Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Avast 4.8 - trojan detected

Jul 11, 2008 11:14PM PDT

While updating Avast 4.8 this morning up pops this box saying a trojan has been detective, recommendations are to move the item to the chest which I did. Now to simply remove it I do what? Click on the item listed in the chest and hit "delete"? This is the first trojan detected by Avast 4.8 since I installed it onto my computer a few months ago.

Discussion is locked

- Collapse -
Steve, I would leave it in the chest
Jul 11, 2008 11:40PM PDT

for a few days to make sure it is not a false positive. If you could tell us the name of the trojan and exactly what avast told you as to which fie it clains is the trojan, we can check to see if it is a false positive or not.

- Collapse -
Re: Steve, I would leave it in the chest
Jul 11, 2008 11:49PM PDT

I'll get back with you on that soon.

- Collapse -
Re: Steve, I would leave it in the chest
Jul 12, 2008 3:24PM PDT

Details of the item stored in the chest in Avast:

Original file name: PROCESSLIST.BIN
Original folder: C:\Documents and Settings\My Name\Application Data\SuperAntiSpyware.com\SuperAntiSpyware
Size of file: 4030397
Virus description: Win32:Delf-KNW[Trj]
File ID: 22

- Collapse -
Steve, they released a second
Jul 12, 2008 7:56PM PDT

update last night to fix some false positives. Make sure you get the latest update and restore the file and scan again and see if it is still being flagged, That looks like a false positive to me.


Here is the update history page with everything that was added so you can see for yourself. Look at yesterday's second update below on that page.

Update avast! 4.x VPS (released:12.7.2008, version: 080712-1)

# 12.7.2008 - 80712-1

This VPS update contains only fixes to existing definitions or removal of false alarms.
http://www.avast.com/eng/vps_history.html

There has also been another released since then.
Update avast! 4.x VPS (released:13.7.2008, version: 080713-0)

- Collapse -
Avast
Jul 12, 2008 12:02AM PDT

Now to simply remove it I do what? Click on the item listed in the chest and hit "delete"?
---------
Yes or at least that's what the help files say.
Does that work?.....unknown...never had anything get put into the chest.

Suggestion.
Let the file sit in the chest for a week or so.
See if the machine crabs about the file being missing.
After a few more updates rescan the file.....might be a FP.

- Collapse -
Problem with Avast
Oct 19, 2008 5:30AM PDT

I am having the same problem right now but the thing is that I had just updated my avast lastnight and it has been getting worse and I am not sure on what I should do....I think that when the message came up to either delete the virus or put it into the chest someone clicked on the chest....The virus popped up before I had updated my Avast and well I am not sure on what I should do....My computer seems like it is going to crash....Internet explore has been messing up and also my messenger....If you can get back to me if you have any suggestion on what I should do that would be great thanks

- Collapse -
"the same problem"
Oct 19, 2008 5:35AM PDT

You mean you put the Processlist.bin file (part of SuperAntiSpyware) is the chest? Then leave it there and reinstall SuperAntiSpyware, because probably it won't run without this file. If it's tagged again as a virus or trojan, neglect the warning! It's a false positive then.

If it's something else, can you give a better description of your problem. All we know now:
- it's getting worse
- it seems like it is going to crash [how does that look?]
- IE has been messing up
- messenger has been messing up
That's not much to help.

Kees

- Collapse -
more information
Oct 19, 2008 5:42AM PDT

Sorry I have the anti-virus scanning again to see if it is going to tell me that it is still a virus....My messenger is deleting people off my list and sometimes not even letting me log on....My internet expore keeps on telling me that the page can not be displayed or if I am on facebook or something that you have to log into it keeps telling me that I am not logged on even if I had just loged on...Some on the programs that came with my pc are not working anymore they will not even open....I will let you know what the virus is and the file and stuff soon thanks

- Collapse -
This is what Avast is telling me
Oct 19, 2008 7:48AM PDT

Win32:Mapler-I [Trj]
Win32:Mapler-I [Trj]
Win32:Root-gen [Rtk]
Win32:Trojan-gen {Other}


I am not sure if this will help any

- Collapse -
add to my last one
Oct 19, 2008 7:52AM PDT

Sorry it is not saying that it is a virus it is saying that it is infected...I am confused on what to do....I scanned each of them and there is no virus found should I just restore them?

- Collapse -
IF NOT a False Positive....
Oct 19, 2008 3:51PM PDT

then it's indicating you have a couple of trojans & a Root Kit on-board.
Super Anti-Spyware should be able to find & remove these. Likely it will put them in quarantine (where they're harmless) for safe storage 'til you decide to empty/delete them. The reason for this is IF they turn out to be F.P"s, you can then restore the quarantined files back where they belong. This is ALWAYS a good idea(safe storage)to have as default behavior. It IS possible, if SAS already removed & stored them, Avast might find them there and report same to you. Avast probably can't remove them from SAS storage, only SAS can.

You can also get a Free Root Kit Remover from F-Secure called "Blacklight" in it's free-standing form. Beta but never misbehaved for me in years of different Beta versions: http://www.f-secure.com/blacklight/


Particularly because of the root kit, you might prefer to re-boot into Safe Mode and then run SAS from there. How to boot to S.M.:
http://www.pchell.com/support/safemode.shtml
Hope this helps. Happy