Results 1 to 10 of 21
- 03-14-2010 #1
"\Device\mfeavfk01.sys" - clean or infected rootkit?
I installed a trial version of AVG antivirus to my sister's laptop and it flagged a warning on the item:"\Device\mfeavfk01.sys" as a hidden driver rootkit. I wonder this might be a false positive as it looks like driver for mcafee.I googled but nothing refer to that so far. I presume that it is clean but in no way sure about it.Please help to identify this if anyone know about it.Thank you.
- 03-14-2010 #2*nix Technical Support
Achievements:




Awards:
- Join Date
- Jan 2009
- Location
- /home/hellnoire
- Posts
- 10,231
- Liked
- 293 times
Are you using McAfee with AVG?
You're not supposed to run two anti-viruses at the same time... it leads to problems like this.
pacman -Syyu life not found in sync db
- 03-14-2010 #3
mfeavfk01.sys does seemed like belonging to McAfee.
Try uploading the file to Virustotal.com and have it scanned with multiple antivirus.
And like Hellnoire said, it is a general rule not to install multiple antivirus.
- 03-14-2010 #4
Hi
The following driver is installed by Mc Afee
c:\windows\system32\drivers\mferkdet.sys
As Raymond said the driver flagged as hidden doesn't belong to Mc Afee
If the path is like \Device\Harddisk0\ it is a Master Boot Record Rootkit
Please download MalwareBytes' AntiMalware free to your desktop, install and update it, then run a scan and post the log file (copy and paste), please.
Now download to C:\
MBR rootkit detector (by Gmer)
http://www2.gmer.net/mbr/mbr.exe (if your antivirus gives you a warning, ignore it since "mbr.exe" is clean)
now Win + R (Start)>Run type "C:\mbr.exe" (without brackets) hit Enter.
If you get something like:
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
malicious code @ sector 0x132c0ab6 size 0x1ce !
copy of MBR has been found in sector 62 !
Your system is infected by a MBR rootkit
In case, reboot in safe mode (hit F8), then: Win + R (Start)>Run type "C:\mbr.exe -f" (without brackets) hit Enter.Last edited by leofelix; 03-14-2010 at 01:00 PM.
"If you really want something in this life, you have to work for it. Now, quiet! They're about to announce the lottery numbers..." - Homer Simpson
- 03-14-2010 #5
I couldn't find that file in that computer,even through windows search. But I found a similar one named "mfeavfk.sys" in system32/drivers folder. I uploaded that to virustotal.Below is the link for that result:
http://www.virustotal.com/analisis/a...2a5-1268549950
no virus found.
@leofelix: I am still waiting malwarebytes to finish its scanning.
this is the scan result from MBAM:
Malwarebytes' Anti-Malware 1.44
Database version: 3865
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
3/14/2010 3:44:51 PM
mbam-log-2010-03-14 (15-44-51).txt
Scan type: Full Scan (D:\|)
Objects scanned: 179330
Time elapsed: 7 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
the result from GMER:
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
all scan look like clean and safe.Last edited by dredge; 03-14-2010 at 04:51 PM. Reason: Automerged Doublepost
- 03-15-2010 #6
- 03-15-2010 #7
When we're talking about AVG probably it's a false positive. Anyways did you check this file on virustotal cuz by it's name and extension it looks like a malware.

Screw Google! Ask me!
- 03-15-2010 #8*nix Technical Support
Achievements:




Awards:
- Join Date
- Jan 2009
- Location
- /home/hellnoire
- Posts
- 10,231
- Liked
- 293 times
I'm still thinking he's running two AVs at the same time... I'd like a response on that too.
- 03-15-2010 #9
- 03-15-2010 #10*nix Technical Support
Achievements:




Awards:
- Join Date
- Jan 2009
- Location
- /home/hellnoire
- Posts
- 10,231
- Liked
- 293 times
Chances are good, once you do what the bolded text says, it will no longer have a problem.
Never run two antiviruses at once. I don't know how many times I've had to say that over the past few months, but I'm certainly getting sick of those who think they can and get away with no bugs. If you can, congrats, power to you. But for most users, you're going to run into a billion and one other bugs. So DON'T DO IT.
Similar Threads
-
Google to Launch "MAJEL" to compete with "Siri" Technology of Apple !
By Mjj in forum Mobile PhoneReplies: 0Last Post: 12-16-2011, 10:23 PM -
Infected with Virus named "ViP Al Ain"
By smiley in forum Spyware/VirusesReplies: 14Last Post: 09-08-2010, 12:03 AM -
finding "hidden" device drivers on you PC
By Rusty in forum General ForumReplies: 1Last Post: 05-02-2009, 12:27 PM -
"Connection Interrupted" and " Failed to Connect"
By Michael Y in forum NetworkReplies: 2Last Post: 09-30-2008, 05:48 PM


LinkBack URL
About LinkBacks





Reply With Quote
