Author Topic: False positive?  (Read 6420 times)

0 Members and 1 Guest are viewing this topic.

August 04, 2015, 08:40:24 PM

gamefan

  • Newbie

  • Offline
  • *

  • 23
  • Reputation:
    0
    • View Profile
False positive?
« on: August 04, 2015, 08:40:24 PM »
Hello, I'd like to report a false positive if this is one


¤¤¤ Antirootkit : 1 (Driver: Not loaded [0xc000035f]) ¤¤¤
[IAT:Inl(Hook.IEAT)] (explorer.exe @ WLDAP32.dll) msvcrt.dll - memset : Unknown @ 0x518d0672 (call 0x4cbe5a42)

It popped up when I ran the Roguekiller in safe mode, I scanned again and it didn't show up. Is this a false positive?

Reply #1August 05, 2015, 01:46:37 PM

gamefan

  • Newbie

  • Offline
  • *

  • 23
  • Reputation:
    0
    • View Profile
Re: False positive?
« Reply #1 on: August 05, 2015, 01:46:37 PM »
found some more out of safe mode, heres the txt file

Reply #2August 06, 2015, 09:51:52 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: False positive?
« Reply #2 on: August 06, 2015, 09:51:52 PM »
Hi gamefan,

Welcome to Adlice.com Forum.
These hooks are indeed legit. ;)

Regards.

Reply #3August 07, 2015, 12:13:15 PM

gamefan

  • Newbie

  • Offline
  • *

  • 23
  • Reputation:
    0
    • View Profile
Re: False positive?
« Reply #3 on: August 07, 2015, 12:13:15 PM »
so i can safely ignore all 79 hooks i reported? i read/was told if they have unknown at the end or vanish and dont show up again to ignore them correct? since they havent shown up again for a day or two I can safely ignore them especially if roguekiller and my othr antivirus/antimalware stuff didnt find anything? just didnt want them being actually being a problem and them getting on an external hdd backup of mine

Reply #4August 07, 2015, 01:49:59 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: False positive?
« Reply #4 on: August 07, 2015, 01:49:59 PM »
Hi gamefan,

Yes, you can safely ignore them. They are not malicious.

Regards.