Avast WEBforum

Other => Viruses and worms => Topic started by: thekochs on July 05, 2011, 04:46:38 AM

Title: (SOLVED) AVGxxxxx.SYS Leftover Drivers: Avast Rootkit False Postive
Post by: thekochs on July 05, 2011, 04:46:38 AM
I'm a long time AVG user now switching all my PCs to Avast....two down more to go.
I really like Avast and have run scans on both machines...clean expect in full scan or on boot after windows comes up Avast shows a rootkit found for what looks like three legacy AVG files, AVGldx86.sys, AVGmfx86.sys, AVGtdix.sys in the Windows/systems32/drivers directory.  Since i'm not trying to cause any BSOD I thought I'd ignore using the Avast popup...they still show/alert on a reboot....I also used full scanner with the rootkit in Avast windows and it asked to reboot.....they still show back up.  I've not done a boot time scan and this would be last resort.  I assume others have run into this since I'm sure many folks are moving away from AVG.

Can you give guidance ?

Attached is pic of Avast popup.

Thx.
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: com155 on July 05, 2011, 05:56:32 AM
so a rootkit huh? try this:

Download aswMBR.exe (http://public.avast.com/~gmerek/aswMBR.exe) ( 1.8MB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
(http://public.avast.com/~gmerek/aswMBR1.png)
 
On completion of the scan click save log, save it to your desktop and post in your next reply
(http://public.avast.com/~gmerek/aswMBR2.png)
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: Pondus on July 05, 2011, 05:59:26 AM
have you uninstalled AVG before installing avast ?
have you run a removal tool to clear all leftovers ?

removal tools can be found here
http://thewebatom.net/uninstallers/security-software/
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: com155 on July 05, 2011, 06:05:42 AM
oh huh!!!!!i almost forgot to ask this.thanks,pondus.....
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: thekochs on July 05, 2011, 06:09:36 AM
I did uninstall AVG.....even ran CCleaner afterwords.....files and registry too.

I just ran the Avast boot scanner and here are results.....puzzling since I am still getting this Avast popup at Windows boot...takes couple minutes to show up.

07/03/2011 16:51
Scan of all local drives

Scanning aborted
Number of searched folders: 445
Number of tested files: 2504
Number of infected files: 0

----------------------------------------
07/04/2011 22:55
Scan of all local drives

Number of searched folders: 11308
Number of tested files: 627504

Number of infected files: 0


I will try to run the cleanup uninstaller per the link above....was looking for it on AVG.

Is the MBR program OK to run for scan mode ?....non instrusive ?

Thx !!!
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: Pondus on July 05, 2011, 06:10:22 AM
oh huh!!!!!i almost forgot to ask this.thanks,pondus.....
almost ?.......  ::)
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: Pondus on July 05, 2011, 06:11:19 AM
Run the AVG removal tool and reboot
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: thekochs on July 05, 2011, 06:37:35 AM
I ran the AVG removal tool and DOS window came up....alot of items scrolled past saying it was removing, etc....then exit.  I then did a manual reboot. After 2-3 minutes into Windows the same Avast popup shows.....in my first post of thread.  As FYI, I was running AVG9....since AVG10-2011 has SOOOO many issues...this uninstaller looks to be 2011 by name....does that matter ?

Also, why when I choose from Avast's popup to ignore does it still come up ?

Thx !
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: Pondus on July 05, 2011, 06:43:14 AM
hmmmmm....not sure

you find the latest here   http://www.avg.com/us-en/utilities


i would guess if you run latest it shold remove all versions...


if you browse to that location, are the files still there after running the tool ?
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: thekochs on July 05, 2011, 07:00:02 AM
They are hidden files so even if I go into Explorer and uncheck the "see O/S files" and look in that directory they are not there.....but Avast is either still seeing them or has some log/buffer that keeps this popup coming up.

Is there something in Avast to ignore these or clear this log/popup ?
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: Pondus on July 05, 2011, 07:09:50 AM
I will send a PM to DavidR but it a may take some time before he enters the forum


not sure if this will make any difference but have you tried removing avast with the removal tool reboot and reinstall  http://www.avast.com/en-no/uninstall-utility

Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: thekochs on July 05, 2011, 07:37:09 AM
This is exactly what I was about to do....but it's ~2am,EDT in USA and need to hit the bed.
I'll check late tommorow this thread for any suggestions prior to uninstall & re-install of Avast.

Af FYI....
When I look at the AVG remover log it says that avgldx86, avgmfx86, avgtdix are not present.
Some log examples/excerpts......(since log is too big to post)
2011-07-05 04:17:04,531 INFO Processing service AvgLdx86, it can take several minutes...
2011-07-05 04:17:04,562 INFO Service AvgLdx86 is not installed
2011-07-05 04:17:04,593 DEBUG Service AvgLdx86 RegCleanup
2011-07-05 04:17:04,625 DEBUG Registry keys for service AvgLdx86 are not present
2011-07-05 04:18:04,265 DEBUG Key SYSTEM\ControlSet001\services\avgldx86 not found

If I run a Avast boot scan it finds nothing as well.
However, on Windows boot I still get the Avast popup shown on first post.
Also, just ran Avast FULL SCAN...it finds them...see attached.
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: com155 on July 05, 2011, 09:31:43 AM
OK, another tool to check for other types of rootkit.


Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: Pondus on July 05, 2011, 10:05:19 AM
have googled the file names and found this. also see under important


avgldx86.sys file information:  http://www.file.net/process/avgldx86.sys.html

avgmfx86.sys file information: http://www.file.net/process/avgmfx86.sys.html

avgtdix.sys file information: http://www.file.net/process/avgtdix.sys.html
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: thekochs on July 05, 2011, 01:28:08 PM
Ok...thanks.....I've run MalwareBytes on the machine many times prior......plus this is happening on other PCs too.
I'll try TDSSKiller and also run Malware Bytes but could these be false positives within Avast ?
How do you submit something that has no file ?

If they are real rootkit and Avast sees why does it not remove ?
Also, strange the Avast scanner can see but the boot scanner cannot.

Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: thekochs on July 05, 2011, 03:02:10 PM
Well, ran TDSSKiller as suggested above and it found nothing.....see attached.
Also ran MBAM again and nothing there.
I read another thread and seems Avast is seeing rootkits that specialized programs are not ?
http://forum.avast.com/index.php?topic=80667.0
Let me know what you guys think ?.....this just seems like false positive ?
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: DavidR on July 05, 2011, 03:27:40 PM
@ com155
I have just been asked to check this topic and you are jumping in with both feet with zero analysis, you have to look at the information presented to you, the files in the inage all appear to be AVG drivers.

Pondus is correct in that these are AVG related files and had you checked this out first (google the file names) you would have been on to the right track.

So it looks like the OP is also running AVG (or remnants of it remain) with avast and it needs to be uninstalled or these conflicts are assured.

Even when this was pointed out to you you continued firing off rootkit tools for the OP to run, this is both counter productive and a waste of time and likely to cause undue worry to the OP. Not to mention shaking his confidence in avast, as these hidden drivers of AVG are apparently still running.

The anti-rootkit scan uses different methods to the regular scans so they wouldn't find anything wrong with these files. It also compares what the windows API says is running against what is actually running.

Once it was identified that there appear to be remnants of AVG on the system then that should have been the first thing to resolve.
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: thekochs on July 05, 2011, 03:36:43 PM
DavidR, thanks for your insights but I think when I posted the thread I suggested it was AVG.
However, the Google on these file does also say they have known to be Malware too.
Other posters have suggested the rootkit tools to try....not me.
I was happy to try the suggestions others posted.

I am open to any of your suggestions on what to try to remove.
As posted above I've used the AVG un-installer utility.
Also, reading your post it is your opinion this is a conflict, not a rootkit malware ?

I appreciate everyone's help...please provide any guidance.

Thx.
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: DavidR on July 05, 2011, 03:50:09 PM
Well, ran TDSSKiller as suggested above and it found nothing.....see attached.
Also ran MBAM again and nothing there.
I read another thread and seems Avast is seeing rootkits that specialized programs are not ?
http://forum.avast.com/index.php?topic=80667.0
Let me know what you guys think ?.....this just seems like false positive ?

You say you actually checked in the c:\windows\system32\drivers folder to see if these files are present and they aren't, which is strange.

You could also try checking the registry for and reference to c:\windows\system32\drivers\avg*.sys entries as there might also be legacy keys remaining.

~~~~
I don't know if the AVG removal tool you used was the correct one - there is a 32bit and 64 bit windows version, ensure you use the correct one for the version you installed. I think that version 8 of AVG will probably have been a 32bit version even though you may now have a 64bit OS.


####
From your last post:

1. My comments were directed @ com155 and not you (which is why I put the @ com155) at the top of the post.

2. In a way it is conflict as essentially they shouldn't be there and if they are then they are low level drivers (which hook files so they are scanned) and it is mainly these that conflict in normal use. The other problem being these are generally kernel mode drivers and hidden from the system and it is this method of hiding that is causing the issue with the anti-rootkit scan.

I would say keep ignoring them on the alert and keep reporting them as possible false positive.
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: essexboy on July 05, 2011, 08:31:18 PM
No they are remnants from AVG but the fuction of the files/drivers has rootkit characteristics

try this if the AVG removal tool does not clear it all

Download AppRemover (http://www.appremover.com/get/appremover.exe) .
 
Uninstall AVG via Programmes and Features
Run the AVG removal tool

Run appremover
Click Next >>
(http://www.hdrcgb.org.uk/g2g/appremover1.jpg)
 
 
Ensure "Remove Security Application" is collected and click Next >>
(http://www.hdrcgb.org.uk/g2g/appremover2.jpg)
 
 
AppRemover will scan all the security applications on your PC
(http://www.hdrcgb.org.uk/g2g/appremover3.jpg)
 
Select Any AVG entries from the applications offered and click Next >> twice.
(http://www.hdrcgb.org.uk/g2g/appremover4.jpg)
 
Follow any further on-screen instructions. If asked to reboot,please do so.
[color="#FF0000"]
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: thekochs on July 06, 2011, 03:30:59 AM
Well, no joy/luck with AppRemover.....see attached....all it found was Avast.

At this point I'm pretty convinced these are not Malware but conflict of some old AVG "drivers" that were not cleanly uninstalled.  The question becomes, can I find a way to get rid of or hope that Avast updates their softwre/DB to mark them as false positives.

My last/next efforts will be to boot into Safe Mode and turn off the "hide O/S files" and see if these three files are visible within Windows directory...perhaps I can move/rename.

If not luck there then last "brute force" method I can think of is to uninstall Avast with its complete uninstaller, run CCleaner (files/reg), install AVG10 (2011), run AVG complete uninstaller, run CCleaner, run AppRemover, install Avast, see if I get same error.

As FYI, I have one other XP machine doing exact same thing but not my 64bit brand new W7 HP Pavilion DM4 laptop....Avast runs fine...no rootkit popup.  I initially installed old AVG9 on it, then uninstall, then installed Avast.  Besides these laptops being different inherently the big diff I see is that the two XP machines had AVG10 (2011) installed....then removed when we saw how BAD it was.  AVG10/2011 never saw the new HP W7 machine....AVG10/2011 has alot more "security" in it than AVG9...perhaps the "root" of the issue...ha...ha. :)

Any other suggestions let me know ?
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: essexboy on July 06, 2011, 07:22:52 PM
Or you could run OTS and I will see if I can find the files then Kill them

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire (http://www.mediafire.com/) and post the sharing link.

Download OTS (http://oldtimer.geekstogo.com/OTS.exe)  to your Desktop
Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check


%SYSTEMDRIVE%\*.exe
CREATERESTOREPOINT


Please attach the log in your next post.
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: thekochs on July 06, 2011, 09:43:04 PM
Well, first thanks to all posters on this thread !!!

I spent the last three hours....clean uninstall Avast (thru util), CCleaner, AppRemover, install lastest AVG10/2011, clean uninstall AVG10/2011 (thru latest util), CCleaner, AppRemover, RE-install of Avast.....and bang....the rootkit saw these files again....ugh !!!!!

At this point I'll try OTS but I'm convinced this is a false positive from Avast Rootkit....not Avast fault because this is left over crud from AVG....one more reason of hundred I want away from their software.

So, I've spent few days on my vacation now trying to run this down and I really appreciate everyones help....really !!!  I'm open to any other suggesstions and I'll feedback the log when I run OTS (FYI, I have system restore turned off since I use RollBack RX so I'll not include that portion of instructions...let me know if any issue there).

Any chance Avast will post to this thread that they will log this/these as false positive in their rootkit and remove in next virus DB or program update ?  Long term I'm not sure I can have these popups and scans show these hits.

Regards.
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: essexboy on July 06, 2011, 11:22:05 PM
It just so happens that AVG is vulnerable to infection, a few days ago one of the AVG drivers was infected and I had to remove the entire programme manually.  Needless to say the user has now changed to Avast 
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: thekochs on July 07, 2011, 02:14:52 AM
essexboy,

I went ahead and ran OTS....attached is txt log.
Can you decipher ?.....not sure if it means anyhting.

Thx.

P.S.  I tried again to hit ignore on the popup and it
appears this no longer is coming up at boot...perhaps
the ignore finally took. However, if I run FULL scan that
has the rootkit it sees the three files....but can't delete
or move to Virus Chest. There is no "ignore" option in
the log files ?....wish Avast would add.

Last item I can think of while I await feedback on the
OTS log is to run CHKDSK /F on reboot to fix any file
Index problems. Not sure this would resolve but worth
a try.
Title: Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
Post by: essexboy on July 07, 2011, 07:40:56 PM
Intriguing I cannot see any AVG drivers there

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

Code: [Select]

[Unregister Dlls]
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-1708537768-261903793-725345543-1003\] > -> HKEY_USERS\S-1-5-21-1708537768-261903793-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{A057A204-BACC-4D26-9990-79A187E2698E}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< RunOnce [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
YN -> "AvgUninstallURL" -> C:\WINDOWS\System32\cmd.exe [cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYAMABLAE0AQwAtAEUAOQBWAFUAVwAtAEUAVwAwAFYAQQAtAFUAVQAzAFgATAAtAEYARQBXADkANwA"&"inst=NwA3AC0AMQA0ADEANQAzADYAOAA5ADkALQBCAEEAKwAxAC0ASwBWADMAKwA3AC0AWABMACsAMQAtAEYAUAA5ACsANgAtAEIAQQBSADkARwArADEALQBUAEIAOQArADIALQBGAEwAKwA5AC0AWABPADMANgArADEALQBGADkATQA3AEMAKwA1AC0ARgA5AE0AMQAwAEIAKwAyAC0AWABPADkAKwAxAC0ARgA5AE0AMgArADEALQBEAEQAVAArADAA"&"prod=90"&"ver=9.0.894]
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YN -> "C:\Program Files\AVG\AVG10\avgmfapx.exe" -> [C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer]
YN -> "C:\Program Files\AVG\AVG8\avgnsx.exe" -> [C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe]
YN -> "C:\Program Files\AVG\AVG8\avgupd.exe" -> [C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe]
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix.  Post that information back here

I will review the information when it comes back in.

Depending on what the fix contains, this process may take some time and your desktop icons might disappear or other uncommon behavior may occur.

This is no sign of malfunction, do not panic!
Title: AVGxxxxx.SYS: Avast Rootkit False Postive
Post by: thekochs on July 07, 2011, 11:11:19 PM
essexboy,

Thanks for the suggestion but I'm very hesistant to spend time on a fix that may have other impacts to the system....basically intrusive.  Talking with others this clearly is a false positive by Avast....even though it is left over crud from AVG not one other rootkit I run sees the issue...I've now run six.  I think doing more to the system for a false positive runs the risk of being counter productive.  I'm only hoping that the Avast folks will agree and change their program or DB to reflect this...after all I assume others switching from AVG will have the same issue....since I have two PCs that are different machines showing the identical issue.

I did run the CHKDSK and while it did fix some index issues a FULL SCAN (includes their rootkit scan) from Avast still shows these three files as high risk but no way to delete, move to Virus Chest or "ignore" (no option for ignore).  I would at least like the "ignore" option like in the Avast rootkit popup warning....seems that it finally took my "ignore" effort there but guess this does not apply to a scan ?

Anyway, I may change my mind if there is more problems down the road but for now I think it should be left to Avast folks to fix.  As FYI, when you run OTS Avast pops up saying you are about to run an unsafe program and you should run in their "sandbox" and if you do anything it does will not be saved, etc....guess kinda a "shield"....again, I'm new to Avast.

Regards.
Title: SOLVED: AVGxxxxx.SYS Leftover Drivers: Avast Rootkit False Postive
Post by: thekochs on July 18, 2011, 09:55:40 PM
I wanted to post the resolution.....found it.

It seems that even though I uninstalled "AVG" the AVG web searcher was still installed.
This is even though nothing showsi in the Windows Add/Remove.
So, I went ahead and installed Googles search add-in/toolbar as default.
I then went into Internet Explorer and within the add-ins console deleted the AVG add-in.

I re-ran Avast FULL scan with rootkit and no issues found.

Thx for all the help.....hope this thread helps someone else.