Author Topic: kprocesshackers.sys blocked by Avast Self-defence  (Read 14545 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
kprocesshackers.sys blocked by Avast Self-defence
« on: April 12, 2016, 08:57:38 PM »
Hi.
It has been since few days that Avast start stopping kprocesshacker.sys (Process Hacker): it has never done before. I scanned the file and everything it's ok. Is there any way to exclude kprocesshacker.sys from Avast Self-defence check?
Thanks!

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #1 on: April 12, 2016, 09:38:40 PM »
avast self defense is not blocking it, nor is avast flagging the file.

REDACTED

  • Guest
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #2 on: April 12, 2016, 11:27:40 PM »
avast self defense is not blocking it, nor is avast flagging the file.

...the last Avast pop-up says so.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #3 on: April 12, 2016, 11:32:46 PM »
Please post a screenshot of it.

avast self defense (hence the name), is protecting avast folders/files, not third party folders/files.
« Last Edit: April 12, 2016, 11:40:39 PM by Eddy »

REDACTED

  • Guest
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #4 on: April 13, 2016, 03:05:58 PM »
Thanks.
Here it is (in italian).

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #5 on: April 13, 2016, 03:35:28 PM »
Ah, that is not the avast self defense.
I guess you made a mistake by translating it to English.
No worries, it can happen.

It says that avast has automatically blocked the application.
I just tested it here and on my system avast doesn't block it.

Check the avast log files and see if one of them tells you why it was blocked.

REDACTED

  • Guest
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #6 on: April 13, 2016, 04:01:07 PM »
Hi.
When I open Process Hacker
the only one Avast log that updates is UITracking; inside:
Wed Apr 13 15:55:17 2016 - /popup/DoToaster
Wed Apr 13 15:55:20 2016 - [IDR_HTM_TASKBAR_POPUP] {button} close
Wed Apr 13 15:56:01 2016 - /popup/DoToaster
Wed Apr 13 15:56:21 2016 - [IDR_HTM_TASKBAR_POPUP] {button} close
Wed Apr 13 15:57:58 2016 - /popup/DoToaster

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #7 on: April 13, 2016, 04:08:58 PM »
I think it is best to have avast take a look at it.
Please submit a ticket.
http://support.avast.com

REDACTED

  • Guest
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #8 on: April 13, 2016, 04:16:32 PM »
Thanks for your time.

By the way: is there anyway to read logs by Avast without opening the files on Windows? And... where is the virus basket in the new versions?

Thanks again,
bye

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #9 on: April 13, 2016, 04:20:32 PM »
Quote
is there anyway to read logs by Avast without opening the files on Windows?
No, you need to navigate to a log file and open it in a text editor/-viewer.

For the chest > https://www.avast.com/faq.php?article=AVKB21

Edit:
I tested something and it can be that avast is alerting for a process that is accessed by process hacker.
Please attach the Farbar scan logs to your next post. (FRST.txt and Addition.txt)
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/
« Last Edit: April 13, 2016, 04:39:49 PM by Eddy »

REDACTED

  • Guest
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #10 on: April 13, 2016, 04:38:50 PM »
Quote
is there anyway to read logs by Avast without opening the files on Windows?
No, you need to navigate to a log file and open it in a text editor/-viewer.

For most files it denies me access.

REDACTED

  • Guest
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #11 on: April 13, 2016, 04:45:54 PM »
Anyway Process Hacker still succeeds to launch and run.
On my Windows XP netbook, it doesn't give the same issue... Well, issue: popup :D Only on my Win10 desktop and Win10 notebook.

REDACTED

  • Guest
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #12 on: April 17, 2016, 07:22:07 AM »
I have ProcessHacker set as my default "Task Manager". When I start ProcessHacker by invoking "Start Task Manager" from the TaksBar, Avast blocks ProcessHacker from loading KProcessHacker.sys: the exact message that Avast displays is:

Blocked by Avast self-defense: kprocesshacker.sys (C:\Program Files\Process Hacker 2\ProcessHacker.exe)

I have attempted to put in an exception for ProcessHacker.exe, but it does nothing.  ProcessHacker.exe loads and runs of course, but it does not have the functionality afforded by using the kProcessHacker.sys driver.

A few details: this is on a 32-bit Windows 7 box, just built cleanly today, so nothing on it yet but the OS, Avast, Komodo FW and MS Office.
« Last Edit: April 17, 2016, 07:26:27 AM by DavidMcIntosh »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #13 on: April 17, 2016, 01:35:44 PM »
It looks like avast is protecting the task manager in certain Window versions.
Only avast can tell if it does.

I suggest to submit a ticket and let avast have a look at it/answer things.

REDACTED

  • Guest
Re: kprocesshackers.sys blocked by Avast Self-defence
« Reply #14 on: June 01, 2016, 09:44:38 PM »
Here is the posting from the process hacker website forum -

https://wj32.org/processhacker/forums/viewtopic.php?t=2060