Author Topic: Where can I find the filename that was deleted?  (Read 2302 times)

0 Members and 1 Guest are viewing this topic.

camper

  • Guest
Where can I find the filename that was deleted?
« on: July 21, 2011, 02:55:38 PM »
Avast Free 6.0.1203
Windows 7 - 64bit

When I started up the PC this morning, I logged in to my limited privilege account.  After a minute or two, Avast put up a red alert that a rootkit had been found.  It recommended that I select 'delete', which I did.  it also recommended that I perform a boot-time rootkit scan, which I also did.

The boot-time scan did not find anything of interest.

Now I'd like to find out the name of the file that contained the root kit, the file which Avast deleted.   I looked through the log files, but did not see an entry naming the deleted file.

How can I find out what the name of the file was that avast thought contained a rootkit and that avast deleted?

Thanks.

Nnixx

  • Guest
Re: Where can I find the filename that was deleted?
« Reply #1 on: July 21, 2011, 02:59:33 PM »
Start up Avast,then go to Maintenance (on left hand side) then Virus Chest

camper

  • Guest
Re: Where can I find the filename that was deleted?
« Reply #2 on: July 21, 2011, 03:46:40 PM »
The suspect file was not moved to the virus chest, it was deleted, per the suggestion from the alert.

There is nothing in the virus chest.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89034
  • No support PMs thanks
Re: Where can I find the filename that was deleted?
« Reply #3 on: July 21, 2011, 05:20:33 PM »
Check the C:\ProgramData\AVAST Software\Avast\log\aswAr.log file using notepad, that should contain any detection information (this folder may be hidden so you will need to change that).
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

camper

  • Guest
Re: Where can I find the filename that was deleted?
« Reply #4 on: July 21, 2011, 07:50:54 PM »
Thanks.  That was the ticket.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89034
  • No support PMs thanks
Re: Where can I find the filename that was deleted?
« Reply #5 on: July 21, 2011, 08:25:29 PM »
Well what was it that you deleted ?

Personally I opt for confirmation before deletion rather than after.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security