Author Topic: Help please possible Rootkit infection on my computer  (Read 1851 times)

0 Members and 3 Guests are viewing this topic.

Diddy

  • Guest
Help please possible Rootkit infection on my computer
« on: April 15, 2013, 12:42:53 PM »
HI I have a possible rootkit infection on my computer.  When I went into my google browser I got a message from avat free that I have a possible rootkit infection here are the details below:
File name: SVC: MBAMSWISS Arr
RootKit name: hidden service

What does this mean does this mean I have a rootkit infection on my computer or did I delete it like avast recommened I do.

My computer is really slow but it was really slow before avast free popped up with a big warning.

Thanks
here are the logs below:

I am only an intermediate computer user

Operating system is: Windows vista 32 Bit

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Help please possible Rootkit infection on my computer
« Reply #1 on: April 15, 2013, 12:59:30 PM »
Quote
MBAMSWISS Arr
False Positive..... file belongs to Malwarebytes..... you have malwarebytes installed?


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help please possible Rootkit infection on my computer
« Reply #2 on: April 15, 2013, 03:12:36 PM »
That is the main driver for MBAM and loads very early, and has the appearance of a rootkit due to its functionality

But it is a FP

Diddy

  • Guest
Re: Help please possible Rootkit infection on my computer
« Reply #3 on: April 16, 2013, 01:11:15 AM »
HI yes I do have malwarebytes free installed on my computer right now.  So that is not a virus right.  So I want to now Exxboy do I or do I not have a root kit or other viruses on my computer at present time.  My computer has been really slow and I am just curious to now if I have a virus or rootkit infection on my computer at this time.

Thanks again everyone for the help and your time.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help please possible Rootkit infection on my computer
« Reply #4 on: April 16, 2013, 03:33:26 PM »
No sign of infection, but running Vista with less than 1Gb of memory is not going to help with the speed at all

Plus you have all the following starting with windows

Quote
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter File not found
O4 - HKLM..\Run: [Everything] C:\Program Files\Everything\Everything.exe ()
O4 - HKLM..\Run: [IDrive Background process] C:\Program Files\IDriveWindows\idwbg_501.exe (Pro Softnet Corporation)
O4 - HKLM..\Run: [IDrive Monitor] C:\Program Files\IDriveWindows\idwmonitor.exe (Pro Softnet Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NPSStartup]  File not found
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter File not found
O4 - HKCU..\Run: [IDrive Background process] C:\Program Files\IDriveWindows\idwbg_501.exe (Pro Softnet Corporation)
O4 - HKCU..\Run: [IDrive Monitor] C:\Program Files\IDriveWindows\idwmonitor.exe (Pro Softnet Corporation)
O4 - HKCU..\Run: [WeatherEye] C:\Users\Clint\AppData\Local\The Weather Network\weathereye.exe (Pelmorex Media Inc.)