Author Topic: Possible false positive rootkit?  (Read 3575 times)

0 Members and 1 Guest are viewing this topic.

Offline Bowdon

  • Full Member
  • ***
  • Posts: 104
Possible false positive rootkit?
« on: November 09, 2013, 02:38:24 AM »
Hi guys,

Ok I use my laptop as a backup for my nickname on an irc network during the night. My IP address is protected. I usually set the laptop up to keep online. Anyway this morning I wake up and its saying there is a rootkit on there. The thing is that its a valid file, in the correct place. Its a Vaio old laptop. Here is a page from bleeping computers about the file. http://www.bleepingcomputer.com/startups/IcVzMon.exe-26855.html.

So is this a false positive? I've done nothing on the laptop other that connect to the trusted network. Sit on googles front page all night and then logged off in the early morning. So I can't see how I've picked up a virus or anything.

Any ideas.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Possible false positive rootkit?
« Reply #1 on: November 09, 2013, 02:56:50 AM »
Hi, if you would like to be certain it's a FP please run the following programs. AdwCleaner, MBAM, OTL, aswMBR. Please ATTACH (Do not copy and paste) the logs.

http://forum.avast.com/index.php?topic=53253.0

After that has been completed I can have the removal guys check everything out.

Also, please upload the file and test it here: www.virustotal.com
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Bowdon

  • Full Member
  • ***
  • Posts: 104
Re: Possible false positive rootkit?
« Reply #2 on: November 09, 2013, 01:12:02 PM »
Hi

thanks for replying to me. Ok I used the programs that you mentioned in the other thread. Though the interface for the OTL program was different and didnt have all those options shown in the picture. I just hit scan then saved the log. I also scanned with MBAM and saved that log. Nothing showed up on that. I then used Adwcleaner. I dont think anything showed up there either. Then lastly I used aswMBR. It scanned the computer and pulled up the same file avast did. From the looking in to the file it seems its part of sony's packages. I do have a sony laptop.

Also I scanned the file myself with avast and it said no threat file. I then uploaded the file to virustotal site and out of 47 places it scans the file only 1, Commtouch said it was a W32/Trojan.LZVW-4403 . I noticed avast is on thelist and that ticked it as ok.

Btw I should mention that when this 'rootkit' is detected its named as a Win32:Evo-gen . I've noticed there as been a few of those threads on the forums recently.

What should I do next?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Possible false positive rootkit?
« Reply #3 on: November 09, 2013, 01:21:55 PM »
Quote
What should I do next?
Make coffee and wait     ;)

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Possible false positive rootkit?
« Reply #4 on: November 09, 2013, 02:09:27 PM »
Hi,

aswMBR uses avast! engine, therefore detection are the same.

Quote
Service Image Converter video recording monitor for VAIO Entertainment C:\Program Files\Sony\Image Converter 2\IcVzMon.exe **INFECTED** Win32:Evo-gen [Susp]

These detections are FP.

Abaut OTL log, are you been able to create OTL.txt logreport? Can you attach it here?

Offline Bowdon

  • Full Member
  • ***
  • Posts: 104
Re: Possible false positive rootkit?
« Reply #5 on: November 09, 2013, 03:48:24 PM »
Ok I got OTL to work. It only created an OTL.txt log though.

I'll attach it.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Possible false positive rootkit?
« Reply #6 on: November 09, 2013, 10:21:26 PM »
Hi,
Posted logs are clean. No signs of active infection. This OTL fix shall remove some orphans keys and clean temp & cache files.



Re-run OTL.exe.

  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]
:OTL
O3 - HKU\S-1-5-21-2630728093-908478267-753119046-1006\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-2630728093-908478267-753119046-1006\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.

:FILES
dir C:\Documents and Settings\Brian\Ÿ9Ÿ9 /c
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp

:COMMANDS
[EMPTYTEMP]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
If the log doesn't appear, it can be found here:

c:\_OTL\MovedFiles\mmddyyyy_hhmmss.log