Author Topic: (SOLVED) AVGxxxxx.SYS Leftover Drivers: Avast Rootkit False Postive  (Read 12755 times)

0 Members and 1 Guest are viewing this topic.

thekochs

  • Guest
I'm a long time AVG user now switching all my PCs to Avast....two down more to go.
I really like Avast and have run scans on both machines...clean expect in full scan or on boot after windows comes up Avast shows a rootkit found for what looks like three legacy AVG files, AVGldx86.sys, AVGmfx86.sys, AVGtdix.sys in the Windows/systems32/drivers directory.  Since i'm not trying to cause any BSOD I thought I'd ignore using the Avast popup...they still show/alert on a reboot....I also used full scanner with the rootkit in Avast windows and it asked to reboot.....they still show back up.  I've not done a boot time scan and this would be last resort.  I assume others have run into this since I'm sure many folks are moving away from AVG.

Can you give guidance ?

Attached is pic of Avast popup.

Thx.
« Last Edit: July 18, 2011, 09:56:09 PM by thekochs »

com155

  • Guest
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #1 on: July 05, 2011, 05:56:32 AM »
so a rootkit huh? try this:

Download aswMBR.exe ( 1.8MB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan

 
On completion of the scan click save log, save it to your desktop and post in your next reply

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #2 on: July 05, 2011, 05:59:26 AM »
have you uninstalled AVG before installing avast ?
have you run a removal tool to clear all leftovers ?

removal tools can be found here
http://thewebatom.net/uninstallers/security-software/

com155

  • Guest
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #3 on: July 05, 2011, 06:05:42 AM »
oh huh!!!!!i almost forgot to ask this.thanks,pondus.....

thekochs

  • Guest
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #4 on: July 05, 2011, 06:09:36 AM »
I did uninstall AVG.....even ran CCleaner afterwords.....files and registry too.

I just ran the Avast boot scanner and here are results.....puzzling since I am still getting this Avast popup at Windows boot...takes couple minutes to show up.

07/03/2011 16:51
Scan of all local drives

Scanning aborted
Number of searched folders: 445
Number of tested files: 2504
Number of infected files: 0

----------------------------------------
07/04/2011 22:55
Scan of all local drives

Number of searched folders: 11308
Number of tested files: 627504

Number of infected files: 0


I will try to run the cleanup uninstaller per the link above....was looking for it on AVG.

Is the MBR program OK to run for scan mode ?....non instrusive ?

Thx !!!
« Last Edit: July 05, 2011, 06:13:01 AM by thekochs »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #5 on: July 05, 2011, 06:10:22 AM »
oh huh!!!!!i almost forgot to ask this.thanks,pondus.....
almost ?.......  ::)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #6 on: July 05, 2011, 06:11:19 AM »
Run the AVG removal tool and reboot

thekochs

  • Guest
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #7 on: July 05, 2011, 06:37:35 AM »
I ran the AVG removal tool and DOS window came up....alot of items scrolled past saying it was removing, etc....then exit.  I then did a manual reboot. After 2-3 minutes into Windows the same Avast popup shows.....in my first post of thread.  As FYI, I was running AVG9....since AVG10-2011 has SOOOO many issues...this uninstaller looks to be 2011 by name....does that matter ?

Also, why when I choose from Avast's popup to ignore does it still come up ?

Thx !

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #8 on: July 05, 2011, 06:43:14 AM »
hmmmmm....not sure

you find the latest here   http://www.avg.com/us-en/utilities


i would guess if you run latest it shold remove all versions...


if you browse to that location, are the files still there after running the tool ?
« Last Edit: July 05, 2011, 06:48:57 AM by Pondus »

thekochs

  • Guest
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #9 on: July 05, 2011, 07:00:02 AM »
They are hidden files so even if I go into Explorer and uncheck the "see O/S files" and look in that directory they are not there.....but Avast is either still seeing them or has some log/buffer that keeps this popup coming up.

Is there something in Avast to ignore these or clear this log/popup ?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #10 on: July 05, 2011, 07:09:50 AM »
I will send a PM to DavidR but it a may take some time before he enters the forum


not sure if this will make any difference but have you tried removing avast with the removal tool reboot and reinstall  http://www.avast.com/en-no/uninstall-utility


thekochs

  • Guest
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #11 on: July 05, 2011, 07:37:09 AM »
This is exactly what I was about to do....but it's ~2am,EDT in USA and need to hit the bed.
I'll check late tommorow this thread for any suggestions prior to uninstall & re-install of Avast.

Af FYI....
When I look at the AVG remover log it says that avgldx86, avgmfx86, avgtdix are not present.
Some log examples/excerpts......(since log is too big to post)
2011-07-05 04:17:04,531 INFO Processing service AvgLdx86, it can take several minutes...
2011-07-05 04:17:04,562 INFO Service AvgLdx86 is not installed
2011-07-05 04:17:04,593 DEBUG Service AvgLdx86 RegCleanup
2011-07-05 04:17:04,625 DEBUG Registry keys for service AvgLdx86 are not present
2011-07-05 04:18:04,265 DEBUG Key SYSTEM\ControlSet001\services\avgldx86 not found

If I run a Avast boot scan it finds nothing as well.
However, on Windows boot I still get the Avast popup shown on first post.
Also, just ran Avast FULL SCAN...it finds them...see attached.
« Last Edit: July 05, 2011, 07:51:56 AM by thekochs »

com155

  • Guest
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #12 on: July 05, 2011, 09:31:43 AM »
OK, another tool to check for other types of rootkit.


  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
     

     
     
  • If an infected file is detected, the default action will be Cure, click on Continue.
     

     
     
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
     

     
     
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
     

     
     
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #13 on: July 05, 2011, 10:05:19 AM »
have googled the file names and found this. also see under important


avgldx86.sys file information:  http://www.file.net/process/avgldx86.sys.html

avgmfx86.sys file information: http://www.file.net/process/avgmfx86.sys.html

avgtdix.sys file information: http://www.file.net/process/avgtdix.sys.html

thekochs

  • Guest
Re: Newbie Help Needed: AVGxxxxx.SYS Avast Rootkit Message
« Reply #14 on: July 05, 2011, 01:28:08 PM »
Ok...thanks.....I've run MalwareBytes on the machine many times prior......plus this is happening on other PCs too.
I'll try TDSSKiller and also run Malware Bytes but could these be false positives within Avast ?
How do you submit something that has no file ?

If they are real rootkit and Avast sees why does it not remove ?
Also, strange the Avast scanner can see but the boot scanner cannot.

« Last Edit: July 05, 2011, 01:57:34 PM by thekochs »