[Resolve]Is this Real ROOTKIT???

i already uploaded in Virus Total Here the Result :slight_smile:

http://www.virustotal.com/file-scan/report.html?id=6d0c5691b52d7aa396258589d1932a16131b4d581292d68a5a0367cfee09a824-1290676047

I think that a false threat sense avast and Gdata is using the same engine so. hopefully avast will correct this with the next virus update.

thanks for sharing and helping improving avasts detection rate.

@bong2x
have sendt you a PM

Done :wink:

we cannot say what is it. so we wait the result of investigation

Edit: i miss read it

Hello,
send us (virus@avast.com) the file to analyze, please. Put “False positive” to subject.

Milos

Sample is sendt :wink:

OBS: subject - sample requested

Done!!!

sir,
i use to send virus from the chest and i always put " potential Malware" and put the comment “for investigation”
if i do like that, it will be still at the same detection?

Regards!!!

Thanks avast team for your fast action

i don’t understand why other detected it now ??? ??? ::slight_smile:

http://www.virustotal.com/file-scan/report.html?id=5922fb1d14408060c4f00ad08208194cf5c0406bbd19deaef719f27b84441adf-1290757866

Regards!!!

Sheep, or if you check what it is that they are actually detection they are heuristic or undefined detections, these are more prone to false positive if they are over sensitive.

i check those files before sending and i see that do not have publisher name. maybe that make the avast detect as threats. but maybe because maybe that Win7 is a fresh install.

do you think what is the deference (see picture)
the 652kb is the one that avast capture do not have publisher. and the regeneration is 0kb and it has publisher

if you see that picture whats on your mind???

Norman analysis - Added detection

autochk.exe : Processed - Dloader.AMOBY

Complicated ha???
in my XP it is not Captured by Avast but in Win7 is identified as Rootkit
so be very careful about adding this threats.
do not let people out there suffer for just a small mistakes
this file the function of original files is to check the hardware before start-up and before shutdown
if this file is deleted it will prompted you at the start. autochk.exe not found skip the process
and it will slow down your computer at the start-up.

If i upload and scan the the one i find in my Win7-32bit C:\Windows\system32\autochk.exe i get this

autochk.exe - 0/43 - MD5 : 41e4c8eba464e7d6a5ba5e8827732aeb
http://www.virustotal.com/file-scan/report.html?id=a3447c256d3dee0c999a220d0e4f4a471e2eb6024232474bc47dbaa30ed5b025-1290789226

sigcheck:
publisher…: Microsoft Corporation
copyright…: (c) Microsoft Corporation. All rights reserved.
product…: Microsoft_ Windows_ Operating System
description…: Auto Check Utility
original name: AutoChk.Exe
internal name: AutoChk
file version.: 6.1.7600.16385 (win7_rtm.090713-1255)
comments…: n/a
signers…: -
signing date.: -
verified…: Unsigned

Malwarebytes say CLEAN

The one you sendt me

autochk.exe - 3/43 - MD5 : 43bcf660eaddafcbf638a1af757ca3ae
http://www.virustotal.com/file-scan/report.html?id=941eb31e50c6ed7cf8b2231794bb17577e696d8573b0d53729e76ca22c030f4e-1290789618

sigcheck:
publisher…: n/a
copyright…: n/a
product…: n/a
description…: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…: n/a
signers…: -
signing date.: -
verified…: Unsigned

Malwarebytes detect it as Trojan.Agent

Thanks Pondus!!!

I am also wandering, why my autochk.exe do not have a publisher and copyright.
is it possible that Trojan replaced the whole file?? i will Re install my Win7 and try again.

Regards!!!

and finaly from Avira…they where late this time

File ID FilenameSize (Byte)Result 25963354 autochk.exe 652.5 KB MALWARE

Please find a detailed report concerning each individual sample below:
FilenameResult autochk.exe MALWARE

The file ‘autochk.exe’ has been determined to be ‘MALWARE’. Our analysts named the threat RKit/Undef.A. The term „RKIT/“ denotes a piece of software that uses cloaking techniques to hide itself from view. Therefore it has to be categorized as potentially malicious.Detection will be added to our virus definition file (VDF) with one of the next updates.