Author Topic: avast 5.0.366: suspicious file detected : hardlock.sys  (Read 14246 times)

0 Members and 1 Guest are viewing this topic.

samnetx

  • Guest
avast 5.0.366: suspicious file detected : hardlock.sys
« on: January 18, 2010, 06:33:16 PM »
avast 5.0.366: suspicious file detected : %SystemRoot%\system32\drivers\hardlock.sys
edit: detected by avast heuristics (previous avast version not detected anything suspicious like that)
hardlock.sys
HARDLOCK.SYS is related to Hardlock Device Driver for Windows NT.
Manufacturer: Aladdin Knowledge Systems Ltd.
www.aladdin.com

The file deleted several times from the computer using avast5.0.366 menu whenever avast5.0.366 detected the file but the file is coming back again and again.
Complete virus scan from avast5.0.366 found no virus or malware.

samnetx
« Last Edit: January 19, 2010, 03:25:27 AM by samnetx »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33916
  • malware fighter
Re: avast 5.0.366: suspicious file detected : hardlock.sys
« Reply #1 on: January 18, 2010, 09:36:47 PM »
Hi samnetx,

You could upload to virustotal.com and see what scanners flag it to decide if it is really is a False Positive.

See info on this file:
http://www.tallemu.com/oasis2/file/aladdin_knowledge_systems_ltd_/hardlock_device_driver_for_windows_nt/hardlock_sys/24501

Associated with an alledged worm here: http://www.prevx.com/filenames/X3961266400541339988-X1/HARDLOCK.SYS.html

Any malware can be named anything - so you should check where the files of the running processes are located on your disk. If a "non-Microsoft" .exe file is located in the C:\Windows or C:\Windows\System32 folder, then there is a high risk for a virus, spyware, trojan or worm infection!
Heuristical find: http://heavenward.ru/removeany_search.php?s=4ef7.hardlock.sys

This is why it probably was flagged: First of all there are two versions of hardlock.sys because they contain different packet crypt code. And both do it inside virtual machine. Code of VM and p-code obfuscated. The obfuscation there is probably heuristically flagged - so update to avast with this
remark....

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

samnetx

  • Guest
« Last Edit: January 19, 2010, 08:03:39 AM by samnetx »

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Re: avast 5.0.366: suspicious file detected : hardlock.sys
« Reply #3 on: January 19, 2010, 10:28:46 AM »
Hi Samnetx,

Please submit to virus@avast.com
with compress file name : virus
password : virus

and give subject as : False Positive.

Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: avast 5.0.366: suspicious file detected : hardlock.sys
« Reply #4 on: January 19, 2010, 10:42:50 AM »
It's a Behavior Shield detection.
Can you please post the contents of the file

c:\programdata\alwil software\avast5\log\arPot.log

??

Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: avast 5.0.366: suspicious file detected : hardlock.sys
« Reply #5 on: January 19, 2010, 10:55:49 AM »
How does the Behavior Shield popup look like? I've never seen one to date.
Visit my webpage Angry Sheep Blog

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: avast 5.0.366: suspicious file detected : hardlock.sys
« Reply #6 on: January 19, 2010, 01:38:40 PM »
RejZoR: look at the screenshot somewhere in beta subforum... someone already posted it (yesterday) ;)

samnetx

  • Guest
Re: avast 5.0.366: suspicious file detected : hardlock.sys
« Reply #7 on: January 21, 2010, 04:11:09 PM »
It's a Behavior Shield detection.
Can you please post the contents of the file

c:\programdata\alwil software\avast5\log\arPot.log

??

Thanks
Vlk

Log file arPot.log attached here.
It shows that hardlock.sys file is suspicious by avast5.0.366
File sent to avast for verification.
« Last Edit: February 04, 2010, 03:03:10 PM by samnetx »