Author Topic: Rootkit alert related to chrome - not sure if real  (Read 5777 times)

0 Members and 1 Guest are viewing this topic.

cooby

  • Guest
Rootkit alert related to chrome - not sure if real
« on: June 20, 2013, 07:04:37 PM »
After doing a very clean uninstalling of 8.1483 in safe mode and after two reboots, I installed 8.1489.
I rebooted and startup scan was running and during that, next thing I saw was a welcome screen from chrome and an enormous chrome updates ran.
OT: Even though I was doing Custom installation, how I missed the chrome checkmark, I don't know, I swear it wasn't there :(

I rebooted again and immediately went in to uninstall chrome.
I guess around that time Avast ran a definitions update, or another short scan, and a big red alert came on the screen about rootkits:
svc: gupdate > C:\Program
svc: gupdatem > C:\Program
See attached log and screenie - not sure if really rootkits or avast's internal error.

At some point, in my state of confusion by now, avast suggested boot scan, OK.
It went through all my partitions for hours. I don't think anything was found other that an item in a year-old copy of, all things, avast log I had in My Documents.

The aswAr.log upon next reboot looks clean.

I subsequently checked the web, and those two names, gupdate and gupdatem, seem to be related to that chrome varmin:
http://www.bleepingcomputer.com/startups/GoogleUpdate.exe-25791.html
http://www.bleepingcomputer.com/startups/GoogleUpdate.exe-26582.html

What do I do now? Do I really have a rootkit which bootscan didn't see? How to check? Is gmer still part of avast's scanner?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Rootkit alert related to chrome - not sure if real
« Reply #1 on: June 20, 2013, 07:26:30 PM »
virus and false positive problems should be posted in  viruses and worms forum section....that is what it was made fore
see logs to assist in cleaning malware guide at top in that forum section....


Offline skinnypops

  • Full Member
  • ***
  • Posts: 106
  • backup, backup, backup
Re: Rootkit alert related to chrome - not sure if real
« Reply #2 on: June 20, 2013, 10:26:48 PM »
hope every body is well today. 

gupdate and gupdatem are not dangerous. they are used to update many google products, such as google earth etc. it is safe to simply delete them.
they did come with chrome but are actually no problem.

delete and have a good day.
new HP , amd a10-8700p quad core @ 1.8 gig radeon r6 graphics ,dedicated radeon r8 2gb graphics card, 8 gig ddr3-1600 memory, 1 tb hdd, win 10x64 home 1607 build 14393.1066, avast free 17.3.2291,  windows firewall, mbae free, mbam free, open dns, cryptoprevent, mcshield, paragon bu & recovery 2015,system explorer

cooby

  • Guest
Re: Rootkit alert related to chrome - not sure if real
« Reply #3 on: June 20, 2013, 11:39:12 PM »
virus and false positive problems should be posted in  viruses and worms forum section....that is what it was made fore
see logs to assist in cleaning malware guide at top in that forum section....
@Pondus,
I had two options
1. Post in virus help forum
2. Post here.
Considering that the information I have is mangled with installation issues, and information in the error log, I thought here is the best place.
I had no intention, yet, of acusing avast for including a rootkit in the installer. To go to the other forum comes close to it :)

@pinkme,
Quite possible, as the reference from bleepingcomputer I quoted indicate. At least I hope it is ok. But if you read my entire post, you would see that these must have remained after uninstalling and avast alert suggests a rootkit.



Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Rootkit alert related to chrome - not sure if real
« Reply #4 on: June 21, 2013, 12:09:02 AM »
Hi cooby,

Quote
For convenience, the two modes are stored in the same executable. It is a chrome coder's choice - client side and server...
The consumer editions install both Chrome and Google Update on a per-user basis...

Quote taken from: https://code.google.com/p/chromium/issues/detail?id=114356
You may find all of the ansers to your questions in that link on Issue 114356: Google Update Services (gupdate & gupdatem)
link article author = ryan myers

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

cooby

  • Guest
Re: Rootkit alert related to chrome - not sure if real
« Reply #5 on: June 21, 2013, 02:10:25 AM »
@Polonus,
1. I wanted to mention it several times, here and in the mobile forum, - so finally: I love your genuine Polish Eagle :)
2. Nice link, thanks. Confirms what BC says, but only on name.
But Avast hasn't told me, not in any logs I examined, where that rootkit is. "Program" means nothing to me. "C:\Program (*RAW:SVC: gupdate > C:\Program)" means nothing to me. I have no such directory.
And I still don't know if it was an installer flaw or what avast distributes as chrome has or has not a rootkit in it that is/is-not now on my computer. Simple questions, eh?

Now, I know google says they mean no evil, and I know for sure avast does not, yet ...