Author Topic: Rootkit Found  (Read 5182 times)

0 Members and 1 Guest are viewing this topic.

rm15

  • Guest
Rootkit Found
« on: June 26, 2011, 05:37:01 PM »
C:\WINDOWS\system32\drivers\ndisuio.sys

"A suspicious hidden object (rootkit) has been detected on your system..."

I opened up Avast and did a scan of the drivers folder and nothing was found.

I'm not sure what to do here.
« Last Edit: June 26, 2011, 05:40:56 PM by rm15 »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Rootkit Found
« Reply #1 on: June 26, 2011, 07:06:22 PM »
The problem being this detection appears to have been the anti-rootkit scan and that uses heuristic methods not used in the conventional scanner.

Was this image example the same (other than file name) that was displayed ?

And in the top left was it Suspicious File Found or definitely Rootkit Found ?

Are you using XP ?
As this file name is associated with it, but that isn't a guarantee it is good, but it makes deletion as an option more risky, so Ignore would be the safer option for now.

See http://www.file.net/process/ndisuio.sys.html and http://www.processlibrary.com/directory/files/ndisuio/25623/
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

rm15

  • Guest
Re: Rootkit Found
« Reply #2 on: June 26, 2011, 08:49:47 PM »
The image example you've posted is the same, except the text in the upper left is "Rootkit found" rather than "Suspicious file found" (as in your example).

I am using XP.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Rootkit Found
« Reply #3 on: June 26, 2011, 09:56:30 PM »
OK, there is a chance that this is a legit file so don't act in haste and repent at leisure.

Now when this happens again, try clicking the Advanced option, I don't know if in avast6 there is a submit for analysis as there used to be in avast5, see image1 example of avast5 alert. If so then opt to send it for analysid and for the time being select Ignore for the option. But do not select the 'Do not tell me about this rootkit in the future.' Otherwise you would never know if the avast analysis corrected this detection.

I have XP Pro SP3 and I'm not getting any alert on this during the anti-rootkit scan (approx 8 minutes after boot) and I have that C:\WINDOWS\system32\drivers\ndisuio.sys file. See image2 for info on the file on my system, does yours match ?

See image3 as that driver file is running under explorer.exe.

So I'm at a bit of a loss as to what is happening on your system.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

rm15

  • Guest
Re: Rootkit Found
« Reply #4 on: June 26, 2011, 10:28:04 PM »
I am running XP Pro sp2 and the version of my file is:

5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)

I'm also running Avast 5.1 and I've left the original "rootkit found" window open so I will submit it for analysis and then select "ignore" for now.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Rootkit Found
« Reply #5 on: June 26, 2011, 11:45:51 PM »
OK, that is a good start.

But you really need to bring your OS up to date as your XP SP2 system no longer gets security updates leaving you more vulnerable to OS exploits.

The same is true of not running the the latest version of avast as it offers better levels of protection.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

rm15

  • Guest
Re: Rootkit Found
« Reply #6 on: June 27, 2011, 02:33:32 AM »
I've ignored the alert, but did not tell avast to ignore this issue in the future.  After submitting the info for analysis, I was prompted to do a boot-time scan, which turned up nothing.  Shouldn't the same rootkit have shown up?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Rootkit Found
« Reply #7 on: June 27, 2011, 03:29:25 AM »
Not necessarily as the rootkit scan that runs 8 minutes after boot has more information when it is using its heuristic methods. Essentially it can compare against windows APIs that may not be available on the boot-time scan.

So the next rootkit scan should pick it up again.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

rm15

  • Guest
Re: Rootkit Found
« Reply #8 on: June 27, 2011, 04:13:34 AM »
The system has been up for a couple hours now and still nothing...  Strange.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Rootkit Found
« Reply #9 on: June 27, 2011, 01:32:42 PM »
That's OK, leave it a few more reboots and see if it is picked up. If not then there is a good likelihood that it was a false positive detection which has now been corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

rm15

  • Guest
Re: Rootkit Found
« Reply #10 on: June 27, 2011, 06:23:51 PM »
I've rebooted a couple of times now and still nothing.  I don't understand how Avast would not be detecting the same rootkit as I did not select for it to ignore the rootkit in the future.  Could the avast team have updated a false positive so quickly?  Thanks for your help.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Rootkit Found
« Reply #11 on: June 27, 2011, 06:29:26 PM »
You are unlikely to be the only one to have had this alert and the avast CommunityIQ and personal submissions are likely to have resulted in the detection being analysed and the detection corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

rm15

  • Guest
Re: Rootkit Found
« Reply #12 on: June 27, 2011, 11:54:34 PM »
I see.  Well, everything appears to be okay, so thanks again.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Rootkit Found
« Reply #13 on: June 27, 2011, 11:55:31 PM »
You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security