Adlice forum

Software feedback => RogueKiller => Topic started by: MrSirSteven on March 19, 2016, 08:14:41 AM

Title: False Hooks or Legit? freaking out!
Post by: MrSirSteven on March 19, 2016, 08:14:41 AM
Hello everyone, I've recently reinstalled Windows 7 and so far so good but after installing RogueKiller I scanned my PC a few times and the only thing that has popped up were a view
Start Menu changes which was I who did them. Now the problem comes from this, I started scanning with RogueKiller while I had Chrome open and I got A LOT of these Hooks. After seeing this I started scanning my PC with TDSSKiller, ADWCleaner, JRT, Malwarebytes, Malwarebyte Anti-rootkit, HitmanPro, RKill, SUPER AntiSpyware, Avast and they were all clean. I also went with the trouble to even use Combofix.  I'm kinda freaking out because I have no idea how I got them, It only happens when I have Chrome open and the Extensions I'm using are Avast, Adblock, Adblock Plus, Magic Action, and uBlock Origins, I also use Avast Internet Security Paid. I'll try and attach two, one scan without Extensions and one with. Thank you for the help, this is making me super paranoid.
Title: Re: False Hooks or Legit? freaking out!
Post by: Curson on March 21, 2016, 01:50:01 PM
Hi MrSirSteven,

Welcome to Adlice.com Forum.
These hooks are related to Chrome sandboxing features and, therefore, are legit ones.

The IAT hooks are only displayed on Expert Mode.
I advice you to use RogueKiller Normal Mode, so they won't be displayed.

Regards.
Title: Re: False Hooks or Legit? freaking out!
Post by: MrSirSteven on March 21, 2016, 10:43:12 PM
Hi MrSirSteven,

Welcome to Adlice.com Forum.
These hooks are related to Chrome sandboxing features and, therefore, are legit ones.

The IAT hooks are only displayed on Expert Mode.
I advice you to use RogueKiller Normal Mode, so they won't be displayed.

Regards.

Oh man what a relief, thanks for the reply!  ;D
Title: Re: False Hooks or Legit? freaking out!
Post by: Curson on March 21, 2016, 11:41:56 PM
Hi MrSirSteven,

You are very welcome. :)

Regards.