suspicious file found in drivers

Hello,
I hope someone can help me.
I downloaded a file like a dumby from emule…after that happened a bunch of emails started popping up in my taskbar of all places!
Now an avast warning has popped up stating that a suspicious file has been found in C:\WINDOWS\System32\drivers\66c38c.sys and the type says, hidden services.
Ive done a google search and it turned nothing up.
The recommended action tells me to ignore it. And it tells me to submit the file to alwil software virus lab for further analysis.
Im at my wits end, I dont know wh at to do to get rid of it, I keep hitting delete now, and the warning keeps popping up. Ive even tried deleting the file manually and i get access denied.
Anyone have a possible solution to this problem?

:slight_smile: Hi :

Seems it would be wise to get a “2nd Opinion” !? Have you run any Scans
from good antiSPYWARE/antiTROJAN programs, such as the FREE Version of
“SUPERAntiSpyware” from www.superantispyware.com or the FREE Version
of Malwarebytes’ Anti-Malware from www.malwarebytes.org/mbam.php , to
see IF they “detect” anything ?

Well zero hits on google (excluding the one for this topic) is suspicious in its own right, especially if it is a legit driver.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. You can’t do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

If it is indeed a false positive, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.