Author Topic: Accidental rootkit detection?  (Read 3964 times)

0 Members and 1 Guest are viewing this topic.

miserysyndrome

  • Guest
Accidental rootkit detection?
« on: January 13, 2014, 06:24:02 PM »
While installing an update from Nvidia using the GeForce Experience application, Avast suddenly notified me of a rootkit that may be present at /systemroot/system32/drivers/nvhda64v.sys and gave me the option to delete or ignore the file.
I wasn't to sure about this, since the file is in fact part of the installation, since it's the nvidia HDMI audio driver so I simply closed the alert.
To make sure I wasn't infected, I did a full scan using avast with some settings altered (rootkit (quick scan) changed to rootkit (full scan)).
Results say no threats were found.
To be sure I downloaded MBAR an ran a scan with it, it immediately gave me a message saying "Registry value "AppInit_Dlls" has been found, which may be caused by rootkit activity."
It gave me the option to delete this, and continue to the scan with MBAR or to ignore it and go on. I decided to delete the file, since I don't have this message on any other system that use the same OS, and I never had that message before, and scan with MBAR.
MBAR didn't found any threats.
Also Malwarebites don't seem to find anything.

Is it really safe to assume that nvhda64v.sys was wrongly accused to be a threat ? or did deleting AppInit_Dlls solve this? Or is there something else that I should do to guarantee that my PC is clean?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Accidental rootkit detection?
« Reply #1 on: January 13, 2014, 06:30:13 PM »
upload and test suspicious file(s) at one of these online scanners. www.virustotal.com / www.metascan-online.com / www.jotti.org

post link to scan result here

miserysyndrome

  • Guest
Re: Accidental rootkit detection?
« Reply #2 on: January 13, 2014, 06:45:07 PM »
I scanned with all 3, just to make sure, but they all resulted in giving in no threats for the file avast detected (nvhda64v.sys) had to copy it to desktop in order to upload it.

https://www.virustotal.com/en/file/7ff7b4b8f09e773401ae879897e60bf494b57b9acee990204a4c98a3fb183a33/analysis/1389634945/

https://www.metascan-online.com/en/scanresult/file/6d140ae2ca674100bf63014afd1d2b1f

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Accidental rootkit detection?
« Reply #3 on: January 13, 2014, 06:47:56 PM »
You can upload files and report issues to avast  here : http://www.avast.com/contact-form.php  (select subject according to Your case)

You can use mail
send to virus@avast.com in a password protected zip file
mail subject:  False Positive / undetected sample (select subject according to your case)
zip password:  infected

or you can send files from avast chest
how to use the chest.    http://www.avast.com/faq.php?article=AVKB21



miserysyndrome

  • Guest
Re: Accidental rootkit detection?
« Reply #4 on: January 13, 2014, 06:54:09 PM »
I will be doing a boot scan just to make things sure that it was a false alert then.