Avast WEBforum

Other => Viruses and worms => Topic started by: loafer80 on August 28, 2012, 09:04:30 PM

Title: HELP, rootkit virus in winsxs, false positive?
Post by: loafer80 on August 28, 2012, 09:04:30 PM
I have been trying to resolve this and looking for answers for what to do, knowing how serious rootkit virus can be.

Last night, I manually started a full scan with Avast and it reported 50 rootkit virus in the winsxs folder.  Most of the files are *.dll files with some *.exe. 
knowing that winsxs files could be critical to the OS, I didn't remove the files but unable to move them to chest.

I then scanned the laptop with the latest Malwarebytes Anti-Malware, and reported nothing.
So I scanned with Avast again specifically in the Winsxs folder and full system, both reported nothing.

What should I do next to ensure I'm clean or has the virus stopped any antivirus program to report?

Thanks in advance for helping!
Title: Re: HELP, rootkit virus in winsxs, false positive?
Post by: Pondus on August 28, 2012, 10:28:56 PM
attach OTL and aswMBR logs.   http://forum.avast.com/index.php?topic=53253.0
Title: Re: HELP, rootkit virus in winsxs, false positive?
Post by: loafer80 on August 29, 2012, 05:27:05 AM
here are the MBam log and OTL log
Thanks
Title: Re: HELP, rootkit virus in winsxs, false positive?
Post by: loafer80 on August 29, 2012, 05:29:32 AM
Extras and aswMBR log
Thanks

I will post a screenshot of avast scan log in next post, as I didn't check record log during that scan with 50 rootkit found
Title: Re: HELP, rootkit virus in winsxs, false positive?
Post by: loafer80 on August 29, 2012, 05:30:22 AM
screenshot of avast log
Title: Re: HELP, rootkit virus in winsxs, false positive?
Post by: loafer80 on August 30, 2012, 06:45:51 PM
bump
Title: Re: HELP, rootkit virus in winsxs, false positive?
Post by: Pondus on August 30, 2012, 06:54:28 PM
bump
patient   ;)
Title: Re: HELP, rootkit virus in winsxs, false positive?
Post by: essexboy on August 30, 2012, 07:00:09 PM
When did you last run windows updates ?  Was it during the Avast full scan ?
Title: Re: HELP, rootkit virus in winsxs, false positive?
Post by: loafer80 on August 30, 2012, 07:14:45 PM
Pondus/essexboy, thanks for the replies.

yes, I think window update was running during the full scan or finished update but computer hasn’t been restarted.  I probably restarted the computer and re-scanned then nothing came up.