"potentially rootkit-masked registry" found by Webroot Antivirus with Antispyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by NobleTruths, Mar 22, 2009.

  1. NobleTruths

    NobleTruths Private E-2

    Hello, I am not posting a log, because I have banned the computer in question from the internet...but here is the issue. My Webroot states it found a "potentially rootkit-masked registry". Even tho Webroot says it will quarantine it....it does not (hence, I can not fix it), and a rescan will often find it again. I say "often" because sometimes it does not see it. It can be found in regular and safe mode. The Webroot log states it is found at HKLM\System\ControlSet004\Enum\PCI\VEN_14E4&DEV_4320&SUBSYS_12F4103C&REV_03\4&253a0906&0&10A4\LOGCONF || BOOTCONF (ID=0). MBAM is negative, even in full scan. Before I banned the comp from internet, I downloaded and ran SAS....this, too was negative. TrendMicro Rootkit buster is negative. Comodo BOclean hasnt cleaned this issue. My first symptom was Webroot taking greater than 20 hours to do a scan that usually takes about one and a half hours (I started the scan, and left for the day...could not believe it was still running when I returned the next day.) In safe mode, it does the scan in regular time (and still finds the issue.) I banned the comp from internet after Webroot reported a flury of attempts by some program to access known spyware sites.

    I run on XP, with HP laptop. Avira AntiVir, Comodo Firewall, Webroot with AV disabled since I used AntiVir, and other passive malware scanners.

    Since Webroot has given me a location, should i delete that key? Or is that a false posative, and my problem resides elsewhere that I need more help with? Thanks for your input.
     
  2. NobleTruths

    NobleTruths Private E-2

    Oh, I ran GMER....but i will be darned if i can figure THAT one out, lol.
     
  3. NobleTruths

    NobleTruths Private E-2

    Oh yeah, HJT is benign...i am pretty comfortable interpreting it.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Looks like a false positive to me since that looks like normal info.

    You can run our full cleaning procedure if you want to be sure but I don't think this will be detected. You could also run a few other rootkit scanners or attach your log from GMER.
     
  5. NobleTruths

    NobleTruths Private E-2

    Thanks, chaslang. Here are the logs. I am in safe mode to send them. Will have to send in two posts because there are greater than 4 logs. In the GMLog, it looked like a threat was found (? zlob, but i forget now). There should be no monitoring programs or remote access controls to this computer, I use it solely at home. Also, please let me know if I have programs that are conflicting or duplicating, and hence are not needed. Also, I will be downloading Firefox to use as a primary browser....will my protection cover me there? Any other general advice is appreciated. I have followed the steps outlined to clean my computer, already....but still get the attempts to access dangerous websites (or least, was getting them before I ran the included scans, and hence, banned the internet). Thanks for everything!!
     

    Attached Files:

  6. NobleTruths

    NobleTruths Private E-2

    Here are the additional files. If you find something of GMER (which I had to upload in 3 sections, could you please help me to learn how to interpret GMER....i enjoy the preocess of learning knew information. Thanks a ton.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing in GMER that is of concern. I still think the Webroot information is incorrect. If you have a paid version, you should talk to them about it. The registry info is pretty common type info you have many many more simliar keys in your registry; however, perhaps they are having a problem with it because it is being found in ControlSet004 which is not common but it also does not mean it is bad. In addtion Webroot did say
    which means they question it. They did not come right out and say it was bad.
     
  8. NobleTruths

    NobleTruths Private E-2

    Thanks, chaslang, but i am still having problems. After reading your last post, i tried to allow internet connection on that computer, but almost instantly i got another flurry of warnings from my protection programs that attempts were being made (and blocked) to websites of known spy/malware. And, yes, they were dangerous websites. It does not appear that there have been any views of the GMLog. Could you please review that, and recommend other tools i can run and post, to help us solve this problem? Thanks.
     
  9. NobleTruths

    NobleTruths Private E-2

    As a new update, chaslang, I ran the following on-line scanners:

    1) Kaspersky. It found:

    C:\ProgramFiles|TrendMicro|HijackThis\Backups\Backup-20081007-090248-835-PowerRegScheduler.exe

    Which was inactive, but I deleted it any way.

    2) BitDefender. It found:

    C:\SWSetup\hplmgEnh|delink.exe (Gen: Trojan.Heur.VB.1024DBEBEB)

    Which BitDefender deleted.

    3) F-Secure. Which found nothing.

    I am not allowing non-safe mode internet still, tho. Anything on GMLog? Thanks.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of your logs show any problems. Perhaps you should uninstall your Comodo Firewall and then reboot and reinstall it to have it reinitialize to where it asks you for permission to access the internet again for various applications. Perhaps you have something allowed that should not be. In addition, there is obviously a severe short coming in your WebRoot SpySweeper software if something is really wrong on your PC since it is not finding any real problems and fixing them.

    I already stated in my last message that the log was clean. See msg # 7.

    If you wish, I can try to give you a procedure that will remove the registry key that Webroot is mentioning. But I cannot be responsible for any of your hardware that may no longer work after remove that key since it appears to be related to something on your PCI bus.

    If you wish to run additional scans to check further, try the below two and attach logs from them.

    Using Dr.Web CureIt

    Trend Micro Housecall
     
    Last edited: Apr 2, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds