Gizmos Freeware Reviews  

Go Back   Gizmo's Freeware Forum > Freeware Forum > General Computer Support

Reply
 
Thread Tools Display Modes
Old 19. Dec 2011, 08:08 PM   #1 (permalink)
Member
 
Join Date: Dec 2011
Posts: 4
Default Rootkit infection?

Avast! has been telling me there is a rootkit infection in my PC, something called rootkit-gen. Then, it asks me to press 1 to delete it, and so on. But when I press 1 (or 3, to put it in the vault), nothing really happens. I get a message to the effect that the operation is incompatible with this sort of file. TDSS Killer, otherwise, says that there is no infection. What to think? I will appreciate any help.
neuerung is offline   Reply With Quote
Old 19. Dec 2011, 08:17 PM   #2 (permalink)
Moderator
 
Join Date: Jul 2008
Location: India
Posts: 9,484
Default

I think that you are talking about the boot time scan of Avast? Its because on boot time scan only, it gives the options numbered 1, 2 etc.

Does it give the location of the file that it tells to be infected? Please share the path of the file here, so that we can see which file it is flagging as rootkit.

Its labeled as gen, so it can be a false positive, but cannot be sure, and have to be careful, since its a rootkit.

Please share the file name, and the path where its located.

To be sure, you can scan the system with a system rescue CD, like Kaspersky, which are available for free.
__________________
Anupam
Anupam is online now   Reply With Quote
Old 19. Dec 2011, 09:25 PM   #3 (permalink)
Foundation Editor/Forum Manager Intern
 
kendall.a's Avatar
 
Join Date: Apr 2008
Location: Colorado, USA
Posts: 1,814
Default

You could also try scans with Malwarebytes, SuperAntispyware, HitmanPro, or Emisoft and see if they come up with any rootkits.
__________________
<-------Is looking for his brain....
kendall.a is online now   Reply With Quote
Old 20. Dec 2011, 01:55 AM   #4 (permalink)
Member
 
Join Date: Dec 2011
Posts: 4
Default Thanks

I will run a new scan and make a note. I'll let you know.
neuerung is offline   Reply With Quote
Old 21. Dec 2011, 05:59 PM   #5 (permalink)
Member
 
Join Date: Dec 2011
Posts: 4
Default

I ran a new boot scan with Avast! I got a message saying that C:\System volumen information\_restore {2F2...}...[ASPack] is infected by Win32:Rootkit-gen [Rtk]
Do you need the long string of letters and numbers in the path of the file?
Thanks for any help.
neuerung is offline   Reply With Quote
Old 21. Dec 2011, 06:03 PM   #6 (permalink)
Foundation Editor/Forum Manager Intern
 
kendall.a's Avatar
 
Join Date: Apr 2008
Location: Colorado, USA
Posts: 1,814
Default

Two things:

1. Did you run any of the scans that I suggested above?
2. It appears that it might be in one of your restore points. I would recommend turning off System Restore so that it clears all of your restore points. Reboot. Then, if it boots clean, turn System Restore back on and make a new restore point.
__________________
<-------Is looking for his brain....
kendall.a is online now   Reply With Quote
Old 21. Dec 2011, 06:16 PM   #7 (permalink)
Moderator
 
Join Date: Jul 2008
Location: India
Posts: 9,484
Default

Quote:
Originally Posted by kendall View Post
2. It appears that it might be in one of your restore points. I would recommend turning off System Restore so that it clears all of your restore points. Reboot. Then, if it boots clean, turn System Restore back on and make a new restore point.
Yes, that's what should be done.
__________________
Anupam
Anupam is online now   Reply With Quote
Old 22. Dec 2011, 03:53 AM   #8 (permalink)
Senior Member
 
bo.elam's Avatar
 
Join Date: Nov 2009
Posts: 1,224
Default

Quote:
Originally Posted by neuerung View Post
I ran a new boot scan with Avast! I got a message saying that C:\System volumen information\_restore {2F2...}...[ASPack] is infected by Win32:Rootkit-gen [Rtk]
Do you need the long string of letters and numbers in the path of the file?
Thanks for any help.
This looks like a FP to me but if I was you I would follow Kendalls advice. Don't worry and don't start deleting files, your computer has not been infected.

Bo
bo.elam is offline   Reply With Quote
Old 22. Dec 2011, 06:56 AM   #9 (permalink)
Site Manager
 
MidnightCowboy's Avatar
 
Join Date: Aug 2008
Location: South American Banana Republic, third bunch from the left
Posts: 9,250
Default

There's a bit more information about this here:

http://forum.avast.com/index.php?topic=47662.0

To my knowledge, the Win7 2011 rogue AV can also trigger a (genuine) alert like this.

IMO perhaps the most effective way to check out this system is to submit a HijackThis log to somewhere that can analyze it.
__________________
Knows nothing and cares even less
MidnightCowboy is online now   Reply With Quote
Old 24. Dec 2011, 02:41 PM   #10 (permalink)
Member
 
Join Date: Dec 2011
Posts: 4
Default

Hello again. I did two things: 1) I ran a Malwarebytes scan. Result: three adware things, but no rootkit. 2) I cleared the restore points as kendall suggested. Then, I ran Avast! again (complete system sacn). Result: no threats detected. I will run a reboot scan for a final check.
I appreciate a lot all your help. And, of course, I wish you a Merry Christmas and a Happy New Year!
neuerung is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT +1. The time now is 11:44 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2