Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus batch bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard mouse network printer problem ram registry router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Solved: Windows Defender finds somthing

Reply  
Thread Tools
lunarlander's Avatar
Computer Specs
Senior Member with 3,492 posts.
 
Join Date: Sep 2007
07-Apr-2009, 11:06 AM #1
Solved: Windows Defender finds somthing
Hi,

Just did a event log review and Windows Defender found something. EventID is 3004. It found a "service:rkpavproc1" which is presumably newly added and it says it looks suspicious.

Googled it and the Prevx site says it is a worm. And it has an extension of SYS.

Couldnt find a file named like that. Checked the registry for something named like that and didnt find any. Did a Panda online Active Scan and didnt find anything. Did a Kaspersky online scan and found nothing. Did some event log cross referencing by time and couldn't find anything suspicious in Application, Security or System logs - Admin wasn't logged in, and there were no application crashes near that time. Ran the Backlight rootkit finder and didnt find anything either. Did a HijackThis log and it isnt listed under services section.

The WindowsDefender event didnt say that it removed the file, only telling me that it was suspcious and to review it. But I can't find it..

I suck at forensics. Anyone have any ideas on what to look for?

Its a Vista Business SP1 box.

Last edited by lunarlander; 07-Apr-2009 at 11:14 AM..
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
07-Apr-2009, 11:31 AM #2
You should remove Windows Defender and get SuperAntiSpyware and Malwarebyte's Anti-Malware. Scan your computer again and see what it finds and removes.

What's your antivirus, or do you have one, other than online scanners? Does it show the file?
lunarlander's Avatar
Computer Specs
Senior Member with 3,492 posts.
 
Join Date: Sep 2007
07-Apr-2009, 11:38 AM #3
My onboard antivirus is Avast - it didnt find anything either. I will try MalwareBytes now

Cannot remove Windows Defender on a Vista machine, it is built in I think

Last edited by lunarlander; 07-Apr-2009 at 11:52 AM..
jillian2's Avatar
Member with 372 posts.
 
Join Date: Sep 2004
Location: Georgia
Experience: Intermediate
07-Apr-2009, 12:43 PM #4
Quote:
Originally Posted by lunarlander View Post
My onboard antivirus is Avast - it didnt find anything either. I will try MalwareBytes now

Cannot remove Windows Defender on a Vista machine, it is built in I think

Launch Windows Defender and at the top > Click Tools >then Click Software Explorer > On the left side , make sure that "Start-Up " Programs are showing > Highlight Windows Defender.> At the bottom on the right side you have an option to either "Disable " or "Remove " Defender from start-up.
lunarlander's Avatar
Computer Specs
Senior Member with 3,492 posts.
 
Join Date: Sep 2007
07-Apr-2009, 12:59 PM #5
MalwareBytes found nothing
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
07-Apr-2009, 01:06 PM #6
What did Windows Defender do with the file? Did it quarantine it? Perhaps that's why no other program is showing the file.
lunarlander's Avatar
Computer Specs
Senior Member with 3,492 posts.
 
Join Date: Sep 2007
08-Apr-2009, 10:12 AM #7
No I don't think Windows Defender put it into quarantine. Here's what it says in the event log:

"Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow."
For more information please see the following:
Not Applicable
Scan ID: {4C495F79-18F9-45D4-828E-61AE8DA67478}
User: @@@@@@
Name: Unknown
ID:
Severity ID:
Category ID:
Path Found: service:RkPavproc1
Alert Type: Unclassified software
Detection Type:


It didn't prompt me or anything.

Last edited by lunarlander; 08-Apr-2009 at 10:18 AM..
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
08-Apr-2009, 10:18 AM #8
Does it still find it?
lunarlander's Avatar
Computer Specs
Senior Member with 3,492 posts.
 
Join Date: Sep 2007
09-Apr-2009, 01:42 PM #9
Ha, I found it.

I ran the Panda online ActiveScan again, and checked the event log, there it appears again. So it belongs to Panda ActiveScan.

Thanks for all your help.
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 02:02 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.