Author Topic: Pixum (Photo album software): Ransomware-Protection  (Read 2396 times)

0 Members and 1 Guest are viewing this topic.

Offline pustekuchencake

  • Newbie
  • *
  • Posts: 4
Pixum (Photo album software): Ransomware-Protection
« on: February 07, 2021, 10:53:21 PM »
Dear Avast-Team,

I hope it's the correct way to inform you:

Since yesterday I get a ransomware warning while using a well-known German photo-album software, called Pixum Fotowelt by Cewe.
As I'm using it very often during the last weeks, I can tell, that it didn't happen using it last weekend. Yesterday I wanted to go on modifying my photo album and here it happend for the first time. I did some signature updates yesterday and today - but it didn't help.

As I haven't changed anything in the last days/weeks, I assume that the culprit is a signature update during the last days or week. At first sight it looks like a false-positive.

The ransomware warning appears in a special circumstance: I modify a picture with the included photo-editor (change brightness or sth. else). Afterwards the software asks me if I want to apply the changes. If I acknowlege this, the following ransomware warning appears:
(image isn't shown although I inserted one :( )



My environment:
  • Win 7 x64 (latest Microsoft ESU updates/January 2021)
  • Avast Free Antivirus 20.10.2442 (installed in the beginning of January)
  • Pixum Fotowelt (by CEWE): latest version, 7.0.4 (installed also in the beginning of January)
« Last Edit: February 07, 2021, 11:05:07 PM by pustekuchencake »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Pixum (Photo album software): Ransomware-Protection
« Reply #1 on: February 08, 2021, 06:21:28 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline pustekuchencake

  • Newbie
  • *
  • Posts: 4
Re: Pixum (Photo album software): Ransomware-Protection
« Reply #2 on: February 09, 2021, 07:28:09 PM »
I know how to stop the message. But that can't be the solution. It's like telling: uninstall Avast and it won't appear anymore  ::)
It's obviously a bad signature update that causes this behaviour - at least I hope so. Or a hijacked application!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Pixum (Photo album software): Ransomware-Protection
« Reply #3 on: February 10, 2021, 07:52:56 AM »
I know how to stop the message. But that can't be the solution. It's like telling: uninstall Avast and it won't appear anymore  ::)
Not at all, it's adding an app to the white list.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Pixum (Photo album software): Ransomware-Protection
« Reply #4 on: February 12, 2021, 02:08:10 PM »
Ransomware Shield automatically allows whitelisted apps to access protected folders. It seems this app is not yet whitelisted. If you trust the app, you can just allow it and only this app will be allowed to access protected files in those folders while all others unsafe will still be blocked.
Visit my webpage Angry Sheep Blog

Offline pustekuchencake

  • Newbie
  • *
  • Posts: 4
Re: Pixum (Photo album software): Ransomware-Protection
« Reply #5 on: February 12, 2021, 07:02:10 PM »
Common, guys. I know I can whitelist it. I can also whitelist a virus  :o That's not the topic.

The question is: why does it happen suddenly? The application wasn't whitelisted before and it worked like a charm. So something has happend (my guess: signature update) and the question is what happend. I hoped to find someone of Avast telling me: "Hey, give me your log files or some other details so that we can reproduce it in our Avast labs to fix it".

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Pixum (Photo album software): Ransomware-Protection
« Reply #6 on: February 13, 2021, 07:25:43 PM »
Sorry, but you're chasing ghosts. As said, if you trust the app, allow it - else don't.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Pixum (Photo album software): Ransomware-Protection
« Reply #7 on: February 13, 2021, 10:22:51 PM »
Common, guys. I know I can whitelist it. I can also whitelist a virus  :o That's not the topic.

The question is: why does it happen suddenly? The application wasn't whitelisted before and it worked like a charm. So something has happend (my guess: signature update) and the question is what happend. I hoped to find someone of Avast telling me: "Hey, give me your log files or some other details so that we can reproduce it in our Avast labs to fix it".

avast! automatically adds folders to Ransomware Shield if it thinks given folder is worth protecting based on its content. This usually happens during on-demand scans. Which would explain why it didn't notify before but does now. Open Ransomware Shield and see what folders are protected and you know you didn't add those by hand.
Visit my webpage Angry Sheep Blog

Offline Leo3487

  • Jr. Member
  • **
  • Posts: 64
Re: Pixum (Photo album software): Ransomware-Protection
« Reply #8 on: February 14, 2021, 04:28:59 AM »
Users can remove folders from that list?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Pixum (Photo album software): Ransomware-Protection
« Reply #9 on: February 14, 2021, 07:05:27 AM »
Users can remove folders from that list?
Yes.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline pustekuchencake

  • Newbie
  • *
  • Posts: 4
Re: Pixum (Photo album software): Ransomware-Protection
« Reply #10 on: February 15, 2021, 09:10:15 PM »
The files are placed on my Desktop. I didn't add any custom folder to Ransomware protection.
I think the user folder (where also the Destkop folder resides in) is protected by default, isn't it?