Author Topic: Sign of Rootkit  (Read 6005 times)

0 Members and 1 Guest are viewing this topic.

Nicku

  • Guest
Sign of Rootkit
« on: December 16, 2008, 11:23:49 AM »
Hey all!

Scanning my system with avast! today I get warnings for over 250 files that avast! detected signs of rootkits. In the log file, this looks as follows:

16.12.2008 09:25:36   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\setup.bmp\medctroc.dll" file.
16.12.2008 09:25:37   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\setup.bmp\ehOCGen.dll" file. 
16.12.2008 09:25:37   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\setup.bmp\plusoc.dll" file. 
16.12.2008 09:25:41   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\setupdll.dll\medctroc.dll" file. 
16.12.2008 09:25:41   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\setupdll.dll\ehOCGen.dll" file. 
16.12.2008 09:25:42   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\setupdll.dll\plusoc.dll" file. 
16.12.2008 09:25:46   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\setupapi.dll\medctroc.dll" file. 
16.12.2008 09:25:46   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\setupapi.dll\ehOCGen.dll" file. 
16.12.2008 09:25:46   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\setupapi.dll\plusoc.dll" file. 
16.12.2008 09:26:17   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\CONFIG.TMP\systemprofile\Lokale Einstellungen\Temp\RtkBtMnt.exe" file. 
16.12.2008 09:26:18   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\CONFIG.TMP\systemprofile\Lokale Einstellungen\Temp\RtkBtMnt.exe" file. 
16.12.2008 09:26:38   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\CONFIG.NT\systemprofile\Lokale Einstellungen\Temp\RtkBtMnt.exe" file. 
16.12.2008 09:26:39   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\CONFIG.NT\systemprofile\Lokale Einstellungen\Temp\RtkBtMnt.exe" file. 
16.12.2008 09:26:58   user-name   3844   Sign of "Rootkit: hidden file" has been found in "C:\WINDOWS\system32\spoolsv.exe\drivers\w32x86\3\ZPP.DLL" file.

and so on...

I have no idea nor what this is nor what I can or should do about it. Cleaning the system with CCleaner didn't change anything. Can anyone help?

Thanks in advance

Nicku

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Sign of Rootkit
« Reply #1 on: December 16, 2008, 11:52:19 AM »
Do you use an Acer computer?
There is a well known bug with Acer computers.
They're working on it.
Until there, as a workaround, disable rootkit scanning in the Trobleshooting tab of program settings.
The best things in life are free.

Nicku

  • Guest
Re: Sign of Rootkit
« Reply #2 on: December 16, 2008, 12:04:39 PM »
Yes, it is an Acer!

I guess I'll just wait then...

Thanks anyway!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Sign of Rootkit
« Reply #3 on: December 16, 2008, 12:10:41 PM »
I guess I'll just wait then...
Don't forget the workaround and, also, to check the forums regularly to see if the problem was solved. Also, keep your avast program and virus database updated.
The best things in life are free.