Folder AVG Forums » Other topics » Virus Removal, Tools for Removing » AVG 2014 Sysenter Hook Issue..
Page 1 of 2 12››
September 5, 2013 02:05 AVG 2014 Sysenter Hook Issue.. #233330
Top
VodkaDoll

Avatar

Novice
Join Date: 5.9.2013
Posts: 4
Hi, I'm not sure where to post this or who to go to so I chose you AVG Forums...I switched my free 2013 version to the 2014 and after running a scan AVG (specifically the rootkit scan) has found 8 threats that I cannot seem to find on google.
This is what I'm seeing:
"";"SYSENTER hook -> 0xFFFFF8000387EC40, <unknown>";"Infected"

I am running on an Asus K55A, Windows 7
The AVG product version code is 2014.0.4116, virus database version 3599/6639..
I'm running an intel core i5..

I really don't know what I'm doing at this point because I cannot get the threats to go away...and on a side note, I just got done doing a system factory restore. Please, I really need some help...I've added the overview...I don't know if that helps at all. Thank you.
September 5, 2013 04:12 Re: AVG 2014 Sysenter Hook Issue.. #233331
Top
lgfrantz

Avatar

Novice
Join Date: 5.9.2013
Posts: 1
Windows Defender..

Try using the Windows 7 software called "Windows Defender" to do your scan. AVG 2014 turned off the "Windows Defender" when I installed AVG 2014 Free Antivirus. I would be more likely to believe what "Windows Defender" returns in its scan of your computer, than the AVG scan software. The AVG scan might be returning a false result. smile
September 5, 2013 08:29 Re: AVG 2014 Sysenter Hook Issue.. #233339
Top
Pokornyz

Avatar

Administrator
Join Date: 29.11.2010
Posts: 8235
Hello VodkaDoll,

In order to analyze your issue please provide us with more information (Msinfo output, GMER scan result).

Thank you.



AVG Team
How-To articles | FAQ | Free Support
September 5, 2013 19:07 Re: AVG 2014 Sysenter Hook Issue.. #233376
Top
VodkaDoll

Avatar

Novice
Join Date: 5.9.2013
Posts: 4
Reply..

I have added the msinfo compressed file as requested...I did download avast antivirus and let it scan which did not find any problems with my laptop..
September 6, 2013 23:16 Re: AVG 2014 Sysenter Hook Issue.. #233424
Top
VodkaDoll

Avatar

Novice
Join Date: 5.9.2013
Posts: 4
And here is the GMER scan information...it did say three things couldn't be scanned due to being active but..this is what I've got.

GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-09-06 19:14:33
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JE4O 698.64GB
Running: gmer.exe; Driver: C:\Users\Lauren\AppData\Local\Temp\uxdirpob.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 544 fffff800033a6000 45 bytes [00, 00, 16, 02, 4E, 74, 66, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 591 fffff800033a602f 10 bytes [00, 01, 00, 06, 00, 00, 00, ...]

---- User code sections - GMER 2.1 ----

.text C:\Windows\SysWOW64\ntdll.dll[1376] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075361465 2 bytes [36, 75]
.text C:\Windows\SysWOW64\ntdll.dll[1376] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753614bb 2 bytes [36, 75]
.text ... * 2
.text C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe[1480] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075361465 2 bytes [36, 75]
.text C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe[1480] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753614bb 2 bytes [36, 75]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2140] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075361465 2 bytes [36, 75]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2140] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753614bb 2 bytes [36, 75]
.text ... * 2

---- Threads - GMER 2.1 ----

Thread C:\Windows\SysWOW64\ntdll.dll [1376:1420] 0000000000f93a09

---- Disk sectors - GMER 2.1 ----

Disk \Device\Harddisk0\DR0 unknown MBR code

---- EOF - GMER 2.1 ----


Please, get back to me AVG! I really don't want to get rid of your stuff because it wants to kill good things on my laptop! Don't make me regret buying a product from you...Thanks.
September 9, 2013 02:49 Re: AVG 2014 Sysenter Hook Issue.. #233480
Top
monappi

Avatar

Novice
Join Date: 9.9.2013
Posts: 1
Eerie... I'm running an Asus N56V, just did a restore to factory settings, installed AVG 2014 free edition, did an initial whole system scan and it returned 16 of the same sysenter hook infections as detailed above. What...?
September 9, 2013 12:49 Re: AVG 2014 Sysenter Hook Issue.. #233514
Top
Pokornyz

Avatar

Administrator
Join Date: 29.11.2010
Posts: 8235
Hello VodkaDoll,

Please use AVG Rescue CD and restore your MBR as described here (refer to Offline mode using AVG Rescue CD). Then, scan the system using AVG Rescue CD and remove detected threats.

Should the infection be still present after restart, please provide us with new GMER anti-rootkit scan result and new AVG full computer scan result export. Also, please provide us with a screenshot of your partition table listing as follows:
1. Run the AVG Rescue CD.
2. Switch to the linux terminal by the left ALT + F2 key combination.
3. Login as the root user.
4. Execute the fdisk -l command.
5. Take a picture of your screen and attach it to your reply.
6. Use the left ALT + F1 key combination to switch back to the AVG Rescue CD menu.

Thank you.



AVG Team
How-To articles | FAQ | Free Support
September 12, 2013 14:04 Re: AVG 2014 Sysenter Hook Issue.. #233657
Top
leezy88

Avatar

Novice
Join Date: 12.9.2013
Posts: 1
same problem..

Hi, I seem to having the same problem and was wondering if I should also try to restore my MBR?

New laptop, downloaded AVG 2014 for initial scan
8 sysenter hook -> 0xFFFFF800038811C0 Infected Part of Operating System. Two factory restores, same thing upon further scan.

I'm running on an Acer TravelMate P253-MG, Windows 7.
AVG version 2014.0.4117, virus database version 3604/6656
I'm running an intel core i5.

Hope you can get back to me quickly.
September 13, 2013 22:52 Re: AVG 2014 Sysenter Hook Issue.. #233744
Top
SIObserver

Avatar

Novice
Join Date: 25.8.2009
Posts: 2
AVG Internet Security 2014..

I Just received a new i5 computer from HP. I filled in the proper information on it and registered. I then uninstalled the bundled Norton Internet Security and installed a trial of AVG Internet Security 2014 in anticipation of purchasing several licenses for five people and about twelve computers. As soon as the AVG was installed I ran the initial scan and got eight hits. All of them were SYSENTER hook related. I then Did a total system recovery and followed the same procedure as before. Again I got the same eight SYSENTER hook hits. I am convinced these are false positives. I find it difficult to believe that the exact same virus would infect this brand new computer twice in exactly the same way on two different clean installs. Please don't tell me that I should go ahead and delete these files. I think they are part of Hewlett-Packards additions to the Windows 7 Home Premium 64 bit operating system. I have not yet checked with HP since it is late Friday but I will do so on Monday. AVG has more false positives than any Antivirus software I ever have used. Please come up with a different solution than deleting these files. I looked but could not find where the files reside on the hard drive. If you know please tell me so I can create an exception or else I will not be able to complete my intended purchase of about twelve licenses of AVG Internet Security 2014. Neither Windows Defender or Microsoft Security Essentials has a problem with these files. One other thing I am hardly a novice so please don't try patting me on my pointed head.
September 13, 2013 23:52 Re: AVG 2014 Sysenter Hook Issue.. #233747
Top
BIG AL 43

Avatar

Moderator
Join Date: 18.6.2009
Posts: 23811
SIObserver wrote
I am convinced these are false positives

Have a look @ this Announcement post link How To Handle Suspicious False Positive Detection? & please follow the appropriate instructions....


AVG Forums Volunteer ModeratorAVG Forum member since - Nov. 27, 2004My total posts on the Old AVG Free Forum - 27,063
Alan
How-To Articles | FAQ | Free Support
Page 1 of 2 12››