Author Topic: Did Avast lock away something important? Now with logs  (Read 1986 times)

0 Members and 1 Guest are viewing this topic.

TalkingAbsol

  • Guest
Did Avast lock away something important? Now with logs
« on: October 15, 2010, 04:05:55 PM »
EDIT: I haven't got much time on my laptop. Something's really got a strong hold on it, and I think a virus is trying to crash it. Here' the OTL logs, I can't find the MBAM ones. Please, please help!

PAST: About a month ago (I was putting this off to see if it would get any better), I was browsing around on a site when avast suddenly started going crazy with about thirty different "Rootkit Detected" etc. messages. It appeared to put all of them in the Virus Chest. I thought things looked fine, but when I booted up the next morning, it was running really slowly, the arrow icon would freeze over the toolbar, and it would take about a half hour before that would stop, and then my laptop would be running fine. I thought it had something to do with my Internet connection (wi-fi), because my laptop start running fine when it was connected to the Internet, but it would take that full half hour before it would respond to anything, even turning the wifi button on and off. For the record, I'm currently typing this on the home computer.

I looked in the avast chest, and it had about fifty or more different things in the chest, all with the extension .sys and all located in C:/Windows/system32/drivers , with a few exceptions:

AD0017356.dll
AD0017374.exe
AD0019407.dll
    All located in C:/System Volume Information/_restore (and then a bunch of numbers)
ANOSUYANAMISUNO.DLL - C:/WINDOWS
defdown.dll - C:/WINDOWS/system32
monmvr32.exe - C:/Documents and Settings\Myname.LYCA\Start Menu\Programs\Startup

Now, my mom is the computer geek of the family, and she said that all the ones located in system32/drivers should be safe, and so did all the research I did on my own. I even went so far as to go into Windows Explorer and check to see if the files were already in the system32/drivers folder, and they were. So, of course, I went to restore them from the chest.

HOWEVER, when I did so on the first few, a message popped up saying "This file already exists. Would you like to replace it?" I haven't replaced them, but no matter which one I try it always pops up with that message.

I right-clicked on the file in the chest, and avast keeps insisting that it is a rootkit infection. I've scanned several times in the past few weeks, and so far avast hasn't found anything else. Now, granted, this "rootkit infestation" occurred right before I updated avast's Virus Definitions, but I would still think that, after a month, something would have been solved. No such luck, so I ask the people of avast- What in the world is wrong?

And yes, I have scanned with and updated Malwarebytes. It hasn't detected anything either. I even installed Sophos Rootkit Detection, and it didn't find anything.

And if this kind of problem has already been solved, please gently point me to the post. I can't seem to find anything like this, though...

Thank you very much-
TA
« Last Edit: October 16, 2010, 07:13:08 PM by TalkingAbsol »

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Did Avast lock away something important?
« Reply #1 on: October 15, 2010, 04:22:29 PM »
it could be a rootkit or idk,i think you are safe,wait for others opinion
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37625
  • Not a avast user
Re: Did Avast lock away something important?
« Reply #2 on: October 15, 2010, 04:31:53 PM »
If you want a second opinion from an Expert, i recomend Essexboy.
Follow the guide and you will have the answer later today

http://forum.avast.com/index.php?topic=53253.0

To avoid using multiple post with copy and paste you have to attach the log`s
Lower left corner: Additional Options > Attach ( OTL.Txt and Extras.Txt. and MBAM scan log )