Author Topic: Rootkit Infection - Avast cannot remove the malware - Only Avast detects it  (Read 2439 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Hello! I would like to share this problem and try to find a solution. Avas is detecting this:

01:07:37.787    Disk 0 scanning C:\WINDOWS\system32\drivers
01:07:46.424    File: C:\WINDOWS\system32\drivers\ipfltdrv.sys  **INFECTED** Win64:Evo-gen [Susp]
01:07:59.298    File: C:\WINDOWS\system32\drivers\wanarp.sys  **INFECTED** Win64:Evo-gen [Susp]

However other Rootkit's detection tools such as Malwarebyte and mcafee are not detecting anything.

If you ask Avast to remove it, it says the removal was successful, however after another quick scan it will be there again.

A boot scan has not showed anything.

What should I do?

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Don't listen to drtweak.
Those files seem to be legitimate windows drivers.
Please report it to avast:
https://www.avast.com/contact-form.php?subject=VIRUS-FILE

Offline CraigB

  • Avast Überevangelist
  • Serious Graphoman
  • *****
  • Posts: 11239
  • No support PM's thanks
drtweak also doesn't have permission to suggest tools that are only to be used under the guidance of a malware specialist.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
@    Leonardo Ferreira
Combofix is a powerful tool that that could also do harm to your system, it should only use under guidance of a malware removal specialist.

In this forum it means 'qualified' malware removal specialists. A list of those qualified is given here, https://forum.avast.com/index.php?topic=53253.0.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security