Folder AVG Forums » Other topics » Virus Removal, Tools for Removing » [SOLVED] AVG Cannot Remove
Page 1 of 2 12››
June 14, 2012 12:11 [SOLVED] AVG Cannot Remove #208499
Top
alfie1303

Avatar

Novice
Join Date: 14.6.2012
Posts: 2
Can someone please assist me. The following rootkit virus was traced by AVG but can't be removed as indicated

"";"C:\Windows\System32\Drivers\spyi.sys";"atapi.sys, hooked import ataport.SYS AtaPortWritePortBufferUshort -> spyi.sys +0x2DBA0";"Object is hidden"
"";"C:\Windows\System32\Drivers\spyi.sys";"atapi.sys, hooked import ataport.SYS AtaPortReadPortUchar -> spyi.sys +0x2D224";"Object is hidden"
"";"C:\Windows\System32\Drivers\spyi.sys";"atapi.sys, hooked import ataport.SYS AtaPortWritePortUchar -> spyi.sys +0x2DA24";"Object is hidden"
"";"C:\Windows\System32\Drivers\spyi.sys";"atapi.sys, hooked import ataport.SYS AtaPortReadPortBufferUshort -> spyi.sys +0x2D35C";"Object is inaccessible."
"";"C:\Windows\System32\Drivers\spyi.sys";"Inline hook ataport.SYS DllUnload -> spyi.sys +0x5E360";"Object is inaccessible."
"";"C:\Windows\System32\Drivers\spyi.sys";"pci.sys, hooked import ntoskrnl.exe IoDetachDevice -> spyi.sys +0x625DC";"Object is inaccessible."

Any suggestions as to how to remove this
June 15, 2012 02:47 Re: AVG Cannot Remove #208649
Top
CliffL

Avatar

Novice
Join Date: 15.6.2012
Posts: 1
Same problem!..

Ditto. Just picked it up 2 days ago. The name before the ".sys" seems to change (->_____.sys). AGV acts like it removes the 1st 2 occurrences (but it doesn't), and it won't touch the rest.
scan.JPG
June 15, 2012 04:52 Re: AVG Cannot Remove #208665
Top
E__FD

Avatar

Novice
Join Date: 15.6.2012
Posts: 1
Ditto..

Just started getting this error today, every time I reboot it's a new file with the C:\Windows\System32\Drivers\sp**.sys name, with two new letters in the asterisk.

After a google search, it looks like it's related to sptd.sys used by Daemon Tools.
June 15, 2012 11:43 Re: AVG Cannot Remove #208721
Top
RandomRootkit

Avatar

Novice
Join Date: 15.6.2012
Posts: 4
Same problem here. I run daily scans - it seemed to start after the install of the most recent batch of windows updates. Other software and "sfc /scannow" finds nothing.

"";"C:\Windows\System32\Drivers\spjy.sys";"pci.sys, hooked import ntoskrnl.exe IoAttachDeviceToDeviceStack -> spjy.sys +0x62650";"Object is hidden"
"";"C:\Windows\System32\Drivers\spjy.sys";"pci.sys, hooked import ntoskrnl.exe IoDetachDevice -> spjy.sys +0x625DC";"Object is hidden"
"";"C:\Windows\System32\Drivers\spjy.sys";"atapi.sys, hooked import ataport.SYS AtaPortReadPortBufferUshort -> spjy.sys +0x2D35C";"Object is hidden"
"";"C:\Windows\System32\Drivers\spjy.sys";"atapi.sys, hooked import ataport.SYS AtaPortReadPortUchar -> spjy.sys +0x2D224";"Object is hidden"
"";"C:\Windows\System32\Drivers\spjy.sys";"atapi.sys, hooked import ataport.SYS AtaPortWritePortUchar -> spjy.sys +0x2DA24";"Object is hidden"
"";"C:\Windows\System32\Drivers\spjy.sys";"atapi.sys, hooked import ataport.SYS AtaPortWritePortBufferUshort -> spjy.sys +0x2DBA0";"Object is hidden"
"";"C:\Windows\System32\Drivers\spjy.sys";"Inline hook ataport.SYS DllUnload -> spjy.sys +0x5E360";"Object is hidden"
June 15, 2012 13:44 Re: AVG Cannot Remove #208751
Top
Bertrus

Avatar

Novice
Join Date: 15.6.2012
Posts: 3
Rootkits Infection..

Yes, me too this morning mine is via spwz.sys 6 items:-
atapi.sys, hooked import HAL.dll READ_PORT_UCHAR->spwz.sys +0x2042
atapi.sys, hooked import HAL.dll READ_PORT_BUFFER_USHORT -> etc
atapi.sys, hooked import HAL.dll READ_PORT_USHORT -> etc
atapi.sys, hooked import HAL.dll WRITE_PORT_BUFFER_USHORT -> etc
atapi.sys, hooked import HAL.dll WRITE_PORT_UCHAR -> etc
i8042prt.sys, hooked import HAL.dll READ_PORT-UCHAR -> etc

All Object is hidden. HELP! I think the i8042 concerns the keyboard & mouse driver!! frowning
June 15, 2012 14:31 Re: AVG Cannot Remove #208767
Top
RandomRootkit

Avatar

Novice
Join Date: 15.6.2012
Posts: 4
I am going to assume that this is a false alarm, I have tested with yet another AV and still found nothing. Anybody from AVG care to comment?
June 15, 2012 15:13 Re: AVG Cannot Remove #208789
Top
yikes55

Avatar

Novice
Join Date: 15.6.2012
Posts: 1
gmer result..

i know this is a double-post but this is thread i was trying for confused

EDIT.. Other post deleted.
June 16, 2012 13:03 Re: AVG Cannot Remove #208919
Top
Pokornyz

Avatar

Administrator
Join Date: 29.11.2010
Posts: 8214
Hello yikes55,

In order to analyze your situation please provide us with Msinfo output.

Thank you



AVG Team
How-To articles | FAQ | Free Support
June 16, 2012 16:21 Re: AVG Cannot Remove #208947
Top
Graeyson

Avatar

Novice
Join Date: 16.6.2012
Posts: 1
Similar problem..

I started getting this rootkit information pop up on my AVG also here are the two ones that it shows for me, i did install rosetta stone recently and then it started happening, so i am unsure if that is the cause. But ever since the notices my headsets have not been working properly at random times, at first it was Netflix (which has since fixed itself) and now it will not work with rosetta stone. Heres the two things AVG finds:

"";"C:\Windows\System32\Drivers\spci.sys";"pci.sys, hooked import ntoskrnl.exe IoAttachDeviceToDeviceStack -> spci.sys +0x65C58";"Object is hidden"

"";"C:\Windows\System32\Drivers\spci.sys";"pci.sys, hooked import ntoskrnl.exe IoDetachDevice -> spci.sys +0x65BE4";"Object is hidden"


Any help would be appreciated, i need to know if this is a legitimate threat before reformatting my operating system :/

edited post to include my msoinfo as per mod requested from other user in previous post, in case it helps. undecided
June 17, 2012 10:01 Re: AVG Cannot Remove #209055
Top
chakotay68

Avatar

Novice
Join Date: 17.6.2012
Posts: 1
Same stuff here...

im downloading anitvir by now ...

avg doesnt seem to respond to real danger ...

Page 1 of 2 12››