Author Topic: New version finds rootkit hidden files - can't delete & nothing else does  (Read 49584 times)

0 Members and 1 Guest are viewing this topic.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11754
    • AVAST Software
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #30 on: December 03, 2008, 07:31:34 PM »
I'd say the file is called aswAr0.dll, not aswArO.dll (i.e. it's zero, not "O" letter)

Offline Crowella

  • Jr. Member
  • **
  • Posts: 21
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #31 on: December 03, 2008, 08:04:17 PM »
Is this what you need? Attached it down below.

Christine

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31345
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #32 on: December 03, 2008, 08:15:34 PM »
See, you can do it (with a little help)  ;)

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11665
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #33 on: December 03, 2008, 08:33:16 PM »
Is this what you need? Attached it down below.

Unfortunately not quite. :)

I need the file C:\Program Files\ALWIL Software\Avast4\Data\Log\aswAr1.log (if it exists; if it doesn't, we have done something wrong)...


Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.

Offline Crowella

  • Jr. Member
  • **
  • Posts: 21
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #34 on: December 03, 2008, 08:59:49 PM »
Hi there, i think i've got it but couldn't attach it as the file was too large, any suggestions? Can't copy/paste it as there's too much text; it's a looong list! I could email it if that's any good?

Christine

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11754
    • AVAST Software
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #35 on: December 03, 2008, 09:06:26 PM »
Sure, you can send it to Vlk's e-mail (you'll see it when you click on his profile).
Or, if needed, you can upload it to our FTP server: ftp://ftp.avast.com/incoming
Thanks!

Offline Crowella

  • Jr. Member
  • **
  • Posts: 21
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #36 on: December 03, 2008, 09:34:50 PM »
Thanks for that, i've just emailed it to him, bet you're all fed up of me now!  ;)

Cheers all!

Christine

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11754
    • AVAST Software
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #37 on: December 03, 2008, 09:39:45 PM »
Of course not... we'd like to uncover this mystery.
Thanks for your help, let's hope Vlk finds out something.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31345
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #38 on: December 03, 2008, 09:44:48 PM »
Quote
Thanks for that, i've just emailed it to him, bet you're all fed up of me now!
No way!  :D

Vlk loves these problems ;D

Offline Crowella

  • Jr. Member
  • **
  • Posts: 21
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #39 on: December 03, 2008, 10:08:29 PM »
I'm glad someone does! Viruses, trojans, rootkits...for me it's the stuff of nightmares! I'm even starting to feel nostalgic for those halcyon days of Sinclair ZX Spectrums (my Dad had one), before viruses and all the other nasties were ever invented! Ahh... happy days!  :D

Christine

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11665
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #40 on: December 03, 2008, 10:58:03 PM »
Interesting indeed. :)

Could you please try doing the following?

Go to My Computer, right-click disk C: and choose Properties. Go to the Tools page and click the "Check Now..." button.

Click Start, and let the operation complete.

Does it report any problems?

And if you re-run the scan after this, does it still find the "rootkits"?

Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.

Offline Crowella

  • Jr. Member
  • **
  • Posts: 21
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #41 on: December 03, 2008, 11:57:30 PM »
Hi there,

Just did the disk check as you asked and no problems - 'Disk check complete'. Will re run Avast scan and let you know! When you say 'interesting' does that mean good interesting or bad (you're full of nasty viruses) interesting?

Cheers,

Christine

Offline Crowella

  • Jr. Member
  • **
  • Posts: 21
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #42 on: December 04, 2008, 01:08:55 AM »
Grrrr...ok, just finished the Avast scan and it's exactly the same; the pop up saying suspicious files (the rootkits) have been found using the heuristic method and asking me to reboot, then the pop up appears informing me there's a virus in the memory.

Nothing's changed i'm afraid!  >:(

Night night all...

Christine
« Last Edit: December 04, 2008, 01:10:32 AM by Crowella »

Offline gcon60

  • Newbie
  • *
  • Posts: 14
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #43 on: December 04, 2008, 05:08:41 PM »
Hi Vik,

I have been reading your latest suggestions.  Would it be useful if I also sent you the resultant file?

Gerard

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11665
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: New version finds rootkit hidden files - can't delete & nothing else does
« Reply #44 on: December 05, 2008, 09:32:58 AM »
Hi gcon60,

I don't know how proficient you are with computers, but if you can handle the command line, I'd be grateful if you could do the following:

1. download http://public.avast.com/~vlk/avar.exe and place it to a directory
2. start cmd.exe, go to the directory where you placed avar.exe and run the following command

avar.exe -a -f c:\ >avar.txt

3. when the command completes (may take some time, roughly 10 minutes or so, depending on the size of your C: drive) send me the resulting file avar.txt (by email).


Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.