The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    AVG Anti Rookit Problem.

    Discussion in 'Security and Anti-Virus Software' started by Dead0rAlive, May 9, 2009.

  1. Dead0rAlive

    Dead0rAlive Notebook Consultant

    Reputations:
    18
    Messages:
    113
    Likes Received:
    0
    Trophy Points:
    30
    Hey guys,

    Just ran for the first time AVG Anti rootkit, and it came back with 1 result.

    "Object name";"C:\Windows\System32\Drivers\aj2eg8k5.SYS"
    "Detection name";"Hidden driver"
    "SDK Type";"Rootkit"
    "Result";"Object is hidden"

    So when I click to heal and remove, AVG says: Some files cannot be healed. Access denied.

    So I searched around the net and downloaded Autoruns by sysinternals. And located it in the drivers section.

    It tells me that aj2eg8k5.SYS is an Atapi miniport driver. Developed by Microsoft corp. It has a file size of 0 bytes.

    What do you guys reckon? Any ideas would be greatly appreciated.

    Thanks in advance.

    *EDIT: Well I haven't had much luck with this one. What I did find out is, unless my mates pc also has the same problem, it looks like its natural to have one hidden atapi miniport driver. Its not necessarily under the same name either. For example the *.sys file I had this morning is now called adq1yjbn.sys. And according to Autoruns it is a verified microsoft driver. So I reckon the anti rootkit that comes with avg is just being over paranoid and everything is a-ok. But, what do I know? =) *
     
  2. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    Why not contact AVG through their forum?
    Surely, if it seems a common atapi (miniport) driver, AVG can tell you if it's OK and that the program gave a false positive.
     
  3. Dead0rAlive

    Dead0rAlive Notebook Consultant

    Reputations:
    18
    Messages:
    113
    Likes Received:
    0
    Trophy Points:
    30

    I did over the weekend. And here is what they had to say:

    *Re: AVG Anti Rookit Problem: Hidden Driver = False positive?
    Posted by: BIG AL 43 - Moderator (IP Logged)
    Date: May 10, 2009 02:55PM

    Dead0rAlive

    Are you sure that you actually mean AVG Anti-Rootkit [free.avg.com] [freeforum.avg.com] since it's been withdrawn.*

    I wasn't even aware. :D But its still annoying. I was kind of hoping for an answer at least. But never mind.