Rootkit Hidden Service Found

Hi.

Yesterday I had avast detect a Rootkit threat found. I followed the suggested advice and “deleted” and rebooted and allowed Avast to do a full scan before my computer started. The results came back clean and no threat detected.
Twice last night the same message popped up again, I did the delete and reboot again with the same results so with the 3rd time I ignored.
Tonight I’m having the same problem only now I’m getting an error message saying action was unable to be performed. I performed a scan and I threat was detected but I haven’t done a reboot as of yet simply because it takes so damn long and I dont want to have the same results as last night.
I have a few screen shots of the log for the scan and the message I received but I’m unsure how to attached them/post them.
The result reads as -
File name SVC:swcustcfg> ???
Severity High
Status Threat: Rootkit: hidden service
Action Delete
Result X Error: Error: 0xA0000101.(-1610612479)

Is this a false positive??

Thanks
Kylie

Really hope you get your problem solved, the very same incident has happened to me where I wasn’t able to delete them because of an error. And I followed that with a full scan and the rootkit threat was no longer there. Its been worrying me all day, even getting paranoid that my reboots take longer than usual and the computer altogether is slower.

If I do a boot scan it doesn’t detect it but when I have finished re-boot it detects it on start up… What’s going on >.<

follow this guide and attach (not copy and paste) logs from Malwarebytes / OTL / aswMBR
http://forum.avast.com/index.php?topic=53253.0

As I said in my first post I don’t know how to attach files, I’ve tried and nothing happens. I dont have an additional options option at the bottom of my posts.

I’ve done a Malwarebytes scan and it was clean. Nothing found, detected, quarantined.

If you could tell me how to attach I’d be happy to give you both the screen shots AND the Malwarebytes log.

below the txt box you write in here…click “Attachments and other options

and we need more then malwarebytes log…
also OTL and aswMBR

That is the zeroaccess wireless configuration file. And is a false positive. When it next appears select ignore

Thanks so much essexboy, my friend has literally found a thread that you had posted about that very problem/solution. You are awesome!