Hello!
After startup I usually check Comodo Proactive Defense review list. Today I have noticed that these three files are under status “modified” although I have checked and removed them on previous time?
Does these files really change on every boot or why does they appear again and again in review section?
Comodo says that they are “safe” files…
They all exists in Avast DATA folder and I assume that they are legit files?
ps. Iadhide5.dll… does it have something to do with Avast!..?
iadhide5.dll is a F-Secure Backweb Component from BackWeb belonging to BackWeb Autoupdater. This is used for the automatic updates of many applications
aswar?.dll belongs to the avast anti-rootkit module Alwil SoftWare, the ‘asw’ part and ‘ar’ the anti-rootkit. I placed a ? to indicate that this number could other than 0.
clnr0.dll (Virus/Worm Cleaner Application for avast!) is a component from the software avast! Virus Cleaner Tool
exts0.dll
These files may have the following Vendor, Product, Version Information in the file header ALWIL Software; Avast! Antivirus Scanner Extension Library; 1, 0, 0, 0
* The following Vendor, Product, Version Information has also been reported:
Yes, all three files are extracted from 400.vps (the avast virus database) at the time of loading.
They basically change (=get overwritten) during every VPS update.