Author Topic: Scans 1 and 2: Rootkit positive; Scan 3: no issues found  (Read 2671 times)

0 Members and 2 Guests are viewing this topic.

Offline Jp41

  • Newbie
  • *
  • Posts: 8
Scans 1 and 2: Rootkit positive; Scan 3: no issues found
« on: April 23, 2019, 01:57:05 AM »
Please be gentle, I am not computer savvy and I don't know how to create a scan log.  :D
But I ran a full scan today and got THREE infected files detected (although two of them seem identical?):

C:\Windows\Temp\inv7EE6_tmp\Executables\DRVUpdate.exe
  Rootkit: hidden process
C:\Windows\Temp\inv7EE6_tmp\Executables\DRVUpdate.exe
  Rootkit: hidden process
C:\Windows\Temp\inv7EE6_tmp\Executables\APPUpdate.exe
  Rootkit: hidden process

I tried to resolve them but kept getting the result: "Error: Access is denied (5)"

Frantic, I ran the full scan again.  But interestingly, I only got one infected file result instead of three:

C:\Windows\Temp\inv7EE6_tmp\Executables\DRVUpdate.exe
  Rootkit: hidden process

Again, I was unable to resolve the issue and got error (5) again.

So I said to myself, hmm, this is getting better all by itself, so I did a full scan again and came up with NO infected files detected.  Were the first two false positives? Or is there something lurking?  I am afraid to use my computer at all.  PLEASE HELP ME!!

Offline Jp41

  • Newbie
  • *
  • Posts: 8
Re: Scans 1 and 2: Rootkit positive; Scan 3: no issues found
« Reply #1 on: April 23, 2019, 04:02:07 AM »
Argh, so 3 hours later i do a scan full scan again. And this time now there are two infected files reported:

C:\Windows\Temp\inv7EE6_tmp\Executables\DRVUpdate.exe
  Rootkit: hidden process
C:\Windows\Temp\inv7EE6_tmp\SCSI_ODD\SCSIUpdate.exe
  Rootkit: hidden process

And again, I get "Error: Access is denied (5)"

Please some kind soul let me know what I should do or what I should post so you can tell what is wrong.

Thanks!

Offline Jp41

  • Newbie
  • *
  • Posts: 8
Re: Scans 1 and 2: Rootkit positive; Scan 3: no issues found
« Reply #2 on: April 23, 2019, 04:22:24 AM »
So I ran a full virus scan one more time, only 10 minutes after the scan that said 2 infections. And this time it said no infected files. So this is very frustrating.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Scans 1 and 2: Rootkit positive; Scan 3: no issues found
« Reply #3 on: April 23, 2019, 06:40:52 AM »
Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Jp41

  • Newbie
  • *
  • Posts: 8
Re: Scans 1 and 2: Rootkit positive; Scan 3: no issues found
« Reply #4 on: April 23, 2019, 12:19:15 PM »
Thanks Asyn. I downloaded the two programs and ran the logs. I wanted to turn off the virus software before running them but could not figure out how -- so Avast and Windows defender were both running while I ran these logs (in case that is relevant).

Offline Jp41

  • Newbie
  • *
  • Posts: 8
Re: Scans 1 and 2: Rootkit positive; Scan 3: no issues found
« Reply #5 on: April 24, 2019, 01:27:32 AM »
I attached the three logs as attachments to my prior posting. So if anyone could please =review them and let me know?
Late last  night when I did a full scan again, Avast identified two infected file results and was unable to delete them. But today another scan shows not issues.  I expect that if I scan again there will be more infected files. It keeps going back and forth.  Thanks for your help!
« Last Edit: April 24, 2019, 04:25:17 AM by Jp41 »

Offline Jp41

  • Newbie
  • *
  • Posts: 8
Re: Scans 1 and 2: Rootkit positive; Scan 3: no issues found
« Reply #6 on: April 24, 2019, 12:56:02 PM »
Please if some kind soul could review my logs and let me know any information. I am not using my computer and am considering doing a factory reset. Any thoughts would be appreciated.

Online mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5606
  • Spartan Warrior
Re: Scans 1 and 2: Rootkit positive; Scan 3: no issues found
« Reply #7 on: April 24, 2019, 04:52:26 PM »
A malware expert has been notified.  Please be patient.  You've done what you could, now you've to wait a bit.
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline Jp41

  • Newbie
  • *
  • Posts: 8
Re: Scans 1 and 2: Rootkit positive; Scan 3: no issues found
« Reply #8 on: April 25, 2019, 02:33:12 AM »
Thanks mchain.  I am still getting alternating Avast results of no issues and then later results with infected files and then later results with no issues. So here are a new battery of scan logs from malware bytes and frst attached . . .

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: Scans 1 and 2: Rootkit positive; Scan 3: no issues found
« Reply #9 on: April 28, 2019, 09:40:34 AM »
  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {374A62B8-8736-4756-969E-4FB6922E76A8} - System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => C:\WINDOWS\TEMP\DeleteFolderTask.exe <==== ATTENTION
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

Offline Jp41

  • Newbie
  • *
  • Posts: 8
Re: Scans 1 and 2: Rootkit positive; Scan 3: no issues found
« Reply #10 on: April 30, 2019, 04:51:04 AM »
Thanks for all your help, but I couldn't wait, and so I wiped my computer, rebooting form a USB and removed all partitions, and reinstalled Win 10. Seemed the only safe thing to do.