Author Topic: Rootkit found, avast keep warning me just after computer startup  (Read 4677 times)

0 Members and 1 Guest are viewing this topic.

Amaryl

  • Guest
Hello,

two days ago, Avast showed me this message


"Rootkit found... it is recommended to delete". I confirmed Avast could delete it, I don't care about this service anyway. Then Avast tells me it is recommended to schedule a scan at startup and then reboot. I did that do. Here is the result of the scan:



During the scan, I chose to delete the files.

But now, Avast keep giving me the same messages again and again just after the computer started. I thought maybe Avast just couldn't delete the file because the service was running, but I actually don't find this service anymore in the Services' window, and I don't find the process in the Task manager anymore either! I know it used to be there.
I don't find the corresponding exe file either!

What should I do?

mDNSResponder, Win32:Evo-gen, HideMe-F trojan
« Last Edit: January 10, 2014, 11:29:50 PM by Amaryl »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #1 on: January 10, 2014, 10:38:11 PM »
Attach the requested logs Malwarebytes / OTL / aswMBR     http://forum.avast.com/index.php?topic=53253.0


Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #2 on: January 10, 2014, 11:28:00 PM »
You're french right? If you'd like to get help infrench, do let me know so I can PM g3n-H@ackm@n
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Amaryl

  • Guest
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #3 on: January 11, 2014, 07:00:53 PM »
You're french right? If you'd like to get help infrench, do let me know so I can PM g3n-H@ackm@n

Thanks Alan, but I think I'll be fine.

Attach the requested logs Malwarebytes / OTL / aswMBR     http://forum.avast.com/index.php?topic=53253.0

Did it.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #4 on: January 11, 2014, 07:24:09 PM »
Do you have some web pages stored on your D drive ?  As that appears to be what Avast is now alerting on

Amaryl

  • Guest
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #5 on: January 11, 2014, 08:13:33 PM »
Do you have some web pages stored on your D drive ?  As that appears to be what Avast is now alerting on

Yes, loads.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #6 on: January 11, 2014, 08:38:13 PM »
Some of the HTML files are infected with the hideme script

Use Avast to scan the D drive only and note which files are infected.  Unless you have backups you will need to clean them manually

Amaryl

  • Guest
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #7 on: January 16, 2014, 03:58:52 PM »
Some of the HTML files are infected with the hideme script

Use Avast to scan the D drive only and note which files are infected.  Unless you have backups you will need to clean them manually

Well, Avast did that already the day everything begun. I re-scanned it, and there is apparently no problem left on the D. Still am I unable to solve the initial problem: the rootkit.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #8 on: January 16, 2014, 04:11:05 PM »
The rootkit is a false positive .. select ignore/do not show again

Amaryl

  • Guest
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #9 on: January 17, 2014, 09:49:27 AM »
The rootkit is a false positive .. select ignore/do not show again

I'm happy it is but... how do you know?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #10 on: January 17, 2014, 02:33:10 PM »
The file reported is a part of iTunes http://support.apple.com/kb/ht2250

Amaryl

  • Guest
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #11 on: January 17, 2014, 02:42:14 PM »
The file reported is a part of iTunes http://support.apple.com/kb/ht2250

Yes, but maybe was it injected with vicious code? Isn't this possible?
Because I know I have this file and service running for a very long time, even if I never installed iTune, and I only have problems with it now!
« Last Edit: January 17, 2014, 02:44:22 PM by Amaryl »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Rootkit found, avast keep warning me just after computer startup
« Reply #12 on: January 17, 2014, 04:59:00 PM »
It is probably due to the behaviour of the service as it does adjust the network on your computer. 

I have that service disabled on my system as it just uses resources for no real benefit.  If you wish you can uninstall it via control panel