Author Topic: Rootkit or false alarm, please?  (Read 4866 times)

0 Members and 1 Guest are viewing this topic.

1eyedjack

  • Guest
Rootkit or false alarm, please?
« on: April 01, 2009, 10:18:02 PM »
Hi, I am running Avast 4.8 Professional, and in addition am running Spyware Detector.
A sweep by Spyware Detector shows an apparent rootkit infection, the file being
c:\program files\alwil software\avast4\data\aswar.run

Is there enough information from this in order to advise whether it as a false positive?
I am prompted to quarantine the file.  Would it cause any damage if I accepted the prompt and it is a false positive?

Interestingly I cannot see the file if I try to view the folder in Windows Explorer (even if I set it to view all hidden and system files).

I have also tried a full sweep using Webroot Spysweeper, which apparently checks for rootkits, and it did not detect anything.

Any help gratefully received.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: Rootkit or false alarm, please?
« Reply #1 on: April 01, 2009, 10:38:23 PM »
I auspect an FP by Spyware detector (never heard of this before) the aswar stands for Alwil SoftWare Anti-Rootkit so it looks like part of the anti-rootkit module. Though I don't have that file aswar.run in my avast4\data folder. That may well be because I'm using the Home version.

So it looks like what can happen tools to detect things being incorrectly detected as what it would be hunting for. Checking some of the other aswar files like aswar0.dll, aswar1.dll, arpot.dll and they are digitally signed by Alwil software, the signature wouldn't be good if it were modified and the avast self-defence module should stop it getting modified.

The file may only be there when the anti-rootkit scan is running 8 minutes after boot and it would only be running for a few seconds, that may account for why you can't see it in the data folder either.

I just ran a test running the anti-rootkit and that file didn't appear, though it wasn't run in the conventional way, see image.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

CharleyO

  • Guest
Re: Rootkit or false alarm, please?
« Reply #2 on: April 03, 2009, 05:06:18 AM »
***

This program has been reported here before. Last time I remember was March 12th when it's homepage was rated unsafe and the homepage is still rated unsafe today.

It's homepage is rated as unsafe by ScanDoo. Click image below to enlarge.


***