A new virus has been detected which modifies the settings on the computers affected by it and begins to display Avira websites on Google Chrome and Mozilla Firefox web browser. The virus is believed to be a bit more sophisticated as it also performs multiple other activities on compromised computers such as blocking the victims to type with their keyboards and other. At the moment nobody can find out why it links a legitimate Avira antivirus web page. If your computer has become victimized by the Ame.Avira threat, we recommend you to read the following article.
|Type||Browser Hijacker, PUP|
|Short Description||Advertisements generated from this platform can display on other sites and redirect you.|
|Symptoms||You see adverts in your browsers, like pop-ups or other ads. Slow computer and other suspicious behavior.|
|Distribution Method||Freeware Installations, Bundled Packages|
|Detection Tool|| See If Your System Has Been Affected by Ame.Avira |
Malware Removal Tool
|User Experience||Join Our Forum to Discuss Ame.Avira.|
How Does Ame.Avira Enter Your PC
One method, used by this antivirus program is to be slithered into your computer via installers of programs, more specifically system patches. One of those patches is for Minecraft Alpha which when started closes automatically the launcher and begins to redirect users to the Avira websites. The legitimate antivirus Avira is not familiar with such programs and it is unclear yet why their web pages are the ones being displayed. However, the theory exists, that if someone has entered an affiliate program and one of the tools advertised via it is Avira’s antivirus program, he or she may be making money by simply opening this web link on the computers infected with the Ame.Avira virus.
Ame.Avira Virus – Further Details
The main URL of the sites which are automatically opened on the victims computers begins like the following:
This is a strong indicator that this very web link passes through one domain after which redirects to the official Avira web page, where you can purchase all their antivirus products:
As you may be well aware, Avira offers great antivirus protection and is in our Top 3 of the best antivirus software on the market, according to SensorsTechForum’s report. The site itself is safe to use and we have strong reasons to believe that someone has likely engaged in an affiliate scheme to generate revenue by causing web browser redirects on the computers infected by his/her virus.
When victims infected with the Ame.Avira threat have scanned their computers, multiple suspicious files with completely random name were found in the %UserData% directory of Google Chrome, located in:
→ %AppData%\Local\Google\Chrome\User Data\Profile 1\
In addition to modifying the web browsers by creating files deep within their directories, the suspicious software also makes modifications in the following registry sub-keys:
Judging by the random names, Ame.Avira virus probably creates a suspicious browser extension to run in the background of your Mozilla Firefox or Google Chrome web browser. In addition to this, the search plugin may also be changed, because the virus creates the file avira-safesearch.xml in the %Profiles% directory of the browser.
In addition to heavily displaying the Avira web page, the virus may also use tracking technologies to collect your information and may even steal:
- Saved logins.
- Browsing history.
- IP and MAC addresses.
- Unsecured ports.
- Other exposed credentials.
How to Remove Ame.Avira Virus Completely
In order to completely delete this virus, you have to remove every single object created by it on your computer. In addition to this, you must completely clean your web browsers off the Ame.Avira virus. We have created a removal manual which can help you cope with those activities below, but in the event that you are experiencing difficulties or feel unsure that you have removed all objects, it is advisable to take the automatic approach. Experts often advise victims to use an advanced anti-malware software in order to perform the removal process automatically and protect your computer against such malicious objects in the future as well.