Author Topic: Win32:Rootkit-gen  (Read 8558 times)

0 Members and 1 Guest are viewing this topic.

Offline kyuuketsuki_kurai

  • Jr. Member
  • **
  • Posts: 88
Win32:Rootkit-gen
« on: July 16, 2009, 06:29:48 AM »
I just got 2 pop ups today from Avast regarding files that appear to be or are part of my Google Notifier.
I have put them in the chest for now, but I'm thinking it could be a false positive, since they appear to be legit files, as far as I can tell.
The files in question are:
C:\Program Files\Google\GoogleToolbarNotifier\swg-5.1.1309.15642\SearchWithGoogleUpdate.exe
C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
These seem to be the only files coming up, but this happened while I had no internet connection, so it stuck me as odd. Can anyone comment on this?
Thanks for any help.
Kurai
Alienware 17, Windows 10, Intel Core i7-4700MQ, 8GB RAM, Avast 19.2, Chrome 72.0 64-bit

Jtaylor83

  • Guest
Re: Win32:Rootkit-gen
« Reply #1 on: July 16, 2009, 06:44:34 AM »
Upload both files to VirusTotaland post results.

Offline kyuuketsuki_kurai

  • Jr. Member
  • **
  • Posts: 88
Alienware 17, Windows 10, Intel Core i7-4700MQ, 8GB RAM, Avast 19.2, Chrome 72.0 64-bit

Offline mathboyx215

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 449
Re: Win32:Rootkit-gen
« Reply #3 on: July 16, 2009, 06:53:46 AM »
Could be false postive because g data uses the avast engine
It is not possible to divide anything by zero

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2293
Re: Win32:Rootkit-gen
« Reply #4 on: July 16, 2009, 09:01:55 AM »
Thanks for notice, will be fixed in next VPS update.

Offline kyuuketsuki_kurai

  • Jr. Member
  • **
  • Posts: 88
Re: Win32:Rootkit-gen
« Reply #5 on: July 16, 2009, 08:08:28 PM »
So these are false positive, then?
I can restore them?
Alienware 17, Windows 10, Intel Core i7-4700MQ, 8GB RAM, Avast 19.2, Chrome 72.0 64-bit

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89012
  • No support PMs thanks
Re: Win32:Rootkit-gen
« Reply #6 on: July 16, 2009, 09:50:43 PM »
Yes but you have to wait for the VPS to be updated, check (scan) the file from within the chest and when it isn't detected then you can Restore it.

Edit: attachments removed.
« Last Edit: July 16, 2009, 09:56:59 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline kyuuketsuki_kurai

  • Jr. Member
  • **
  • Posts: 88
Re: Win32:Rootkit-gen
« Reply #7 on: July 17, 2009, 04:27:19 AM »
Okay. Thank you very much for your assistance.
Alienware 17, Windows 10, Intel Core i7-4700MQ, 8GB RAM, Avast 19.2, Chrome 72.0 64-bit

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89012
  • No support PMs thanks
Re: Win32:Rootkit-gen
« Reply #8 on: July 17, 2009, 03:50:32 PM »
You're welcome, there has been an update since your last post I believe  (current version 090716-1) check that you have it and scan the file again.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

silvermac

  • Guest
Re: Win32:Rootkit-gen
« Reply #9 on: July 20, 2009, 03:22:08 AM »
hi guys can you help me this one....

my Last update was on may 6, 2009 and im not connected to internet for almost 2 months.. then after that i found rootkits in my pc... when i updating my pc it doest work and and the msg in VRDB is not done yet... what can i do to update and remove rootkits in my pc.. ty guys!!

Offline kyuuketsuki_kurai

  • Jr. Member
  • **
  • Posts: 88
Re: Win32:Rootkit-gen
« Reply #10 on: July 20, 2009, 03:52:06 AM »
Please post what exactly was found (for example: Win32:Trojan-gen)and in what file(s).
Please, include file paths and be sure to take careful note in the spelling of the file names.
Alienware 17, Windows 10, Intel Core i7-4700MQ, 8GB RAM, Avast 19.2, Chrome 72.0 64-bit

silvermac

  • Guest
Re: Win32:Rootkit-gen
« Reply #11 on: July 20, 2009, 05:14:45 AM »
hi  this is what i found....

C:\WINDOWS\SYSTEM32\nmdfgds0.dll
Rootkit: hidden process

W8Lifter

  • Guest
Re: Win32:Rootkit-gen
« Reply #12 on: July 20, 2009, 07:53:47 AM »
I got SEVERAL virus/worms/trojans the other day that wont allow me to load WinXP, so I am running in Safe Mode with Networking.

After many attempts, I was able to delete or move, but still have 2 that wont go away.

One is the Win32:Rootkit-gen ya'll are discussing. Im hoping there is a way to deal with them all, so Im going to list them here, rather than post in several separate threads.

I have:

Win32 Rootkit-gen UPS.exe  in C://Documents/Settings/UPS_NR1.exe

Win32 UPS (cryp) in  C://...../letter_UPS55364.doc

I tried moving, deleting, repairing & nothing works.

I just updated Avast defiinitions to no avail. The Win profile these files are in is not accessible and states there is 0 Files/0 Bytes, so I cant see them, modify, etc.

Is there a tool I can use to remove this and others? Sorry, but Im new to this problem, so please have patience. Thank you.
« Last Edit: July 20, 2009, 08:17:28 AM by W8Lifter »

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2293
Re: Win32:Rootkit-gen
« Reply #13 on: July 20, 2009, 10:22:36 AM »
hi  this is what i found....

C:\WINDOWS\SYSTEM32\nmdfgds0.dll
Rootkit: hidden process

Hi,
all files with this filename submitted as false positives to us are not false positives.

Milos