Author Topic: Avast 4.8 and rootkit alert  (Read 11974 times)

0 Members and 1 Guest are viewing this topic.

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: Avast 4.8 and rootkit alert
« Reply #15 on: April 12, 2008, 11:44:30 PM »
My system logs do indeed show that the driver is created and then (after the display information is obtained) the driver is immediately deleted.  Leaving just the main process running.  The driver loading is also recorded in the boot log (ntbtlog).

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: Avast 4.8 and rootkit alert
« Reply #16 on: April 13, 2008, 12:40:56 AM »
That is fine, but it seems strange that it would be around at boot to be caught by avast Unless speedlever has procexp.exe run on boot. But equally why it is caught by avast yet yours isn't. Definitely strange.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

speedlever

  • Guest
Re: Avast 4.8 and rootkit alert
« Reply #17 on: April 13, 2008, 12:50:07 AM »
For the record, I do not have PE run at boot. I have a shortcut to it on my quick launch bar only.


speedlever

  • Guest
Re: Avast 4.8 and rootkit alert
« Reply #18 on: April 13, 2008, 12:54:10 AM »
Check this sysinternals thread for more info about this issue.


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: Avast 4.8 and rootkit alert
« Reply #19 on: April 13, 2008, 01:16:40 AM »
Thanks for taking the time to post on the Sysinternals Forums, good to get it direct from the source.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

psw

  • Guest
Re: Avast 4.8 and rootkit alert
« Reply #20 on: April 13, 2008, 07:38:32 AM »
So Avast logic is clear. Rootkit scan is launched after 120 sec from system load. If a) for any loaded driver driver file is deleted during rootkit scan (procexpXXX.sys) or b) driver process is terminated during scan (Gigabyte markfun.w32) then these drivers are meet 'hidden' criteria (file invisible - 'hidden' or process invisible - 'hidden').