Windows 10: Rootkit Virus? Inline Hook Ntoskrnl.exe AVG

Discus and support Rootkit Virus? Inline Hook Ntoskrnl.exe AVG in AntiVirus, Firewalls and System Security to solve the problem; I basically downloaded the 1607 Windows update, the latest one. And one time, my AVG came up with 800 plus threats to do with a rootkit or something,... Discussion in 'AntiVirus, Firewalls and System Security' started by Gelbs, Aug 2, 2016.

  1. Gelbs Win User

    Rootkit Virus? Inline Hook Ntoskrnl.exe AVG


    I basically downloaded the 1607 Windows update, the latest one. And one time, my AVG came up with 800 plus threats to do with a rootkit or something, and I think ntoskrnl.exe. I can't remember. Basically, the threats I think were hidden, and either way it couldn't delete them. I thought that it might of been to do with where I configured my boot settings to safe mode, as I sometimes go into that mode to be able to delete certain files I can't normally. But now, I've tried doing numerous scans with AVG, and everything seems clear and detected?? Any idea what it might of been? I haven't downloaded nothing 'bogus' since the update etc neither. Kinda worried, lol.

    :)
     
    Gelbs, Aug 2, 2016
    #1
  2. IgFe Win User

    I just got a report from AVG's Anti-rootkit that there's a threat in my operating system (W 10 Home) that cannot be removed

    *Original Title: Inline hook ntoskrnl.exe

    Hi,

    I just got a report from AVG's Anti-rootkit that there's a threat in my operating system (W 10 Home) that cannot be removed:

    "Inline hook ntoskrnl.exe HvilslommuInUse+0xCCE8 -> 0x35DC65A0"

    (please note that I have retyped the name and I may have mistaken some "l" for capital "i", etc.)

    Could anyone please tell me what to do about it? I don't dare continue using that computer until I resolve the issue.

    Many thanks,
     
    IgFe, Aug 2, 2016
    #2
  3. DeeB16 Win User
    I have a virus "Inline hook ntoskrnl.exe HvilslommuInUse+0xCCE8 -> 0x35DC65A0"

    Inline hook ntoskrnl.exe ExAcquireSharedStarveExclusive+0x390 -> 0xFFFFF80319758055

    AVG has found this apparent -Medium threat level- virus. Within my OS -Windows 10. Is this a common false positive? Is AVG just not liking certain files within Windows?

    Never seen this before, AVG always scans 0 threats on my computer.

    Unsure whether to ignore it?

    Thoughts?
     
    DeeB16, Aug 2, 2016
    #3
  4. Borg 386 Win User

    Rootkit Virus? Inline Hook Ntoskrnl.exe AVG

    If you're still concerned, which would be a valid concern when it comes to a rootkit, then run a scan with TDSSKiller which is designed to find/remove rootkits.

    TDSSKiller Download


    Rootkit Virus? Inline Hook Ntoskrnl.exe AVG [​IMG]
    Note When running TDSSKiller, launch the program, click on the blue text "Change Parameters" & check the box marked "Detect TDLFS File system." Click OK & then run the scan.

    A rootkit will create a hidden partition, at the end of the drive, 1 - 10 MB in size and set itself as the boot partition. Hence, the rootkit is already running before Windows loads. This hidden partition will not show up on Windows Disk Management in most cases.

    Malwarebytes also includes a rootkit scan. The free version will work fine.

    Malwarebytes | Free Anti-Malware & Malware Removal

    Enable Rootkit Scan on Malwarebytes
     
    Borg 386, Aug 2, 2016
    #4
  5. Gelbs Win User
    Okay thanks! I'll give them a try. It was an 'Inline Hook' virus detected or something as well. I thought it might of been to do with a registry hack for Cortana http://www.howtogeek.com/265027/how-...in-windows-10/ but either way, AVG is now detecting no new threats, pretty strange! Unless it was a false positive or something.
     
    Gelbs, Aug 2, 2016
    #5
  6. Borg 386 Win User
    It would be a good idea to run Malwarebytes & do a full system scan to see if it finds anything else. Viruses tend to invite others to the party. Malwarebytes will not cause a conflict with AVG & it's suggested you add this to your arsenal of malware scanners. You will need to update the definitions manually every time you scan unless you opt for the Pro version.

    Be aware that the free version is a "on demand" scanner & does not run active background scanning. The Pro version however does.
     
    Borg 386, Aug 2, 2016
    #6
  7. Gelbs Win User
    I'll see what Malwarebytes does. I already have it, but just waiting for AVG to finish another scan. I also have a third 'volume' disc showing under my optimise drives settings. Anyway of me finding out what that is? Although it might be where I sometimes connect an external hard-drive to my computer. Getting paranoid now, lol.
     
    Gelbs, Aug 2, 2016
    #7
  8. Gelbs Win User

    Rootkit Virus? Inline Hook Ntoskrnl.exe AVG

    Malwarebytes hasn't detected anything thus far. If that's the case, what do you think it was previously? I mean, to detect 800 odd threats is a heck of a lot! Seems strange. Should I do a clean install or something, or you think that I'm safe?
     
    Gelbs, Aug 2, 2016
    #8
  9. Borg 386 Win User
    800 does sound like a lot. That is always the safest option, a clean install. It's up to you, most people try to avoid this as it involves setting everything up again from scratch. Be sure to wipe the entire drive if you opt for this action as some rootkits can survive a re-installation.

    Reset Windows 10 - Windows 10 Forums

    Refresh Windows 10 - Windows 10 Forums

    Windows 10 - Clean Install - Windows 10 Forums

    You will find links to other options & related tutorials at the bottom of the page on all of these tutorials.
     
    Borg 386, Aug 2, 2016
    #9
  10. Gelbs Win User
    Yeah. I hate having to install everything. Pain in the arse lol. I'll see how things go. Hopefully it might not of been anything.
     
    Gelbs, Aug 2, 2016
    #10
  11. Borg 386 Win User
    Yeah, it is a PIA but the best way when in doubt.

    See what Malwarebytes as well as TDSSKiller says. Other good malware scanners are AdwCleaner & SuperAntiSpyware Portable.

    There is another way to confirm if you do have a hidden partition on your HDD that might be hiding from Windows. GParted is a bootable partition manager that you can use to look at your HDD. Since it runs at boot up, you can get a good look at what exists on your drive before windows engages.

    As I stated earlier, a rootkit will show as a hidden boot partition, usually at the end of the drive, 1 - 10 MB in size, depending on the variant.

    You can d/l it here & make a boot disk/USB.

    http://gparted.org/

    GParted -- Documentation
     
    Borg 386, Aug 2, 2016
    #11
  12. This is why you should have your system backup. Also, some rootkit has the ability to modify MBR.
     
    RubberDucky, Aug 2, 2016
    #12
  13. Gelbs Win User

    Rootkit Virus? Inline Hook Ntoskrnl.exe AVG

    Basically done all searches with numerous software scans, and nothing is no longer detected. Could of just been a temp thing with AVG!
     
    Gelbs, Aug 2, 2016
    #13
  14. I don't know much about this virus but generally, you can restart your computer, and go to Safe Mode, and from Safe Mode download Microsoft's Security Essentials and Malwarebytes Anti-Malware--Yes, you can use the trial--and run them one by one.--The order doesn't matter, just don't run them at the same time.--After they are done delete anything that appears on both MSE and MAM. Then power it off and back on, and see if it is gone. My father taught me this.
     
    ProgrammerWhiz, Aug 2, 2016
    #14
  15. Gelbs Win User
    I did an AVG root-scan last night. It picked up 20 'Inline hook ntoskrnl.exe' threats. I did a fresh install and kept my files of Windows 10, did a scan and it was fine. Now, it's found one again! Getting pissed off with this. No idea if it's a false positive etc, and has something to do with the recent 1607 update!
     
    Gelbs, Aug 3, 2016
    #15
Thema:

Rootkit Virus? Inline Hook Ntoskrnl.exe AVG

Loading...
  1. Rootkit Virus? Inline Hook Ntoskrnl.exe AVG - Similar Threads - Rootkit Virus Inline

  2. AVG Anti-Virus Free Deletions

    in Windows 10 Gaming
    AVG Anti-Virus Free Deletions: I always scan my computer with AVG every night, using a smart scan, but I have been noticing that files that it comes up with in "junk files" in the performance issues section of the scan has been going down. I'm worried that AVG is deleting important files, because my...
  3. BSOD Minidump shows page_faul ntoskrnl..exe

    in Windows 10 BSOD Crashes and Debugging
    BSOD Minidump shows page_faul ntoskrnl..exe: KUKutter_UKFirstly, I would like to say that I am posting this again because after having an instant reply from an 'Andrew', and posting my dmp files as requested on July 24th I haven't heard anything back since! I have responded a couple of times but nothing is happening to...
  4. BSOD Minidump shows page_faul ntoskrnl..exe

    in Windows 10 BSOD Crashes and Debugging
    BSOD Minidump shows page_faul ntoskrnl..exe: Hi there, My new machine around 8 months old now runs perfectly most of the time. Uptime 3 - 6 weeks at a time. NO issues at all - I am a heavy PC user: Gaming, Audio Work and some 3D modelling, so my machine goes through its paces.Every now and then on boot, I get the error...
  5. Is this .exe a virus ?

    in Windows 10 Ask Insider
    Is this .exe a virus ?: [ATTACH] Hey everybody today i just navigate to the Win10 folder and there a .exe which names and do the same work as notepad. I don't have idea . Is there a notepad.exe in Win10 folder but according me the notepad.exe is present inside the Sys32 Folder, is this .exe a...
  6. Sudden Phishing Attack or Rootkit or Virus ????

    in AntiVirus, Firewalls and System Security
    Sudden Phishing Attack or Rootkit or Virus ????: I have no idea what is happening. I have seen the attempt just this afternoon on three of my networked PC's but, SO FAR, Malwarebytes AntiMalware Premium has blocked attempts on all three. Malwarebytes says "Malicious Website" - "Category: Phishing". This PC system is Windows...
  7. BSOD ntoskrnl..exe

    in Windows 10 BSOD Crashes and Debugging
    BSOD ntoskrnl..exe: My computer has crashed a few times often when i play games. I bought more ram because i thought that it was the issue but it didn't help. It did work a few days but then the crashes came back. After that i fixed the BSOD´s by lowering the graphics and the resolution on the...
  8. Problem Removing Virus in AVG

    in AntiVirus, Firewalls and System Security
    Problem Removing Virus in AVG: My AVG scan indicated a infected file. I have attempted to resolve the issue but is is not removing it. It suggests that I move it to the virus chest. What will I have to do to move it to the virus chest? [Original Title: virus]...
  9. BSOD ntoskrnl..exe+1b35e0

    in Windows 10 BSOD Crashes and Debugging
    BSOD ntoskrnl..exe+1b35e0: Help. Getting 4-5 of these a day. Running latest Windows 10 Pro, Xibo signboard, Docker with Xibo server. Always the same 'Caused By Address'. Put in new memory, ran memory test, no errors, all drivers up to date. Change disk type to AHCA, made sure windows driver was...
  10. exe virus

    in AntiVirus, Firewalls and System Security
    exe virus: help to remove that[ATTACH] https://answers.microsoft.com/en-us/protect/forum/all/exe-virus/585ba649-c702-41a6-81a8-af784896eb8d
Tags: