1
RogueKiller / Re: False positive?
« on: November 20, 2014, 03:37:45 AM »
Well, actually as the time it was a system disk, it was F:.
The problem now is that the file
F:\WINDOWS\System32\CTFMON.EXE
or
I:\WINDOWS\System32\CTFMON.EXE
doesn't exist and both volume are used only for data (and paging file), so I don't undestand how Rouguekiller can found it (and detect it as bad).
Where are the reg hives? In the hidden directory "System Volume Information" with the restore point data?
Today I boot with a linux live-cd and I see that in "System Volume Information" of I: there are also files with the date attribute showing some years before the last clean install on C:, maybe they come from the old installation and Rouguekiller read it as the current one (is it possibile?).
The problem now is that the file
F:\WINDOWS\System32\CTFMON.EXE
or
I:\WINDOWS\System32\CTFMON.EXE
doesn't exist and both volume are used only for data (and paging file), so I don't undestand how Rouguekiller can found it (and detect it as bad).
Where are the reg hives? In the hidden directory "System Volume Information" with the restore point data?
Today I boot with a linux live-cd and I see that in "System Volume Information" of I: there are also files with the date attribute showing some years before the last clean install on C:, maybe they come from the old installation and Rouguekiller read it as the current one (is it possibile?).