first you should check the file at www.virustotal.com to be sure if it is really malicious… the location of the file is pretty strange, let’s see the virustotal analysis…
@ Maxx
Since this dlimport.exe is inside an $ntservicepackuninstall$ I would imagine it would exceed the 10MB upload maximum of VT and I don’t believe it is possible to extract the dlimport.exe file from the ntservicepackuninstall archive ???
Does this allow us to conclude this detection might be a FP ?
I week ago, I removed, using the usual MS delete/modify program procedure (independently
of what SAS had discovered), some adware pieces of code that came along with the Pando
toolbar (see my previous post entitled : “Pando false positive ?” ), do you think this might be
related to the strange location of the suspicious file ?
Even if this file might be a FP, can it spread itself anywhere ?
There are, indeed, some viruses that avast is being the first (or among the first) of detect.
GData uses avast scanner as well. It’s difficult to judge right now. Maybe yes, maybe not.
I would say it is an FP but it may be worth sending the sample to avast for analysis and exclude the file C:\WINDOWS$NTSERVICEPACKUNINSTALL* see below (the asterisk saves typing the full file name, I suggest excluding the archive file as I don’t know if you can exclude a file within the archive or not).
I don’t thing this is related to your earlier issue.
Well, I do not know how worms do work : are they not supposed to spread and/or
replicate (reincarnate) themselves for ever ? When a worm is detected, how do you
have to behave the best ? Sorry, I do not much about these bests …
There really is only one way to tell and that is by analysis as outlined in the above posts.
However, I my memory isn’t playing tricks wmplayer.exe may have featured in a previous detection (try the forum search). So a) insure that you have the latest version of the avast VPS, b) ensure you have the latest version of WMP and c) if the file is still detected upload to VT to confirm.
Due to the recent Avast virus database (version 080613-1), it looks that the file is no more
consided as worm, so I have restored the file to it’s original location and removed the name
of this file from the Avast exclusion list.
So I can assume this detection is definitively a FP, right ?
Now this is of no help to me. I did what I was supposed to do but avast didn’t give me the option of returning two files from the chest back to the d (system restore) drive. Thus they are lost. The main false positive restored just fine to the c drive. Do what you’re supposed to do and get screwed!!!
Can someone help me please. I am new here having never had trouble with it in four years! I haven´t had time to read about how this forum works because I need help quickly.
This post relates to 1-18. I keep getting the same warnings (3 in all) but I cannot get Avast to quarantine them. It keeps telling me that they are being used by another programme. Every time I try to do something to resolve the problem I get the same message when I am asked by Windows update to install it which installs up to the first 5 and then everything freezes. I keep getting stuck with windows update and Avast virus alert open but frozen.! Can someone please help before I go nuts. I have Very little tech skills but normally can handle stuff. I have even panicked and pulled the plug just to clear the desktop but I keep getting this problem. Help!!