1
RogueKiller / Re: ===> False Positives <===
« on: May 07, 2016, 12:25:12 AM »
F-Secure Antivirus is again coming up as Zeus, as you can see in log attached.
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
In fact, I haven't received anything.
Could you please host the dump on DropBox/Onedrive and share the link here ?
Hi Jukka,
The hook is mostly related to your antivirus.
However, we are going to verify it.
Please follow the following process.Regards.
- Download Process Explorer and save it to your desktop.
- Click on the setup file (procexp.exe) and select Run as Administrator to start the tool.
- Locate the process named explorer.exe, right click select Create Dump > Create Full Dump...
- Save the dump on your desktop and compress it.
- Go to Adlice Software upload form, select the dumps as files to be uploaded and copy/paste a link to this thread in the "Comment" section.
Quote from: JukkaBut that isn't what I'm worrying about, I'm worried about that IAT hook that was detected:Do you use anti-exploit softwares on your computer ?
[IAT:Inl(Hook.IEAT)] (explorer.exe @ KERNELBASE.dll) ntdll!NtCreateUserProcess : Unknown @ 0x7ffb99622018 (jmp 0xffffffff8000bb88)