Author Topic: avast 4.8 Rootkit Problem  (Read 8034 times)

0 Members and 1 Guest are viewing this topic.

koke4716

  • Guest
avast 4.8 Rootkit Problem
« on: April 03, 2008, 11:41:01 PM »
Hi All...

Have used avast home for some time now and just upgraded to the new 4.8 but every time I boot/reboot I get a warning stating that a rootkit has been found in memory.

The warning states the rootkit is in system 32\drivers and identfies the file as QL1240.SYS.

I click DELETE NOW and get an error message saying there was an error processing the action.

I use XP and the funny thing is that the QL (Quick Logic) driver files are in the system32\dllcache folder and not in the driver folder.

I also check under Services and do not see anything running automatically at startup that refers to any Quick Logic PCI Drivers...

I have also uninstalled and rebooted and reinstalled version 4.8 but the problem continues and everything else os working fine.

Anyone have a clue as to what this is all about?

Thanks for your help/comments/suggestions

Peter

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: avast 4.8 Rootkit Problem
« Reply #1 on: April 04, 2008, 12:16:03 AM »
Seems a false positive... Can you send that file to virus (at) avast.com and inform a link to this thread in the message body saying that it seems a false positive?
Better if you can manually move that file to another folder.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89129
  • No support PMs thanks
Re: avast 4.8 Rootkit Problem
« Reply #2 on: April 04, 2008, 12:20:26 AM »
Some infor on the file properties for ql1240.sys, http://hashes.castlecops.com/hash21141214-ql1240_sys.html. If you are able to find this file in the location reported, you could check if they match. Not terribly good as I don't know what version it is of as the web page dates from 2 Oct 2005.

The problem with rootkits they aren't likely to advertise their presence. Like in services, etc.
Quote from: koke4716
I also check under Services and do not see anything running automatically at startup that refers to any Quick Logic PCI Drivers...

I have XP Pro and only have ql1240.sys inside a .cab file, in c:\windows\driver cache\i386\driver.cab. So I don't have it outside the .cab file.

I have a little program Hash Calc and I have extracted the file from the cab and dropped it in hash calc and it gives these details, see image.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

koke4716

  • Guest
Re: avast 4.8 Rootkit Problem
« Reply #3 on: April 04, 2008, 01:12:09 AM »
Seems a false positive... Can you send that file to virus (at) avast.com and inform a link to this thread in the message body saying that it seems a false positive?
Better if you can manually move that file to another folder.

Tech - Thanks input - I will send to avast as suggested with a link and suggesting a FALSE POSITIVE.

Many thanks...

koke4716

  • Guest
Re: avast 4.8 Rootkit Problem
« Reply #4 on: April 04, 2008, 01:18:16 AM »
Some infor on the file properties for ql1240.sys, http://hashes.castlecops.com/hash21141214-ql1240_sys.html. If you are able to find this file in the location reported, you could check if they match. Not terribly good as I don't know what version it is of as the web page dates from 2 Oct 2005.

The problem with rootkits they aren't likely to advertise their presence. Like in services, etc.
Quote from: koke4716
I also check under Services and do not see anything running automatically at startup that refers to any Quick Logic PCI Drivers...

I have XP Pro and only have ql1240.sys inside a .cab file, in c:\windows\driver cache\i386\driver.cab. So I don't have it outside the .cab file.

I have a little program Hash Calc and I have extracted the file from the cab and dropped it in hash calc and it gives these details, see image.

DavidR - Thanks also for your comments.  Even though avast has reported the file being in a location it is not (i.e. WINDOWS32\DRIVERS), I have not only moved the ql1240.sys file from the WINDOWS32\DLLCACHE folder (into a junk folder) but I have also renamed the extension from ".SYS" to ".OLD" and then rebooted only to find the same warning msge is still generated.

I did a REGEDIT search for QL1240.SYS and nothing came up.

Strange indeed....

Thanks again
Peter

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89129
  • No support PMs thanks
Re: avast 4.8 Rootkit Problem
« Reply #5 on: April 04, 2008, 01:53:11 AM »
Your welcome, I think we need some input from the Alwil team as we really don't know that much about the rootkit module or its returns.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: avast 4.8 Rootkit Problem
« Reply #6 on: April 04, 2008, 02:31:30 AM »
I do have this file on Windows XP SP2 in the folder specified by avast.  Startup will not show you anything about drivers generally.

I use the free program Serviwin from MS/SysInternals.


koke4716

  • Guest
Re: avast 4.8 Rootkit Problem
« Reply #7 on: April 04, 2008, 05:08:42 PM »
Your welcome, I think we need some input from the Alwil team as we really don't know that much about the rootkit module or its returns.

DavidR & Tech - I have emailed avast with a link to this thread as well as a full description of my problem and a copy of the offending file (ql1240.sys)

I have also solved my problem but not 100% sure as to why.  I again removed the file from the DLLCache folder and again renamed the extension. 

I then did a warm boot but the rootkit warning and errors were repeated.  So, I did a complete shut down/cold boot and the problem seems to be solved.

Again, not sure why...

You can see attached the warning message that avast! 4.8 generated....

Thanks all your comments.
Peter

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: avast 4.8 Rootkit Problem
« Reply #8 on: April 04, 2008, 05:17:17 PM »
Peter, what happens if you click delete button?
Do you receive the message if you run:
XP: Windows Start > Run
"C:\Program Files\Alwil Software\Avast4\ashQuick.exe" "<RTK>SUPERQUICK"

Vista: Windows Start > write "cmd" without quotes > click CTRL+SHIFT+ENTER
Anwswer 'Yes' to UAC question.
Write down (or paste):
"C:\Program Files\Alwil Software\Avast4\ashQuick.exe" "<RTK>SUPERQUICK"
Click Enter
The best things in life are free.

koke4716

  • Guest
Re: avast 4.8 Rootkit Problem
« Reply #9 on: April 05, 2008, 04:23:50 PM »
Peter, what happens if you click delete button?
Do you receive the message if you run:
XP: Windows Start > Run
"C:\Program Files\Alwil Software\Avast4\ashQuick.exe" "<RTK>SUPERQUICK"


Tech -

1) When I click the DELETE button, I get the error message attached to this post.

2) When I run ashQuick.exe (or a full deep scan, nothing is detected - the system is clean)

/peter

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: avast 4.8 Rootkit Problem
« Reply #10 on: April 05, 2008, 05:51:32 PM »
I need help from the programmers... Igor ???
The best things in life are free.

koke4716

  • Guest
Re: avast 4.8 Rootkit Problem
« Reply #11 on: April 06, 2008, 05:57:42 PM »
I need help from the programmers... Igor ???

Igor - Hehehe - I guess the error msge is generated because the file (ql1240.sys) is not residng in the folder \WINDOWS\SYSTEM32\DRIVERS.

The file was however residing in the \WINDOWS\SYSTEM32\DLLCACHE folder but why avast saw the file as being in the \WINDOWS\SYSTEM32\DRIVERS folder is way beyond me.

Anyway, I have found my fix and also passed the info onto avast.  Scanning with avast or trendmicro's housecall and AdAware and SpyBot have all indicated my system is now clean.

Thanks
/peter

koke4716

  • Guest
Re: avast 4.8 Rootkit Problem
« Reply #12 on: April 07, 2008, 11:16:31 PM »
Wonderful - the RootKit warning is back. 

It popped up when I started my scanner, which is on an Adaptec SCSI/Pci Adapter, and now I must assume that this is the hardware device that uses the driver file "ql1240.sys".

The warning message continues to say the file is in "C:\WINDOWS\SYSTEM32\DRIVERS" but after doing a search I cannot find the file anywhere on my harddrive except in a cab file.

/peter

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: avast 4.8 Rootkit Problem
« Reply #13 on: April 07, 2008, 11:26:10 PM »
You may want to go back and look at my previous post.

It is a simple little program from Microsoft/System Internals - requires no install - just run it (make sure in the "View" menu to select "Drivers").

See if tells you anything about that driver on your system.

koke4716

  • Guest
Re: avast 4.8 Rootkit Problem
« Reply #14 on: April 09, 2008, 06:30:16 PM »
You may want to go back and look at my previous post.

It is a simple little program from Microsoft/System Internals - requires no install - just run it (make sure in the "View" menu to select "Drivers").

See if tells you anything about that driver on your system.

AlanRF - Thanks - I did download and install the ServiWin program - much better tool than what XP provides.  Unfortunately, it says nothing about the driver file in question (i.e. ql1240.sys).  Seems avast 4.8 has some bugs in it as nothing I do can identify anything wrong on my system except for avast 4.8.  Everything else I have done to scan for Viruses, Worms, MalWare, RootKits comes up with nothing.

Only avast 4.8 is seeing a RootKit.

hmmmmmm......

Thanks
Peter