avast!WEBforum
February 09, 2010, 01:08:37 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: User Map added recently - see where we all live!
 
   Home   Help Search Calendar Login Register  
Pages: [1] 2 3 4   Go Down
  Print  
Author Topic: Suspicious file found in rootkit hidden process "C:\windows\system32.\ils.dll"  (Read 19988 times)
NourinE
Full Member
***
Offline Offline

Gender: Male
Morocco Morocco

Posts: 107



Personal Message (Offline)
« on: December 15, 2008, 09:53:28 AM »

I have avast pro latest version. today a warning popped up showing that there's a suspicious file found in rootkit hidden process : "C:\windows\system32.\ils.dll".
I think it's a false positive : I searched in google and other sites, the file is authentic.
and this the report of virstotal site :
http://www.virustotal.com/fr/analisis/106adb90b408e372ad7fd3ff22af087e
I didn't delete it and avast recommended to run scan boot but I haven't yet. I need to make sure it's not a false positive.
Logged

NourinE
NourinE
Full Member
***
Offline Offline

Gender: Male
Morocco Morocco

Posts: 107



Personal Message (Offline)
« Reply #1 on: December 15, 2008, 10:00:52 AM »

I went to the file "ils.dll" and scanned it but avast detects nothing about it?! I don't understand what's wrong!!!
Logged

NourinE
maleas
Jr. Member
**
Offline Offline

Gender: Male
Posts: 20

I'm a llama!


Personal Message (Offline)
« Reply #2 on: December 15, 2008, 10:25:45 AM »

Same case here, on Windows XP. Details:
File: C:\windows\system32\ils.dll
OS: Windows XP SP3 (greek)
File version: 5.1.2600.5512
MD5Sum of the file: bd51ab8c4dbdb5ec2b28c613687fcbd8

@Nourine: I'd suggest to press "Ignore" but also check the "Submit the file to ..." option. Seems like a false positive.
« Last Edit: December 16, 2008, 05:56:46 AM by maleas » Logged
NourinE
Full Member
***
Offline Offline

Gender: Male
Morocco Morocco

Posts: 107



Personal Message (Offline)
« Reply #3 on: December 15, 2008, 10:31:17 AM »

thanks Maleas! I did. I hope I can find a solution as soon as possible, because I'm not the only user of this computer, my sisters use it, too. and they don't know much about viruses and computer. they would have immediately deleted it if they had found it.


@Nourine: I'd suggest to press "Ignore" but also check the "Submit the file to ..." option. Seems like a false positive.
Logged

NourinE
Pekker
Newbie
*
Offline Offline

Ireland, Republic of Ireland, Republic of

Posts: 1


Personal Message (Offline)
« Reply #4 on: December 15, 2008, 10:34:11 AM »

Hi,

First post Smiley

Same thing here. Shortly after booting up this morning I got the "suspicious hidden file found" warning.

I'm ultra paranoid when it comes to internet security so I'm going to assume that this is a FP?
Logged
NourinE
Full Member
***
Offline Offline

Gender: Male
Morocco Morocco

Posts: 107



Personal Message (Offline)
« Reply #5 on: December 15, 2008, 10:40:45 AM »

one more thing, I checked the log viewer and found in warning :

15/12/2008   10:32   1229337133   SYSTEM   1128   Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006. 
15/12/2008   10:49   1229338167   SYSTEM   1128   Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006. 
 Huh
I think the problem started after the today's update, because the database has been updated at 10:20 this morning.
Logged

NourinE
igor
ALWIL team
avast! Evangelist
*****
Offline Offline

Gender: Male
Posts: 8538


WWW Personal Message (Offline)
« Reply #6 on: December 15, 2008, 11:11:26 AM »

The problem should be fixed in a few minutes (with a new VPS update).
Logged
fensi88
Newbie
*
Offline Offline

Gender: Female
Posts: 9


Beograd, Srbija


WWW Personal Message (Offline)
« Reply #7 on: December 15, 2008, 11:27:26 AM »

Thanks, I had I the same problem and run boot scan, but Avast found nothing, all is clear. Glad that you will fix problem so quick! I am extremly satisified with Avast! I was saved 6 times in last year by it! Thanks also for free licence key!
Logged

Gandalf_22h
Newbie
*
Offline Offline

Gender: Male
Posts: 17



Personal Message (Offline)
« Reply #8 on: December 15, 2008, 11:41:57 AM »

Also got ils.dll being flagged as bad. Unable to get on here for a while, kept getting "TRy Later". In the meanwhile did a boot scan - nothing, submitted the dll to Virus Total - 0/38 and finally zipped and submitted to avast vie email.
Having now read this will wait for the next definitions update and re-scan the file.
Logged

I have waited all my life for a woman with a sword to come rescue me.
NourinE
Full Member
***
Offline Offline

Gender: Male
Morocco Morocco

Posts: 107



Personal Message (Offline)
« Reply #9 on: December 15, 2008, 11:46:21 AM »

thanks. vps has already updated I will restart and see.

The problem should be fixed in a few minutes (with a new VPS update).
Logged

NourinE
NourinE
Full Member
***
Offline Offline

Gender: Male
Morocco Morocco

Posts: 107



Personal Message (Offline)
« Reply #10 on: December 15, 2008, 11:48:47 AM »

Smiley I'm glad to say that I'm satisfied with avast, too
Thanks, I had I the same problem and run boot scan, but Avast found nothing, all is clear. Glad that you will fix problem so quick! I am extremly satisified with Avast! I was saved 6 times in last year by it! Thanks also for free licence key!
Logged

NourinE
NourinE
Full Member
***
Offline Offline

Gender: Male
Morocco Morocco

Posts: 107



Personal Message (Offline)
« Reply #11 on: December 15, 2008, 11:51:23 AM »

Also got ils.dll being flagged as bad. Unable to get on here for a while, kept getting "TRy Later".

the same prb here.
Logged

NourinE
2harts4ever
Jr. Member
**
Offline Offline

Gender: Male
Posts: 70


"Either lead, follow or get out of the way!"


Personal Message (Offline)
« Reply #12 on: December 15, 2008, 11:52:09 AM »

Morning igor and all,

The 2nd update today seems to have fixed this quirk.
Thanks for the prompt fix.
Regards,
2harts4ever
Logged

" ... Nuff Said.  Keep Smiling Because I'm Smiling Too!"
Maxx_original
ALWIL team
avast! Evangelist
*****
Offline Offline

Gender: Male
Posts: 1206



Personal Message (Offline)
« Reply #13 on: December 15, 2008, 11:56:06 AM »

sorry, my mistake... it's a false positive.. fixed VPS should be available already...
Logged
falcon710
Newbie
*
Offline Offline

Italy Italy

Posts: 4


Personal Message (Offline)
« Reply #14 on: December 15, 2008, 11:58:40 AM »

this morning I have had the same problem Angry Angry Angry. now I have the 081215-1 version of the VPS.   The problem has been resolved? Huh
Logged
Pages: [1] 2 3 4   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2010, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.085 seconds with 17 queries.