Author Topic: Avast Rootkit Detection mbamswissarmy.sys  (Read 9526 times)

0 Members and 1 Guest are viewing this topic.

whyalwaysme

  • Guest
Avast Rootkit Detection mbamswissarmy.sys
« on: January 30, 2013, 08:54:41 PM »
Hi there,

I have been a happy Avast user (latest Free version) the last years. I have a Windows 7 machine, everything updated. I have Malwarebytes Free installed to do regular scans. I never had any problems.

Today Avast detected a rootkit in (I hope I got it right) mbamswissarmy.sys. Unfortunately, I didnt make a screenshot but I think this was the file. First question: Is there any way I can find this alarm? I have looked in every protection module but nothing is stated there.

Now to the scenario: I booted the computer only to look up the last scan log of MBAM really quick. I booted, and after the desktop appeared went immediately into MBAM, looked at the logfile. Then, I closed the MBAM GUI and then I had the rootkit alarm from Avast. The whole thing took perhaps 5-10 minutes. I have looked into several topics. Apparently, this is not uncommon. However, I came across this thread http://forum.avast.com/index.php?topic=98405.30 and a user there wrote:

Quote
SVC:MBAMSwissArmy Rootkit will pop-up from an antivirus program if it detects a malicious service running on the system. The detection is for a legitimate file called mbamswissarmy.sys that is modified by a virus infection that causes the main program to fail. There are also other variants of Trojan hitting the same file in order to run a malware code every time the affected software is executed. With the rootkit identified in this threat, there is a possibility that the threat attempts to conceal its presence from the infected computer by appending its own code to valid Windows’ system files.

Now, Im a bit worried.

What would you recommend to do? A Fullscan with Avast? A Fullscan with MBAM? A scan on startup with Avast?

Thanks very much for your help.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Avast Rootkit Detection mbamswissarmy.sys
« Reply #1 on: January 30, 2013, 09:03:07 PM »
did you read the hole topic......
the file belongs to Malwarebytes


see section K
http://forums.malwarebytes.org/index.php?showtopic=10138&view=findpost&p=417798

whyalwaysme

  • Guest
Re: Avast Rootkit Detection mbamswissarmy.sys
« Reply #2 on: January 31, 2013, 06:15:23 PM »
Hi,

thanks for your reply. I am aware of that but the quote suggests that the file could also point towards a manipulation of MBAM, ie an infection. Or am I reading this wrong?

Is the rootkit alarm saved in any log of Avast? Can I find the report anywhere?s

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Avast Rootkit Detection mbamswissarmy.sys
« Reply #3 on: January 31, 2013, 06:31:56 PM »
Quote
Or am I reading this wrong?
yes....info is not correct.....zero variants found to be a threat

http://www.threatexpert.com/files/mbamswissarmy.sys.html
http://systemexplorer.net/file-database/file/mbamswissarmy-sys



HDW38

  • Guest
Re: Avast Rootkit Detection mbamswissarmy.sys
« Reply #4 on: April 10, 2013, 10:57:05 PM »
Quote
Or am I reading this wrong?
yes....info is not correct.....zero variants found to be a threat

http://www.threatexpert.com/files/mbamswissarmy.sys.html
http://systemexplorer.net/file-database/file/mbamswissarmy-sys
Hi!

Tried upgrading 'mbam free 1.71.0.1100' to 'mbam free 1.75.0.1300'. No problem under XP with 'avast 8.0.1483'.
But under 'R2 Beta' this happened. So I stopped installing after the old mbam-version was de-installed.
What shall be done?

HDW38