Rootkit problem

Hello everyone,

I have Avast! 4.8 home (4.8.1296) on my Acer Aspire 5610. When i run a scan i receive a message that suspicious files have been found (using heuristic method) and later on tells me there is a virus in the memory. I’ve done as requested by rebooting and submitting the files for analysis, but when the scan finishes i find that i can’t do anything about the infected files; there is no opportunity to get rid/move them to the chest etc as this option is greyed out. The whole process starts again the next time i scan. There were also areas it couldn’t scan.

I have AVG anti rootkit, Sophos anti rootkit and Blacklight rootkit eliminator (which i installed as a result of the scan results), all have found nothing. I also have anti virus and anti spyware all updated.

Hope the attached image of the scan might help, are they all to do with Acer (as i’ve heard mentioned), or have a got a bit of a problem here?

Grateful for any help with this, as i’m at my wits end!

Cheers folks!

Can you please post your anti-rootkit log?

C:/Program Files/Alwil Software/Avast4/DATA/log/aswAr.txt

Edit: avast! anti-rootkit module still detecting Acer drivers?

Hi there,

Sorry, not sure what you mean, was the one i attached no good then? I’ve had a look in log viewer and all i can see is a whole list of stuff under error, warning and notice. Is this any good to you?

Thank you!

Maybe that file is more specific, I mean, the log has more specific info.
Seems false positive of drivers and dlls… don’t delete the files (yet), for sure, update your avast.
Hope they correct these false detections soon.

Please try the standalone antirootkit tool, announced here:
http://forum.avast.com/index.php?topic=33753.0

Just click the Start button and wait for it to finish. Does it report the same results?

I too am having a problem like Crowella. “When i run a scan i receive a message that suspicious files have been found (using heuristic method) and later on tells me there is a virus in the memory. I’ve done as requested by rebooting and submitting the files for analysis, but when the scan finishes i find that i can’t do anything about the infected files; there is no opportunity to get rid/move them to the chest etc as this option is greyed out. The whole process starts again the next time i scan.” In my case avast seems to remove the files but during the next scan it finds them again. When I scan the files using the Avast file on demand file scanner it finds no infection.

I reinstalled my first HDD with a fresh OS install. When I did the scan using the current signature files with an older version of Avast engine (October 2008), Avast had no problems with the scan. Updated the Avast engine (4.8.1296) and did the scan and got the Win32.Rootkitgen problem. I put back my second HDD given that at this point I believe this to be a false positive. The thing I don’t get is why did my Sony VAIO pcv-rx550 have this problem and the 8 other computers in my home did not have a problem. I wanted to know if anyone else is having this problem. Is there more I can do to check this out?

Hi there,

Just tried the standalone Avast anti rootkit and it found no problems (same with all the others):

avast! Antirootkit, version 0.9.6
Scan started: 02 December 2008 20:45:12

Scan finished: 02 December 2008 20:46:24
Hidden files found: 0
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 0
Hidden boot sectors found: 0


Do you think i’m reasonably safe then?

Cheers all!

Most probably, at least against rootkits…

I too got the all clear from the stand alone rootkit tester.

Can you guys please try running the standalone antirootkit tool again, but this time with the “Advanced mode” box checked?

Thanks
Vlk

Hi all,

ok, did the anvanced mode and it found these two, i haven’t fixed them yet, would you recommend that i do? (just don’t want to do more damage!)

avast! Antirootkit, version 0.9.6
Scan started: 02 December 2008 20:45:12

Scan finished: 02 December 2008 20:46:24
Hidden files found: 0
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 0
Hidden boot sectors found: 0


avast! Antirootkit, version 0.9.6
Scan started: 02 December 2008 22:14:26

File C:\Documents and Settings\Christine\Application Data\Mozilla\Firefox\Profiles\nahm4e3a.default\parent.lock HIDDEN
File C:\Documents and Settings\Christine\Application Data\Mozilla\Firefox\Profiles\nahm4e3a.default\places.sqlite-journal HIDDEN

Scan finished: 02 December 2008 22:15:38
Hidden files found: 2
Hidden registry items found: 0
Hidden processes found: 0
Hidden services found: 0
Hidden boot sectors found: 0


Thanks everyone!

And the results of the avast scan are reproducible?
I mean, does it happen every time you run the scan? (the loads of false positives).

Thanks
Vlk

I too am having the same problem with the same thing on windows 2000
ive done everything i can think of i hope it gets fixed in an update ive scan over and over same thing ive ran panda rootkit scan nothing comes up just ran a full scan at the panda website and my unit is clean so i ran avast again and still pops up that im infected with a rootkit .so i dont know any other thing to do but wait.good luck…

Hi there,

Yeah that’s right, the same stuff comes up in the Avast scan, no matter how many times i run it. Not quite sure what to do now!

Cheers all

http://forum.avast.com/index.php?topic=40382.msg340578#msg340578

Happy to help out with the above, so long as it’s safe. Let me know!

Christine

It doesn’t get any safer than this. :wink:

Cheers
Vlk

I’m having the identical problem here. This morning’s Avast! scan came up with 504 rootkit suspicious files. I don’t know what to do anymore.

I am having the same sort of problem with avast finding 134 hidden rootkits and saying these are suspicious files.It gives an option to ignore or delete them.I’ve done both options but each time I run avast scan they are still found by avast. I also get a message saying a virus has been found and that it recommends a scan in boot safe mode which i’ve done and it finds nothing.I get av updates daily automatically so my avast is always up to date.I’ve also run superantispyware and it doesn’t find anything either.So are these hidden rootkits,fasle positives?If so how do I prevent them from showing up whenever I run avast scan in future?and what about this supposed virus it says it’s found,to then only come up with nothing when I do a boot safe scan of my files as recommended?
I’ve left the box ticked to send the results to avast lab but no response.Leaving this box checked,does the program automatically send the results to the lab or do I have to somehow manually do this?
I’ve run a hjt scan but not sure if anything there needs to be removed.Since this problem of hidden rootkits has been found by avast i’ve also noticed,just over the last couple of days i’ve lost a big (to me anyway) chunk of free space on my C drive.

Hope someone can help with this?I mean if avast has found this virus why doesn’t it name it and give me the option to delete or move to chest etc?Can this also be a false positive response aswell?

Boston and Stoney. Please create a new topic.