SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > General > General Topics > PC Hardware/Software forum
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 02-04-10, 11:15 PM   #1
kiwi_2005
Eternal Patrol
 
Join Date: May 2004
Location: Aeoteroa
Posts: 7,382
Downloads: 223
Uploads: 1
Default Avasti 5 and Flash disinfector

This is what could happen to you!

I put an add in the paper for data entry work a few weeks ago, yesterday i got a phone call from a local asking if i fix pc's, well the ad in the paper was about data entry work but I can take a look at it if you want. Yes please i think my pc has a worm was his reply. So I tell him to bring his case over and i'll hook it up to my monitor/keyb as i never go round to peoples places to do this type of work and they so desperately want to get their pcs fix they never decline to bring it over.

He brings over his pc an eMachine E1600, 1.6ghz 1g ram onboard gfrx, the case is the size of a shoebox. Start his pc up running windows home edition, first thing i notice is Ares files sharing app running on his taskbar that their sent warnings. No grfx detected so update his drivers and fix that. No signs of viruses i can surf the internet, no slowdowns or anything strange im playing around with his pc checking folders for at least 30min. He has no antivirus or firewall running except Windows firewall. So i download Avasti 5 free edition and run a scan. That's when everything turned to mud. I couldn't believe well put it this way i stopped counting once i got to Trojan number 30 detected. Once the scan had finished which took over 2 hrs to scan, 88 trogans and malware was found on his pc. Yet i may not be up with the times here but surfing the internet was not a problem nor accessing anything on his drive it was like his computer was fine no slowdowns nothing. Or these trogans just laid dormat and trigger on certain events.

So avasti fixed the above problems then i ran a second scan just to make sure, avasti popup window went crazy about a herss.exe (nasty!)was detected by and stopped before it can modify - then it would repeat the warning over and over. Once herss was detected & triggered it blocked access to the C drive double clicking on the C drive would cause a tab to open with the ''Open with'' option, 'Show hidden services' in the folders/view menu was blocked everytime i checked that it would revert back. So i couldn't open the C drive or access hidden services. Meanwhile Avasti was popping up with same trogan detected every 10 seconds Avasti couldn't fully stop it but just kept sending it to the vault. Still had access to the internet so Google a fix for this herss.exe and found a program called Flash Disinfector. Installed this and ran it, once that was done the c drive was back and the herss.exe file was no longer coming up as warnings in Avasti. I could also check hidden services as i wanted to see what crap was in the Temp folder.

restarted pc and did one more full scan. Everything turned up with no viruses found. Job done. No wait one more thing i should check - his browser and see what sites they visit. I found in a drop down menu full of file sharing links so i installed Zonealarm and blocked them all. This couple is in their 50's and they have two teenagers using the pc so i suspect the file sharing sites are been used by them unless of course they too listen to snoop dogg

Woke up this morning turned on his pc and ran one more scan just to be safe. His windows is good as new.

I stopped using anti-viruses and just run Malwarebytes but after seeing this guys computer i think i will go back to having an antivirus installed just incase! Avasti 5 at least found the Trojans and fixed but had problems with getting rid of herss.exe even so i now have this antivirus install on my pc. Version 5 is smooth and light on the resources and comes with a silent gaming mode option im sure it never had this in Version 4. Flash disinfector is another that's worth having on your pc.
__________________
RIP kiwi_2005



Those who can't laugh at themselves leave the job to others.



kiwi_2005 is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 06:13 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright © 1995- 2024 Subsim®
"Subsim" is a registered trademark, all rights reserved.