Recent Posts

Pages: [1] 2 3 ... 10
1
RogueKiller / Re: Another False Positive? PUP RunOnce in registry
« Last post by Curson on September 22, 2018, 08:55:30 pm »
Hi Faergor,

These entries are present as RunOnce keys used to modify system startup with MSConfig tool.
You can safely ignore them, but they should be gone on next reboot.

Regards.
2
RogueKiller / Another False Positive? PUP RunOnce in registry
« Last post by Faergor on September 22, 2018, 06:30:19 pm »
Hello, again, one hour later.
I did another Roguekiller scan, in safe mode this time, and it found this:

Registry : 2
[PUP] (X64) HKEY_USERS\S-1-5-21-1239764888-2148109162-3447206424-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce | Application Restart #1 : C:\Windows\System32\msconfig.exe %windir%\system32\msconfig [-] -> Found
[PUP] (X86) HKEY_USERS\S-1-5-21-1239764888-2148109162-3447206424-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce | Application Restart #1 : C:\Windows\System32\msconfig.exe %windir%\system32\msconfig [-] -> Found

Is this false positive please? I uploaded text file. Thanks
3
RogueKiller / Re: False Positive? Warframe - [Suspicious.Path] found in registry
« Last post by Curson on September 22, 2018, 05:02:12 pm »
Hi Faergor,

Thanks for your feedback.
This is indeed a false positive. We will fix this as soon as possible.

Regards.
4
RogueKiller / False Positive? Warframe - [Suspicious.Path] found in registry
« Last post by Faergor on September 22, 2018, 03:19:15 pm »
Hello, this was found today while scanning, is this please false positive?


Registry : 2
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {27624FD4-2773-4BBD-8B37-317672D4C322} : v2.28|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|RPort=80|RPort=443|RPort=8080|RPort2_10=6665-6669|RPort2_10=6695-6699|App=C:\Users\XXXXXXX\AppData\Local\Warframe\Downloaded\Public\Tools\Launcher.exe|Name=Warframe Launcher (TCP-In)|EmbedCtxt=Warframe|Edge=TRUE| [7] -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {FE17ED16-68BE-49B0-B16E-7D8378EC5C2A} : v2.28|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|Profile=Public|RPort=80|RPort=443|RPort=8080|RPort2_10=6665-6669|RPort2_10=6695-6699|App=C:\Users\XXXXXXX\AppData\Local\Warframe\Downloaded\Public\Tools\Launcher.exe|Name=Warframe Launcher (TCP-Out)|EmbedCtxt=Warframe| [7] -> Found

I scanned my PC day before yesterday and nothing was found and I had same version of Roguekiller installed as I have today (V12.13.1.0). I have warframe installed on my external HDD, but I do not remember launching it yesterday. I scanned my PC today and this was found. I am attaching txt file as well.
Thanks :)
5
RogueKiller / Re: ===> False Positives <===
« Last post by Curson on September 21, 2018, 08:49:21 pm »
Hi coldi,

Thanks.
We will fix this as soon as possible.

Regards.
6
RogueKiller PREMIUM / Re: maximum limit of activations reached
« Last post by Curson on September 21, 2018, 08:48:52 pm »
Hi MNL,

Welcome to Adlice.com Forum and thanks for supporting our product.
You are very welcome.

Regards.
7
RogueKiller PREMIUM / maximum limit of activations reached
« Last post by MNL on September 20, 2018, 06:23:07 pm »
Roguekiller says my maximum limit of activations has reached. Maybe i installed windows too often, but i only use RK. on my own pc and i have never shared it.

Could you please fix this?

Thank you

Account: Same e-mail as i registered this forum account


-Edit

I see that my account is active again, thank you :)
Btw. I tried the contactform first but i received no confirmation that my message was send. That`s why i made a forumtopic. I`m sorry if you received 8 or 9 messages about this same issue.
8
RogueKiller / Re: ===> False Positives <===
« Last post by coldi on September 16, 2018, 03:09:02 pm »
Sorry took a moment but here https://drive.google.com/file/d/15YH_ZymVP9ohOxTfGGwpVIbrhE77NpLG/view is the file.

regards
9
RogueKiller / Re: ===> False Positives <===
« Last post by Curson on September 15, 2018, 07:11:37 pm »
Hi coldi,

We need to retrieve more information.
Please follow the following process :
  • Download Process Explorer (x64) and save it to your desktop.
  • Click on the setup file (procexp64.exe) and select Run as Administrator to start the tool.
  • Locate the process named Wow.exe, do a right click on it and select Create Dump > Create Full Dump...
  • Save the dump on your desktop and compress it.
  • Upload it to Dropbox, Google Drive or similar services and share the link in your next reply.
Regards.
10
RogueKiller / Re: ===> False Positives <===
« Last post by coldi on September 15, 2018, 05:20:00 pm »
Hi there, I think I stumbled on a false positive. Latest scan detected the  world of warcraft .exe as something seemingly harmful. I add the report.
best regards
Pages: [1] 2 3 ... 10