Avast WEBforum

Other => Viruses and worms => Topic started by: -Genesis- on June 02, 2011, 04:52:14 AM

Title: FP ? USBTOR.sys Avast heuristic Anti Rootkit
Post by: -Genesis- on June 02, 2011, 04:52:14 AM
I think i know the cause of this...

I have also Panda USB vaccine.

@david,

1. Try inserting a USB flash drive.(Behavior shield detect USBTOR.sys as suspicious but no pop up.)

2. Remove the USB flash drive.

3. After restarting the system this pop up appears.


(http://i1216.photobucket.com/albums/dd376/sanjoseparaiso/usbtor.jpg)


(http://i1216.photobucket.com/albums/dd376/sanjoseparaiso/wew.jpg)

Avast all scan logs


(http://i1216.photobucket.com/albums/dd376/sanjoseparaiso/avastlogs.jpg)



Mbam Scan Latest version and updated

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6751

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

6/2/2011 10:45:58 AM
mbam-log-2011-06-02 (10-45-58).txt

Scan type: Quick scan
Objects scanned: 143441
Time elapsed: 3 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Title: Re: FP ? USBTOR.sys Avast heuristic Anti Rootkit
Post by: -Genesis- on June 02, 2011, 05:09:52 AM
I just restart my system

Insert again the same USB Flash drive earlier but now behavior shield didn't detect as suspicious.

I didn't remove anything on my Flash drive.

As my other previous post here. Sometimes avast will not detect same file. THIS IS A WEIRD ON AVAST.

Againt his happen on the latest build on Avast.

The previous build only problems on me is the game launcher.
Title: Re: FP ? USBTOR.sys Avast heuristic Anti Rootkit
Post by: -Genesis- on June 02, 2011, 05:48:56 AM
Fully system scan with visible dates.

(http://i1216.photobucket.com/albums/dd376/sanjoseparaiso/Fullsystemscan.jpg)

I have no malwares or rootkits?

My only problem is having 4 FP on antirootkit feature?


Actually i didnt update you guys that yesterday my firefox is detected as suspicious on behavior shield but no Avast antirootkit pop up. Still observing......

Use 2 scanner.

MBAM and Avast FULLY UPDATED.

You can see also my 1st post that all my Avast logs scan has no viruses and malwares.
Title: Re: FP ? USBTOR.sys Avast heuristic Anti Rootkit
Post by: SafeSurf on June 02, 2011, 10:18:21 AM
You have done all the correct things.  You may want to also do an Avast Boot scan as well.  Report back your results.  Thank you.
Title: Re: FP ? USBTOR.sys Avast heuristic Anti Rootkit
Post by: -Genesis- on June 02, 2011, 12:06:50 PM
06/02/2011 17:36
Scan of all local drives

File C:\Documents and Settings\Albert\Local Settings\Temp\GLB4D.tmp|>Wise0003.bin Error 42145 {Installer archive is corrupted.}
Number of searched folders: 5044
Number of tested files: 356422
Number of infected files: 0


What is that error?


(http://i1216.photobucket.com/albums/dd376/sanjoseparaiso/Bootscan.jpg)
Title: Re: FP ? USBTOR.sys Avast heuristic Anti Rootkit
Post by: SafeSurf on June 03, 2011, 11:18:08 AM
Have you tried an Avast Repair:
- Go to Control Panel > Add/Remove programs > Avast Antivirus.
- Scroll down and choose Repair function in the pop-up window.
- Reboot.

If this does not fix the problem and you have several choices:

1. If you think you may be infected (is your machine acting strange?), you can check the information on the first post of this thread under Virus/Worms for you to check your machine for malware: http://forum.avast.com/index.php?topic=53253.0 (http://forum.avast.com/index.php?topic=53253.0). 
- Follow the directions for obtaining the OTS logs (save it as ANSI).  Post the OTS log as an attachment (Additional Options > Attach > Post).

2. If you think it may be a glitch with Avast and you are not infected, then do an uninstall/clean install of Avast using the Avast Uninstaller tool.  Make sure you uninstall ALL previous versions and products of Avast during the uninstall.


Title: Re: FP ? USBTOR.sys Avast heuristic Anti Rootkit
Post by: -Genesis- on June 03, 2011, 02:39:56 PM
My only problem is having 4 Avast heuristic Antirootkit pop up alert.

Using Google the error is not related to Avast.

I did reinstalling a Bandmaster games 4x. 1X on C:\, 3X on D:\.

I think the error came from that game.

Im very careful downloading stuff.

I always use sandbox for browsing.

I hope Avast team is checking all my post here and check the file ive submitted to viruslab.