False Positive? Odd Scan Results

Not sure what to make of it, but when I ran a full scan yesterday morning, the results came back that C:\Windows$hf_mig$\KB980436\update\update.exe was infected with Threat: Rootkit: System Modification.

Proceeded to scan with both aswMBR and MBAM, both coming up with nothing. A file scan of that file and a quick scan also came up clean. Full scan with MBAM came up empty, though when I tried to run a full scan with avast at the same time (not a good idea for me) windows crashed.

Ran another full scan with Avast after restarting, this time it showed up with four of the same detection on different files in different subfolders of C:\Windows$hf_mig$. At this point, Avast notified me, again, that there was a program update to 6.0.1203 which I had been ignoring throughout the day. Decided to update it, did so, restarted, then ran a full scan again. Nothing, scan came up clean. Boot scan came up with the same results. Another sweep with MBAM and aswMBR also came up with nothing.

Haven’t noticed anything unusual, though my network adapter apparently crashed followed by the rest of windows when I attempted to run MBAM and aswMBR at the same time. Not sure what to make of it, whether this is some sort of insidious infection, or just avast jumping at shadows.

Hi MBanana,

Here is a write-up about deleting these unused files in the $hf_mig$ folder: http://www.pagestart.com/hfmigpart1.html
(linksource: NetworkSolutions)

polonus

Got another of the same result, though again a different file in a subfolder of C:\Windows$hf_mig$. Not sure what’s going on, as scans over the previous days have, as before, been clean.

attach an OTS log and let Essexboy have a look inside…

Well, here it is. A full scan I ran right before running OTS also came up with nothing.

I feel that the heuristics is being a bit overzealous at the moment. I could see no apparent malware. Are you experiencing any problems ?

I haven’t noticed anything out of the ordinary, so I think you’re right about the scanner being a tad sensitive. Thanks for your help, glad it doesn’t seem to be anything more than a false alarm.