AVG8 won't update, Rootkit.Agent.V found

Discussion in 'Malware Help (A Specialist Will Reply)' started by a_hansen, Mar 30, 2009.

  1. a_hansen

    a_hansen Private E-2

    Hi Chaslang et al,

    I have encountered a problem. Since a week back in time my AVG8 won't update, giving a "connection to server failed" message. Uninstalling and updating to the current AVG8.5 has not resolved this issue. When posting in the AVG forum it has been established that I cannot actually connect to the avg update server address of guru.avg.com, which will give a "webpage cannot be displayed" message.

    My system shows no general signs of being infected, but scanning with my already installed MBAM revealed three instances of "Rootkit.Agent.V":

    C:\WINDOWS\system32\dllcache\wadv07nt.sys
    C:\WINDOWS\system32\drivers\wadv07nt.sys
    C:\WINDOWS\ServicePackFiles\i386\wadv07nt.sys

    I have now run the logs required by you and appreciate your response. Thank you.
     

    Attached Files:

  2. a_hansen

    a_hansen Private E-2

    MG Tools log.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean, except for these file:
    c:\windows\system32\xa1541843.exe
    c:\windows\system32\xa1540796.exe

    I do not know what these are, so use windows explorer to find them and right click them and check the properties.....tell me what it belongs to.
     
  4. a_hansen

    a_hansen Private E-2

    Hi Tim,
    thanks for your response. Those two files belong to my Nik Sharpener software. Since March 20, I still cannot update my AVG8 installation. How can I resolve this issue when my logs come out clean? What do you think of that Rootkit.Agent.V? Is there any point in running gmer or some other additional scanner?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run MBAM to see if it does still exist. People have had problems with AVG8...so it may be a program problem not related to malware. Attach the log.
     
  6. a_hansen

    a_hansen Private E-2

    MBAM came out clean. Since my inability to update AVG8 is linked to the fact that I am actually unable to access the AVG update server guru.avg.com using IE7, what would cause that? How could a certain IP address be blocked like that? Should I look into some registry entry being affected or just ditch AVG, which I have used for years? Anyway, thanks for your time this far Tim.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds