system
1
Good Afternoon:
Downloaded most recent Avast Free Version with $19.00 upgrade last night. Ran deep virus scan which indicated “rootkit hidden file” threat. Attempted removal and moving to virus chest both
apparently failed. Received error message " The request is not supported (50). Any help appreciated. Thanks in advance.
Pondus
2
what was detected?
what was det location, full file path
system
3
Pondus, Thank You for responding. The file appears to be: C:\Windows…\clbcatq.dll:WofCompressedData
Thanks in Advance for any help.
rick
Pondus
4
C:\Windows..\clbcatq.dll:[b]WofCompressedData[/b]
Detected file is inside a compressed archive, so avast will not rip it out
- you have to unzip archive and scan
- you move/delete entire archive
i have a feeling this may be a false positive, so i would upload and check file at virustotal.com before doing anything
Milos
5
Hello,
the path does not look like it is archive, but NTFS alternate data stream (http://www.ntfs.com/ntfs-multiple.htm). Send us the file to analyze (https://www.avast.com/false-positive-file-form.php), please.
Milos
system
6
Hello Milos,
Thanks for your help.
I am not quite sure how to do that. I can’t seem to locate the file using file search. Also, If I manage to locate the file what exactly do you need?
Thanks Again.
Rick
Milos
7
Hello,
find the file “clbcatq.dll” in “C:\Windows” folder and sent is to us. To obtain it’s Alternate Data Steam try to use http://www.nirsoft.net/utils/alternate_data_streams.html
Milos