Avg 2011 have detect rootkit

Discussion in 'Malware Help (A Specialist Will Reply)' started by odlspike, Dec 8, 2010.

  1. odlspike

    odlspike Private E-2

    Hi,

    First of all, english is not my main language but i will try to be clear !

    Its the second time that i need help !

    Here's the problem :

    Yesterday a friend of mine have connected his PSP in my computer to check some file from his memory card .... BAM ! AVG detected 2 infections but only 1 was removed !

    I scan all my compter with AVG = Rootkit detected but was unable to clean it ... damn !

    I decide to comeback here in hope to receive again some helpful advice to remove this " crap " !


    I had 2 problems with the Xp cleaning procedure :

    1- with Combofix .... i had a popup message that Combofix had detected rootkit ! I clicked "ok" at the popop, all my desktop desapears and nothing happened even after 20-30 minutes .. So i decided to " hard " reboot my pc and the rest of the combofiix procedure finish ! Dont know if the combfix procedure was ok but i have a log file !

    2- with Mgtools.exe i had the " error message type 4 " cause i didnt have net passport ! Now i have install it ! I have also the log but tell me if i need to execute again Mgtools.

    Here's the scans logs from the " XP cleaning procedure "

    I will put also my scan from AVG telling me about the rootkit infection !
     

    Attached Files:

  2. odlspike

    odlspike Private E-2

    here's the Mgtools log and my Avg " rootkit " scan log !

    Hope to resolve this ...

    I fornat my system 2 weeks ago to restart " clean " ! .. damn !

    Tnx in advance !
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have a rootkit infection. You have Sandboxie 3.51.02 installed and that is what AVG is falsely detection.

    The only problem seen in your logs is that you have no protection software installed. Sandboxie is not a replacement for antivirus, antispyware, and a good firewall.
     
  4. odlspike

    odlspike Private E-2

    Thnx Chaslang for your quick response !

    In order to run Combofix i had to remove AVG 2011, i try only to disable it but Combofix didnt want to run with it !

    But yeah i always have an anti-virus running in my pc but i only have windows xp firewall !

    And always scan every file with AVG and Malwarebytes !

    Xp Firewall only .... its good or not ?

    Ok if i understand, AVG will always flag Sandboxie has a rootkit ?

    When Combofix alert me about rootkit, it was also false flag also ?

    may i conclude that my pc is " clean " ?

    will wait your awnser before doing anything ?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not!

    Correct.

    Correct or could have been due to Sandboxie or Daemon Tools.

    Correct.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  6. odlspike

    odlspike Private E-2

    Unfortunaly i'm stuck on final step #2

    I put "%userprofile%\Desktop\combofix" /uninstall in " run " but it only execute again Combofix ! :(

    Do i need to remove AVG again ?

    And btw i install Comodo for my firewall !
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just skip it. MGclean.bat should remove it. If not, you can manually delete any leftovers at the end.
     
  8. odlspike

    odlspike Private E-2

    Thnx Chaslang for your time and expertise !

    Its really REALLY appreciated !

    Thnx !
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds