Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

2 Rootkits Id'ed By Avg Rootkit


  • Please log in to reply
3 replies to this topic

#1 working girl

working girl

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:memphis
  • Local time:08:39 PM

Posted 18 June 2007 - 01:50 PM

C:\PROGRA~1\SYMANT~1\VIRUS~1\20000616.005\NAVENG.Sys

C:\PROGRA~1\SYMANT~1\VIRUS~1\20000616.005\NavEx15.Sys


They were identified as "hidden driver file" types.

I am running Windows XP Home SP2 and had within past few hours run AVG Spyware and last night Spysweeper.

The warnings about "check to remove" are pretty scary. :thumbsup:

What should I do?

BC AdBot (Login to Remove)

 


m

#2 DaveM59

DaveM59

    Bleepin' Grandpa


  • Members
  • 1,355 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:TN USA
  • Local time:07:39 PM

Posted 18 June 2007 - 02:53 PM

Those are both legitimate files. They are part of the Norton Internet Security suite. See this page in Symantec support where the files are mentioned as two of the Symantec Security Resonse AV (antivirus) engines.

I am not sure why Symantec chose to hide the files, but I understand why AVG antirootkit picked them up. Most rootkits are hidden driver (.sys) files, but not all hidden driver files are malware.

Hope this puts your mind at ease.

Safe computing,

Dave

#3 working girl

working girl
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:memphis
  • Local time:08:39 PM

Posted 18 June 2007 - 03:01 PM

thanks so much. I appreciate it. Made a teenysie donation in appreciation. Alyce

#4 DaveM59

DaveM59

    Bleepin' Grandpa


  • Members
  • 1,355 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:TN USA
  • Local time:07:39 PM

Posted 18 June 2007 - 03:14 PM

You're welcome -- and thanks for the donation!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users