I have avast pro latest version. today a warning popped up showing that there’s a suspicious file found in rootkit hidden process : “C:\windows\system32.\ils.dll”.
I think it’s a false positive : I searched in google and other sites, the file is authentic.
and this the report of virstotal site : http://www.virustotal.com/fr/analisis/106adb90b408e372ad7fd3ff22af087e
I didn’t delete it and avast recommended to run scan boot but I haven’t yet. I need to make sure it’s not a false positive.
Same case here, on Windows XP. Details:
File: C:\windows\system32\ils.dll
OS: Windows XP SP3 (greek)
File version: 5.1.2600.5512
MD5Sum of the file: bd51ab8c4dbdb5ec2b28c613687fcbd8
@Nourine: I’d suggest to press “Ignore” but also check the “Submit the file to …” option. Seems like a false positive.
thanks Maleas! I did. I hope I can find a solution as soon as possible, because I’m not the only user of this computer, my sisters use it, too. and they don’t know much about viruses and computer. they would have immediately deleted it if they had found it.
one more thing, I checked the log viewer and found in warning :
15/12/2008 10:32 1229337133 SYSTEM 1128 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
15/12/2008 10:49 1229338167 SYSTEM 1128 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
???
I think the problem started after the today’s update, because the database has been updated at 10:20 this morning.
Thanks, I had I the same problem and run boot scan, but Avast found nothing, all is clear. Glad that you will fix problem so quick! I am extremly satisified with Avast! I was saved 6 times in last year by it! Thanks also for free licence key!
Also got ils.dll being flagged as bad. Unable to get on here for a while, kept getting “TRy Later”. In the meanwhile did a boot scan - nothing, submitted the dll to Virus Total - 0/38 and finally zipped and submitted to avast vie email.
Having now read this will wait for the next definitions update and re-scan the file.