Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: a.flood on August 21, 2005, 06:20:52 PM

Title: MSDIRECTX.SYS
Post by: a.flood on August 21, 2005, 06:20:52 PM
I have been experiencing problems with tryihg to get rid of MSDIRECTX.SYS using Avast.  When I choose to remove or delete the file it reappears within 60 seconds!  Any ideas??
Title: Re: MSDIRECTX.SYS
Post by: DavidR on August 21, 2005, 06:31:53 PM
Welcome to the forums.

Please Help us to Help you In order to help fully we need more information....
- What OS are you using? is it up to date?
- What avast! version and VPS file (virus database) number, e.g. 0436-4 (see about avast!)
- What was the virus name, what was the filename, where was it found
  example (C:\windows\system32\infected-filename.xxx)?
- What actions have you taken to try and resolve the problem?

A google search for MSDIRECTX.SYS returns many hits. This is the first and probably most relevant, this would appear to be a rootkit virus which is why it is coming back.
http://www.antisource.com/article.php/rootkit-msnt-msdirectx

I reccomend that you download this rootkit finder.
RootKitRevealer from system internals - http://www.sysinternals.com/utilities/rootkitrevealer.html, this will check if there is in fact a rootkit type virus deeply hidden.
I believe this has also been covered in the forums.

Title: Re: MSDIRECTX.SYS
Post by: Eddy on August 21, 2005, 06:41:02 PM
Follow the instuctions on THIS PAGE (http://www.antisource.com/article.php/rootkit-msnt-msdirectx)
Title: Re: MSDIRECTX.SYS
Post by: RejZoR on August 21, 2005, 06:59:23 PM
This re-apearing is really annoying and we must find some easy solution to fix this (ie remove the file without re-apearing). Boot-time doesn't help much in such cases i noticed...
Title: Re: MSDIRECTX.SYS
Post by: Eddy on August 21, 2005, 07:37:32 PM
Boottime doesn't help cause of the fact that it  is a rootkit.