Author Topic: Over 1000 files infected? Rootkit? Please help.  (Read 2452 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Over 1000 files infected? Rootkit? Please help.
« on: February 13, 2017, 08:51:24 PM »
Hi, I got a pop up from advast today saying it detected some unknown virus.. I ran a scan and it found over 1000 files infected. This has never happened to me ever. I searched online about it and not sure how to handle it. I will attach a picture of the scan.. I am not sure if it is safe to delete or what the virus even is? If someone could please help me and tell me what I should do? Thank you.
https://gyazo.com/b024a9c3dfd515d1451640ba33715a71

Also, I ran malawarebytes and it detected nothing.
« Last Edit: February 13, 2017, 09:14:17 PM by butterflikissies »

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Over 1000 files infected? Rootkit? Please help.
« Reply #1 on: February 13, 2017, 09:32:25 PM »
Reboot your system, update Avast definitions and rescan your system.  This looks like a False Positive but we should wait to see if Avast personnel respond here.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Over 1000 files infected? Rootkit? Please help.
« Reply #2 on: February 13, 2017, 09:44:45 PM »
I just installed Malawarebytes anti rootkit beta and running it right now to see if it picks up anything. I honestly don't know what I am doing but found some website with a bunch of other scanning programs to detect them. I will wait for Avast to reply before I do anything. Thank you for replying!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Over 1000 files infected? Rootkit? Please help.
« Reply #3 on: February 13, 2017, 09:47:06 PM »
IndicatorOSD.exe 
The process known as OSD Tool belongs to software Dell KM632 Wireless Keyboard Caps Lock or OSD Tool by DELL

I would say this is a False positive from avast, probably on a dell update

Quote
I honestly don't know what I am doing but found some website with a bunch of other scanning programs to detect them.
follow instructions given by malware expert @dbrisendin  dont play on your own




« Last Edit: February 13, 2017, 09:49:43 PM by Pondus »

REDACTED

  • Guest
Re: Over 1000 files infected? Rootkit? Please help.
« Reply #4 on: February 13, 2017, 09:53:47 PM »
Yes, I am just running the scan to see. I am not doing anything and I will be following dbrisendin's advice and wait for Avast to reply. Thank you.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Over 1000 files infected? Rootkit? Please help.
« Reply #5 on: February 13, 2017, 09:59:05 PM »
Then reboot / update and do a new avast scan, not any other tool unless instructed


REDACTED

  • Guest
Re: Over 1000 files infected? Rootkit? Please help.
« Reply #6 on: February 13, 2017, 10:00:28 PM »
OMG... I forget to check do nothing when it was set to automatic fix when I closed it. But never clicked apply to fix automatically... and it said it would fix it with a reboot. Any way I can prevent it from doing that now? I am not familar with Avast that much..  :-\
« Last Edit: February 13, 2017, 10:25:03 PM by butterflikissies »

REDACTED

  • Guest
Re: Over 1000 files infected? Rootkit? Please help.
« Reply #7 on: February 13, 2017, 11:19:43 PM »
I updated and ran another scan and everything is good!!! Thank you both very much!! Have a great day!  :)

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2295
Re: Over 1000 files infected? Rootkit? Please help.
« Reply #8 on: February 14, 2017, 09:00:32 AM »
Hello,
send us detected files using https://www.avast.com/false-positive-file-form.php and mention link to this forum thread.

Thanks.
Milos