I got the avast! Home 4.7 version, which I’ve used since late winter 2005, and I am very happy with it.
But lately I’ve had some problems with my PC. When I get online, avast! notices an incomming trojan horse,
but it “stops the malware”, as it says, so I get the chance to Abort Connection. But after aborting,
the Trj. comes back, with the following description:
This happens all the time!
I’ve scanned my drives several times, and I cant find any threats on my PC.
Is there anyone who could give me a helping hand?
Download, install and update the programs. Disconnect from the internet (pull the plug) before running scans in Safe Mode if possible.
Always select the option to quarantine any malware found rather than delete it, then you will be able to restore files or registry entries wrongly identified as malware- a rare but not unknown event for any malware scanner.
Try some online scans. (Disable avast! while scanning.)
Disable System Restore and reenable it after step 3.
Clean your temporary files.
Schedule a boot time scanning with avast with archive scanning turned on.
Use AVG Antispyware; SUPERantispyware and/or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
Good advice given here. You may have a downloader. Make sure you update any of the antispyware programs before you scan and do a complete scan rather than a qick scan. My choice to start with is SAS, but it up to you.
One more thing that may help. If you are using a firewall besides windows firewall, you may want ot check the logs and see if anything suspicious/unusual is accessing the internet.
I only have the Windows Firewall running…
By the way… just before starting the Panda Anti-Rootkit, I found a suspicious file, named “loader.exe”.
I deleted it, then scanned with the P A-R, but found nothing… so now I will try the NanoScan to see if there
may be more viruses/spyware etc. etc.
What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ?
Check the avast! Log Viewer (right click the avast ‘a’ icon), Warning section, this contains information on all avast detections.
The reason I ask is that Panda’s on-line scanner has a habit of dumping its signatures on the system and they aren’t encrypted, so avast might be detecting those.