Got a mildly infected Vista x86 system today.
It had AnVir installed. At startup, an error would follow that local temp file csrss.exe that couldn't be found.
First round of cleanup? Steven Gould's Cleanup - gives for faster scantimes
Then actual antivirus cleanup: Combofix fist. Found some nasty toolbars and the like.
I now installed Avast 7, Hitman Pro & Superantispwyare.
I let them all do a quick scan, to see if there would be any differences.
These are the results...
- Hitman Pro scan? 300MB RAM (360 max)
It says (!) IE uses a local proxy on port 50566. I could not find evidence of this, but I won't dispute it either.
Found possible malware in crack file for game.
Found temp file in ServiceProfiles\LocalService\AppData\Local\Temp considered to be Infected. Maybe from other antivirus apps? If not, it was missed by Combofix.
Also found (traces of) Adware.MyWebSearch.
- Superantisypware scan? 95MB RAM (135 max)
Same results, except proxy (maybe fixed while still scanning due to me pressing Repair). Adware.MyWebSearch is called Adware.MyWebSearch/funweb/products.
- Avast scan? Nothing... :|
Peace!
devnullius