware become infected. In addition, Linux systems are often used in Windows environments and thus come into contact with Windows Malware. Astute Linux users, however, need to install a virus scanner, according to the German test lab AV-Test.

AV-Test decided 16 different security packages for Linux with both Linux and Windows Malware to test an Ubuntu system.The results are disconcerting for some products, because they are by letting 85% of the Windows Malware and up to 75% of the Malware Linux. Eight of the sixteen security suites able to detect between 99.7% and 99.9% of the 12,000 common Windows Malware. Only Symantec scores 100%. McAfee and Comodo scoring with 85.1% and 83% respectively lower.Much worse are the results from Dr. Web (67.8%), F-Prot (22.1%) and ClamAV (15.3%).

Tested for the second part of the test was 900 malware instances for Linux. Kaspersky'm here solely to detect all malware, followed by ESET with 99.7%. AVG scores 99%, followed by the server versions of Kaspersky and Avast that detect more than 98% of malware. Symantec, which identified all Windows Malware recognizes 97.2% of Linux Malware. The other products scored less well, with ClamAV, McAfee, F-Prot Comodo and finish at the bottom. The detection rates lie between 66.1% and 23%.

Linux And Malware


The question remains to what extent it is necessary for Linux users to install a virus. According to AV-Test, the number of Trojans for Linux has increased recently, but they are of poor quality. This is according to the test lab because attackers are aware of good security practices that Linux offers. There is then also especially the ignorance of users use, for example, which become infected by operational errors.

The most common way to become infected by Malware Linux is by installing software updates or via third parties, according to AV-Test. The software will ask during the installation to temporary root privileges. If the user allows this software to the system will be manipulated and attackers can install a backdoor on the system and is it part of a botnet.

According to AV-Test, most Linux users believe that they are one of the safest systems available use. "This statement is true if you only look at the system and leave the rest aside." Insecure third-party software and user errors can ultimately ensure that a Linux system, like Windows and Mac with malware gets infected.

Research by anti-virus companies shows that many infected Linux servers that are part of a botnet. Linux-based botnets often remain even longer operational because the servers do not use security software, unlike Windows Servers where this is the case. And if there is already software installed are often the wrong products. "In many Linux Forums free Comodo products, ClamAV and F-Prot be recommended to home users. This is not good advice", says AV-Test.

The test shows that home better for the free versions of Sophos or Bitdefender can choose. For server systems, there is the free scanner from AVG. ESET is as a whole out on top, followed by Symantec and Kaspersky. For servers are Kaspersky, AVG and Avast recommended.

Virus Scanner Necessary?

Or Linux Users must install a virus is ultimately to their own behavior. AV-Test says that security suites are only a second line of defense. The main security is in fact the user. Anyone who loves his system up-to-date, no unnecessary ports opens, only install software from trusted sources, prevents the browser to run active content and not open just e-mail attachments will do when it comes to Linux Malware no worries make, according to the testing lab.

Saturday, 15 August 2015

Kaspersky Accused Of Sabotage Anti-virus Companies


The Russian anti-virus firm Kaspersky Lab would have the virus for years of competing anti-virus companies sabotaged to show to clean files for malware, so important files were deleted or quarantined.

Let two former employees facing Reuters know. Kaspersky Lab, however, denies any wrongdoing. According to former employees, there was a secret campaign against Microsoft, AVG, Avast and other competitors that lasted for ten years. The plan would be carried out with the knowledge of Kaspersky founder Eugene Kaspersky. According to former employees, who wish to remain anonymous, Kaspersky found that the competition software imitated.

Microsoft, AVG and Avast showed earlier told Reuters that unknown parties in recent years had tried to cause false positives, such as the improper detection of clean files as malware is called. According to the former employees of Kaspersky were provided important files from malicious code, to upload them then to VirusTotal. This website Google scans files with dozens virus. Uploaded files are then shared with connected anti-virus companies.

If the malicious file seemed adequate to the original, the virus would clean file as malware can label. Microsoft says that in 2013 discovered thousands of these files and warned here at that time also ( pdf ). Kaspersky Lab said in a statement that it has never carried out such a secret campaign to mislead competitors with false positives. "Such actions are unethical, unfair, and if it is legal, at least questionable," said the Russian virus fighter.

Update

Eugene Kaspersky cites Reuters story on Twitter complete nonsense. "Usually I do not read to Reuters, but when I do I see false positives. This story was complete nonsense."

Saturday, 30 May 2015

Android Phone App Lets Look Unnoticed Porn


Google Play researchers again several malicious Android apps encountered after installing the device unnoticed kinds of porn sites and make visits to these sites to open multiple links and advertisements. In late April discovered anti-virus company Avast called "Dubsmash 2 app" on Google Play that was downloaded between 100,000 and 500,000 times before Google removed these.

Once the app actively trying to hide from the user and then visited several pornography sites in the background. Presumably the creator got paid for clicks that generated the app. Clicks that advertisers think they are carried out by people. Although Google removed the app there are recent days several variants of the app on Google Play appeared as late as anti-virus company ESET know.

Apps that should keep Google actually, say the researchers from the company. In a period of several days, several variants of the Trojan Dubsmash 2 uploaded and removed by Google. Yet one variant in two days would have been downloaded about 5,000 times. A total of nine discovered called Dubsmash 2 apps which were in reality "porn clickers". Once active every minute is charged a porn site, followed by a random click pattern.

"Although click fraud causes no direct harm to victims, such as to steal passwords, generates a lot of traffic and thereby generating additional costs for victims who have a data limit, so they remain at the end of the month with a high phone bill" , the researchers note. Which argue that Google Play has some weaknesses, given that the same malicious app could be placed several times on the app store before they intervened.

Wednesday, 22 April 2015

Users Turn Off Virus Because USB Malware


Malware that spreads via USB drives is still a major problem, but some users make cyber criminals very easily by ignoring warnings from their antivirus and even disable the security software. That informs anti-virus company Avast.

The virus fighter gives every day some 140,000 people a warning because the Jenxcus worm that was found on the USB stick. The malware last year was the target of a major operation by Microsoft, but is still active, which is also explained by some users. On infected USB drives the worm makes all kinds of shortcuts with the same names as the files that were already on the USB stick. However, the shortcuts point to the malware. Jenxcus also has backdoor capabilities, allowing attackers to gain access to the infected computer.

According Avast let most people remove the malware on their USB stick, but there is also a group that keeps alive and active infection. These users namely refuse to believe that there is a threat and argue that the virus has it wrong, says analyst Antonin Hyza. Then they turn off the anti-virus software so that the malware can infect their computer. One of the most common reasons to disable the virus scanner is that they use the file continuously or that it only involves an image. In the case of Jenxcus, however, refers to shortcuts. Once the computer is infected will infect the newly connected USB sticks again and the infection cycle can repeat itself.

Wednesday, 4 March 2015

IOS App Scans Password And Security Of WiFi Routers


Anti-virus company Avast at the Mobile World Congress in Barcelona announced an app for iPhones and iPads that checks the security of Wi-Fi networks. The free app searches for Wi-Fi networks in the area and then determine whether they are safe. Thus, among other things, to see whether the Wi-Fi router that the wifi connection offers used weak passwords, the WiFi network is encrypted and whether vulnerabilities are present in the router that attackers can exploit.

In the case of unprotected Wi-Fi networks put the SecureMe app a secure VPN connection. Make in case users with an open Wi-Fi network connection, this VPN connection will be switched automatically. The app is free, but whether this also applies to the VPN part is unclear. Avast will first organize a beta test of the app before it appears in the App Store.

Wednesday, 4 February 2015

Durka Malicious App: Apps On Google Play Store Infect Millions With Adware


Researchers have found several apps on Google Play that occur as games, but found to contain a million times and downloaded in reality adware. Some of the apps, including the card game Durka, activate the existing adware only after 30 days.

The adware ensures that when users unlock their device, they get a warning that their device is infected or outdated or full porn state. Then you will be asked to take action. If users are being redirected to come dubious apps and app stores herein secretly send text messages or collect all sorts of personal information. In some cases, users refer to security apps on Google Play.

Anti-virus company Avast thinks the adware distributors get paid for generating traffic to the apps and app stores. "Most people will not find out the cause of the problem and will have to deal with every time ads as they unlock their device," says analyst Filip Chytry. He thinks that most people end up trusting the solution offered, which can lead to more unwanted apps or costs. Besides Durka also involves an IQ test app and an app on the history of Russia. The apps are downloaded together between 5 million and 10 million times.

Hashes:

BDFBF9DE49E71331FFDFD04839B2B0810802F8C8BB9BE93B5A7E370958762836 

Thursday, 15 January 2015

Researcher Warns Of Software On Download.com


Download.com is a popular download site, but how secure is the software that is actually offered here?A researcher from How-To Geek decided the ten most popular programs from Download.com to install and startled by the result that he advises users not to repeat the experiment on their own computer. For the experiment, the programs were completely installed by default, as a typical user would do.

Download.com , which is part of CNet News, sets the policy that all downloads are offered free of adware, spyware or other malicious software. Many of the software appeared to be bundled with a variety of other programs. Via Download.com users can download the software directly, but there is also a Download.com -installer, which is much more apparent. This includes an installer that in addition to the desired program installs all sorts of other programs. It appears to include "browser hijackers" and fake "registry cleaners" to go.

Remarkably, the virus Avast is one of the first programs were installed and then some other downloads blocked because they were labeled as malicious. "Free software vendors to bundle earn almost all money through complete nonsense and scareware that mislead users to pay to clean up their PCs, regardless of the fact that you can avoid this by this" crappy "freeware nothing to install," says Lowell Heddings .

The experiment was repeated for several months and each time ended Heddings with other software on the computer. "Every software that unifies itself brings with it the same culprits: browser hijackers that hijack your search engine and home page and place ads everywhere because if the product is free, you are the real product.."