SOLVED - 1290 False Positive - Root-Kit

This was not an issue prior to 1282 and I could not run 1282 anyway. With 1290 every time I
reboot Avast finds (after a few minutes) a root-kit which is really a file in C:\ which is part of
an anti-theft system I need to keep. I select IGNORE and DO NOT SHOW AGAIN yet it finds
it every time. I have added the file in Avast to IGNORE in every place I could find with no luck.

Vista Home Premium x86 (32 bit) SP1

Any way to make Avast actually ignore this file?

Normally the file needs to be added to the “exclusions” list (R.Click tray icon>Program settings>Exclusions.)
I’m really not sure if adding it to the exclusions list will also exclude it from the antirootkit module (which runs its scan some minutes-8, I think- after computer start), but it says it affects all parts of Avast, except for the resident protection.
Be interesting to confirm this.

I already had it there to no avail. Any other places?

Where is the IGNORE - DON"T SHOW ME THIS AGAIN setting kept. It either is not
being set or is ignored.

The only other way I know of that might work - and maybe you’ve already tried it - is to ring up the “provider settings” by left clicking the tray icon, select Standard Shield> Customise, Advanced, and add the folder the file is in to the list of areas that won’t be scanned.
[EDIT] PS, another way would be to actually disable the rootkit scan. Program settings > Troubleshooting.

Yep its already there too? :-[

Oh it is actually in C:\ root so I have it as C:\filename.exe

See edit above. Not the most desirable state of affairs, however.

Yes was hoping to be able to avoid the Disable of the Root Scan.

Any ideas where the Ignore - Don’t show this again check is kept?
Since it asks when notification pops up it has to be or is supposed
to be kept as an entry somewhere?

No, I don’t know. Not sure if it even exists for some types of detection. :-[

Please see this thread - the standard exclusion lists do not work with the anti-rootkit function.

Please see Tech’s notes on the avast4.ini file for the way to exclude a file from the antirootkit scan

Also see an example here.

Well I figure the setting is supposed to be kept somewhere. If not why does it have an
IGNORE and DON’T ASK ME THIS AGAIN box?

Thanks for your help, maybe someone else knows.

I will check the other thread too.

Rootkit scan is performed 8 minutes after boot.
If you add the file to the both avast exclusion lists, it shouldn’t warn you again: Standard Shield and on-demand scanning.
Does the file has 8+3 characters in its name?

Oh, I’ve forgot…
To know if a file is a false positive, please submit it to VirusTotal and let us know the result. VirusTotal has a file size limit of 10Mb. You can use VirScan also.
If it is indeed a false positive, send it in a password protected zip to virus@avast.com. Please, mention in the body of the message why you think it is a false positive and the password used. Thanks.

Maybe you need to disable Hide protected operating system files and enable View hidden files and folders to manage the file(s).

I put the C:\filename.exe in the ini file and will test it now.

Many thanks!

Where? Which session and value?

Which is the filename?

I have the Files in Standard Shields - Custom - Advanced and in
Program Settings - Exclusions. Are there any other places to add it?

its name is 8.3 format.

Please see the link to the example I posted.

I regret to say that I believe the advice Tech gave you is ineffective.

You need to edit the avast4.ini file to make this exception as recorded by Tech in the avast4.ini documentation.

passwords.exe and added C:\passwords.exe to

C:\Program Files\Alwil Software\Avast4\DATA\avast4.ini

[AntiRootkit]
Exceptions=C:\passwords.exe
SubmitFiles=0

is this correct?

No, you’ve also used the Antirootkit exception list…
Did you boot after adding them to the exclusion lists?

Use passwor~1.exe (it’s on 9+3 format).

Tech …

can you please show us where the avast team has said theses exclusions work for the rootkit?

In the thread I referenced Igor specifically referred to antirootkit exclusions being in the avast4.ini and you have published the information.

Why would there be an antirookit exclusion list if the other exclusions covered it?

See the title of this thread.

Well… I’ll need to search the board a lot. Probably Vlk said that… But could be Igor as you’ve said.

A specific configuration for this particular scanning? ???