My avast! displays a “threat has been detected” message two or three times every day. The threat always refers to the same file, C:\WINDOWS\system32\eobij.fre
Avast! says the threat was detected when creating or modifying the file, by process ID 4 (which is ‘System’) and proceeds to move the file to the chest. The threat is reported as Win32:Rootkit-gen[Rtk]
Is it a false positive? Is this a real rootkit? If so, how can I remove it? What do you advice me to do?
Thank you very much.
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
I have not received any new notification, so it seems the treat has been removed. However, I will wait one or two days to be sure. I’ll let you know.
Thank you very much!
Download ComboFix from one of the following locations: Link 1 Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks
I jusr run ComboFix, and I am attatching the log. I’ll have to wait for another whole day, because the message only appears about two times a day.
Thank you!
I’m starting to think this file is regenerated by the System process from time to time, and it might be a false positive.
However, I didn’t get this message until a couple of weeks back.