Author Topic: Startup scan, malware and compressed bombs  (Read 1662 times)

0 Members and 1 Guest are viewing this topic.

Offline emil.aretorn

  • Newbie
  • *
  • Posts: 1
Startup scan, malware and compressed bombs
« on: November 20, 2020, 12:00:48 AM »
Hi!
So I noticed recently that I have some sort of malware that sends me to a specific website if I don't type in the full website adress in chrome. (i.g if i type in adidas.com it sends me to this website http://192.168.8.1/html/home.html?randid=3978944880 that wants me to download something.)
I did a startup scan and it found a bunch of compressed bombs. I don't think they would cause this but maybe I'm wrong. Should I just leave them?  I don't have a lot of space available on my computer... I can't find the logs for the scan and Avast just tells me that it found no infected files.
Also there is an icon in Avast next to the boot time scan in scan history that looks like a little ghost with an "!" on it but i don't know what that means either.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: Startup scan, malware and compressed bombs
« Reply #1 on: November 20, 2020, 01:22:36 AM »
1.  Have you made any changes to your HOSTS file as 192.168.8.1 is an IP address on your local computer ?
Commonly this is used to prevent you visiting adidas.com, but more so a malicious site.  However the /html/home.html and randid (random ID bit at the end is suspect).

It could also be something connected to your local network
https://www.google.co.uk/search?q=what+is+192.168.8.1

2.  Decompression Bomb, a file that is highly compressed, which could be very large when decompressed. This used to be a tactic long ago to swamp the system.

The name really is the most dangerous thing about this and I wish they would change it or simply not report it, a real PITA.

These highly compressed files are generally 'archive' files which are inert, don't present an immediate risk until they are unpacked. If you happen to select 'All packers' in your on-demand scans then you are more likely to come across this type of thing. Personally it is a waste of time scanning 'all packers' and that is why it isn't enabled by default.

3.  This little icon simply means that for some reason the avast scan wasn't able to scan a file, not infected, etc.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security