Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: koke4716 on April 03, 2008, 11:41:01 PM

Title: avast 4.8 Rootkit Problem
Post by: koke4716 on April 03, 2008, 11:41:01 PM
Hi All...

Have used avast home for some time now and just upgraded to the new 4.8 but every time I boot/reboot I get a warning stating that a rootkit has been found in memory.

The warning states the rootkit is in system 32\drivers and identfies the file as QL1240.SYS.

I click DELETE NOW and get an error message saying there was an error processing the action.

I use XP and the funny thing is that the QL (Quick Logic) driver files are in the system32\dllcache folder and not in the driver folder.

I also check under Services and do not see anything running automatically at startup that refers to any Quick Logic PCI Drivers...

I have also uninstalled and rebooted and reinstalled version 4.8 but the problem continues and everything else os working fine.

Anyone have a clue as to what this is all about?

Thanks for your help/comments/suggestions

Peter
Title: Re: avast 4.8 Rootkit Problem
Post by: Lisandro on April 04, 2008, 12:16:03 AM
Seems a false positive... Can you send that file to virus (at) avast.com and inform a link to this thread in the message body saying that it seems a false positive?
Better if you can manually move that file to another folder.
Title: Re: avast 4.8 Rootkit Problem
Post by: DavidR on April 04, 2008, 12:20:26 AM
Some infor on the file properties for ql1240.sys, http://hashes.castlecops.com/hash21141214-ql1240_sys.html (http://hashes.castlecops.com/hash21141214-ql1240_sys.html). If you are able to find this file in the location reported, you could check if they match. Not terribly good as I don't know what version it is of as the web page dates from 2 Oct 2005.

The problem with rootkits they aren't likely to advertise their presence. Like in services, etc.
Quote from: koke4716
I also check under Services and do not see anything running automatically at startup that refers to any Quick Logic PCI Drivers...

I have XP Pro and only have ql1240.sys inside a .cab file, in c:\windows\driver cache\i386\driver.cab. So I don't have it outside the .cab file.

I have a little program Hash Calc and I have extracted the file from the cab and dropped it in hash calc and it gives these details, see image.
Title: Re: avast 4.8 Rootkit Problem
Post by: koke4716 on April 04, 2008, 01:12:09 AM
Seems a false positive... Can you send that file to virus (at) avast.com and inform a link to this thread in the message body saying that it seems a false positive?
Better if you can manually move that file to another folder.

Tech - Thanks input - I will send to avast as suggested with a link and suggesting a FALSE POSITIVE.

Many thanks...
Title: Re: avast 4.8 Rootkit Problem
Post by: koke4716 on April 04, 2008, 01:18:16 AM
Some infor on the file properties for ql1240.sys, http://hashes.castlecops.com/hash21141214-ql1240_sys.html (http://hashes.castlecops.com/hash21141214-ql1240_sys.html). If you are able to find this file in the location reported, you could check if they match. Not terribly good as I don't know what version it is of as the web page dates from 2 Oct 2005.

The problem with rootkits they aren't likely to advertise their presence. Like in services, etc.
Quote from: koke4716
I also check under Services and do not see anything running automatically at startup that refers to any Quick Logic PCI Drivers...

I have XP Pro and only have ql1240.sys inside a .cab file, in c:\windows\driver cache\i386\driver.cab. So I don't have it outside the .cab file.

I have a little program Hash Calc and I have extracted the file from the cab and dropped it in hash calc and it gives these details, see image.

DavidR - Thanks also for your comments.  Even though avast has reported the file being in a location it is not (i.e. WINDOWS32\DRIVERS), I have not only moved the ql1240.sys file from the WINDOWS32\DLLCACHE folder (into a junk folder) but I have also renamed the extension from ".SYS" to ".OLD" and then rebooted only to find the same warning msge is still generated.

I did a REGEDIT search for QL1240.SYS and nothing came up.

Strange indeed....

Thanks again
Peter
Title: Re: avast 4.8 Rootkit Problem
Post by: DavidR on April 04, 2008, 01:53:11 AM
Your welcome, I think we need some input from the Alwil team as we really don't know that much about the rootkit module or its returns.
Title: Re: avast 4.8 Rootkit Problem
Post by: alanrf on April 04, 2008, 02:31:30 AM
I do have this file on Windows XP SP2 in the folder specified by avast.  Startup will not show you anything about drivers generally.

I use the free program Serviwin from MS/SysInternals.

Title: Re: avast 4.8 Rootkit Problem
Post by: koke4716 on April 04, 2008, 05:08:42 PM
Your welcome, I think we need some input from the Alwil team as we really don't know that much about the rootkit module or its returns.

DavidR & Tech - I have emailed avast with a link to this thread as well as a full description of my problem and a copy of the offending file (ql1240.sys)

I have also solved my problem but not 100% sure as to why.  I again removed the file from the DLLCache folder and again renamed the extension. 

I then did a warm boot but the rootkit warning and errors were repeated.  So, I did a complete shut down/cold boot and the problem seems to be solved.

Again, not sure why...

You can see attached the warning message that avast! 4.8 generated....

Thanks all your comments.
Peter
Title: Re: avast 4.8 Rootkit Problem
Post by: Lisandro on April 04, 2008, 05:17:17 PM
Peter, what happens if you click delete button?
Do you receive the message if you run:
XP: Windows Start > Run
"C:\Program Files\Alwil Software\Avast4\ashQuick.exe" "<RTK>SUPERQUICK"

Vista: Windows Start > write "cmd" without quotes > click CTRL+SHIFT+ENTER
Anwswer 'Yes' to UAC question.
Write down (or paste):
"C:\Program Files\Alwil Software\Avast4\ashQuick.exe" "<RTK>SUPERQUICK"
Click Enter
Title: Re: avast 4.8 Rootkit Problem
Post by: koke4716 on April 05, 2008, 04:23:50 PM
Peter, what happens if you click delete button?
Do you receive the message if you run:
XP: Windows Start > Run
"C:\Program Files\Alwil Software\Avast4\ashQuick.exe" "<RTK>SUPERQUICK"


Tech -

1) When I click the DELETE button, I get the error message attached to this post.

2) When I run ashQuick.exe (or a full deep scan, nothing is detected - the system is clean)

/peter
Title: Re: avast 4.8 Rootkit Problem
Post by: Lisandro on April 05, 2008, 05:51:32 PM
I need help from the programmers... Igor ???
Title: Re: avast 4.8 Rootkit Problem
Post by: koke4716 on April 06, 2008, 05:57:42 PM
I need help from the programmers... Igor ???

Igor - Hehehe - I guess the error msge is generated because the file (ql1240.sys) is not residng in the folder \WINDOWS\SYSTEM32\DRIVERS.

The file was however residing in the \WINDOWS\SYSTEM32\DLLCACHE folder but why avast saw the file as being in the \WINDOWS\SYSTEM32\DRIVERS folder is way beyond me.

Anyway, I have found my fix and also passed the info onto avast.  Scanning with avast or trendmicro's housecall and AdAware and SpyBot have all indicated my system is now clean.

Thanks
/peter
Title: Re: avast 4.8 Rootkit Problem
Post by: koke4716 on April 07, 2008, 11:16:31 PM
Wonderful - the RootKit warning is back. 

It popped up when I started my scanner, which is on an Adaptec SCSI/Pci Adapter, and now I must assume that this is the hardware device that uses the driver file "ql1240.sys".

The warning message continues to say the file is in "C:\WINDOWS\SYSTEM32\DRIVERS" but after doing a search I cannot find the file anywhere on my harddrive except in a cab file.

/peter
Title: Re: avast 4.8 Rootkit Problem
Post by: alanrf on April 07, 2008, 11:26:10 PM
You may want to go back and look at my previous post.

It is a simple little program from Microsoft/System Internals - requires no install - just run it (make sure in the "View" menu to select "Drivers").

See if tells you anything about that driver on your system.
Title: Re: avast 4.8 Rootkit Problem
Post by: koke4716 on April 09, 2008, 06:30:16 PM
You may want to go back and look at my previous post.

It is a simple little program from Microsoft/System Internals - requires no install - just run it (make sure in the "View" menu to select "Drivers").

See if tells you anything about that driver on your system.

AlanRF - Thanks - I did download and install the ServiWin program - much better tool than what XP provides.  Unfortunately, it says nothing about the driver file in question (i.e. ql1240.sys).  Seems avast 4.8 has some bugs in it as nothing I do can identify anything wrong on my system except for avast 4.8.  Everything else I have done to scan for Viruses, Worms, MalWare, RootKits comes up with nothing.

Only avast 4.8 is seeing a RootKit.

hmmmmmm......

Thanks
Peter
Title: Re: avast 4.8 Rootkit Problem
Post by: koke4716 on April 09, 2008, 07:02:48 PM
I also just ran the AVG RootKit software and it found my system clean too...!

/peter
Title: Re: avast 4.8 Rootkit Problem
Post by: koke4716 on April 09, 2008, 11:02:19 PM
Below are the 15 lines/contents of my avast Error Log file;

Date/Time                                     Application   Description
4/2/2008 1:56:24 PM   SYSTEM   1388   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002. 
4/2/2008 2:10:28 PM   SYSTEM   1432   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002. 
4/2/2008 4:15:23 PM   SYSTEM   1408   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002. 
4/3/2008 5:09:27 PM   SYSTEM   1164   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002. 
4/3/2008 7:54:45 PM   SYSTEM   1176   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002. 
4/5/2008 5:17:09 PM   SYSTEM   1164   Internal error has occurred in module aswar scan function failed!, function C0000005. 
4/6/2008 11:10:57 AM   SYSTEM   1164   Internal error has occurred in module aswar scan function failed!, function C0000005. 
4/7/2008 9:05:36 AM   SYSTEM   1164   Internal error has occurred in module aswar scan function failed!, function C0000005. 
4/7/2008 4:54:25 PM   SYSTEM   1240   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002. 
4/8/2008 10:05:09 AM   SYSTEM   1164   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002. 
4/8/2008 2:09:28 PM   SYSTEM   1188   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002. 
4/9/2008 8:11:08 AM   SYSTEM   1164   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002. 
4/9/2008 8:23:52 AM   SYSTEM   1244   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002. 
4/9/2008 12:02:48 PM   SYSTEM   1164   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002. 
4/9/2008 12:48:28 PM   SYSTEM   1156   Internal error has occurred in module basEncodeFileToRootkitSubmit failed! , function 00000002.