New version finds rootkit hidden files - can't delete & nothing else does

I use Firefox. I right clicked and got ‘save link as’, and a window appeared, not sure what to do from there… ???

Christine

Ok, that is good. Select in the window the folder Vlk and I gave you (C:\program files\Alwill software\avast4\data), then choose to download the file.

how about disabling the self-defense first? don’t know if this has been done already…

Sorry guys, but this isn’t happening, i get a window and in the text field for file name i’ve got aswArO. It seems to want to save this to my desktop.

Can hear gnashing of teeth already!

Hi Christine,

don’t worry about it. Maybe someone else with the same problem will follow up.

We don’t want you to spend the whole afternoon with this! :slight_smile:

Cheers
Vlk

So sorry about that, it’s obviously not my day!

Just out of interest, if these false positives keep coming up, how am i to know when i real one is there? After all, i don’t want to damage my machine by deleting something i shoudn’t, it’s a bit like the boy who cried 'Wolf!. I’m wondering whether it’s a good idea to carry on using Avast if i can’t trust the results. What do you guys think?

p.s. And i am very grateful for your help, please don’t think the question above is a reflection on you guys, not meant in that way!

Christine :slight_smile:

You can ignore the “suspicious file” type of warnings. However, don’t ignore the “A virus was found” warnings (if any).

Disable the self protection (steps 4 - 6 on THIS website

Then click HERE and open (run) that file,
or save it and then double click it.

It will do exactly what Vlk told. (downloading and installing the file in the correct folder.

Edit:
Vlk, for your information: That little .exe is just a installer that places the aswAr0.dll in the data folder for her.

Hi there,

Did as you asked, even got a nice orangey screen with my name on it (i’m easily pleased!); it’s now sitting as an icon on my desktop, should i run it?

C

On the screen with your name on it, click next, then click install (after you have disabled the self-protection)
That is all you have to do.
It you done it, you can enable the self protection again.

This has copied aswArO.dll to the correct folder as Vlk asked you.
I leave it up to him to guide you further.

You can remove the icon from your desktop if you want.

I’d say the file is called aswAr0.dll, not aswArO.dll (i.e. it’s zero, not “O” letter)

Is this what you need? Attached it down below.

Christine

See, you can do it (with a little help) :wink:

Unfortunately not quite. :slight_smile:

I need the file C:\Program Files\ALWIL Software\Avast4\Data\Log\aswAr1.log (if it exists; if it doesn’t, we have done something wrong)…

Thanks
Vlk

Hi there, i think i’ve got it but couldn’t attach it as the file was too large, any suggestions? Can’t copy/paste it as there’s too much text; it’s a looong list! I could email it if that’s any good?

Christine

Sure, you can send it to Vlk’s e-mail (you’ll see it when you click on his profile).
Or, if needed, you can upload it to our FTP server: ftp://ftp.avast.com/incoming
Thanks!

Thanks for that, i’ve just emailed it to him, bet you’re all fed up of me now! :wink:

Cheers all!

Christine

Of course not… we’d like to uncover this mystery.
Thanks for your help, let’s hope Vlk finds out something.

Thanks for that, i've just emailed it to him, bet you're all fed up of me now!
No way! :D

Vlk loves these problems ;D

I’m glad someone does! Viruses, trojans, rootkits…for me it’s the stuff of nightmares! I’m even starting to feel nostalgic for those halcyon days of Sinclair ZX Spectrums (my Dad had one), before viruses and all the other nasties were ever invented! Ahh… happy days! :smiley:

Christine