Author Topic: Possible false positive?  (Read 7334 times)

0 Members and 1 Guest are viewing this topic.

November 12, 2014, 12:37:59 PM

bokhe

  • Guest
Possible false positive?
« on: November 12, 2014, 12:37:59 PM »
Hi I run a roguekiller scan once in a while and never had problems till version 10.4 but yesterday with 10.5 It terminates a process(in the inizial scan) based on IAStorDataMgrSvc.exe( marked in red in roguekiller), a file from Intel rapid storage. Even if in the report it does not specify a file path I have found that it terminates a process of a file of that name in the right place(aka intel rapid storage directory)
Scans with adwcleaner, kaspersky,tdss killer, junkware removal tool, rkill and malwarebytes anti-malware find nothing.After terminating the process if i do a second scan( aka close and open roguekiller 10.5) it finds nothing till I reboot my pc
Is it a false positive or am I infected?
Here is today log
RogueKiller V10.0.5.0 (x64) [Nov 11 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Admin [Administrator]
Mode : Scan -- Date : 11/12/2014  11:56:29

¤¤¤ Processes : 1 ¤¤¤
[Proc.Injected] IAStorDataMgrSvc.exe --
  • -> Killed [TermProc]


¤¤¤ Registry : 24 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gdrv (\??\C:\Windows\gdrv.sys) -> Found
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\klkbdflt2 (system32\DRIVERS\klkbdflt2.sys) -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gdrv (\??\C:\Windows\gdrv.sys) -> Found
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\gdrv (\??\C:\Windows\gdrv.sys) -> Found
[PUM.HomePage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome  -> Found
[PUM.HomePage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome  -> Found
[PUM.SearchPage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.SearchPage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-516113981-128559712-3750866543-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-516113981-128559712-3750866543-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-516113981-128559712-3750866543-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyComputer : 2  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-516113981-128559712-3750866543-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-516113981-128559712-3750866543-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowDownloads : 2  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-516113981-128559712-3750866543-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyComputer : 2  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-516113981-128559712-3750866543-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-516113981-128559712-3750866543-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowDownloads : 2  -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1   localhost

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD5000AAKX-001CA0 +++++
--- User ---
[MBR] 7e0f446f7c155f741d969ef5becf8a4d
[BSP] 161c0b8f017405d118db6226398ee0b4 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 476838 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_SCN_11112014_190906.log - RKreport_SCN_11112014_225041.log



Btw the hidden from SCM(marked in yellow) reg entry should be a kaspersky virtual keyboard file
Sorry for my bad english
Hope you can help me

Reply #1November 12, 2014, 03:42:14 PM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Possible false positive?
« Reply #1 on: November 12, 2014, 03:42:14 PM »
Hello
Could you send the file? (zip it with password)

Reply #2November 12, 2014, 05:28:41 PM

bokhe

  • Guest
Re: Possible false positive?
« Reply #2 on: November 12, 2014, 05:28:41 PM »
How can I send the file?BTW how i can add a password to a zip file?Tried winrar and it cannot access the file while windows buildt-in utility makes a zip but i dunno how i can add a password

Reply #3November 13, 2014, 08:11:24 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Possible false positive?
« Reply #3 on: November 13, 2014, 08:11:24 AM »
try to copy the file on the desktop first.
Forget the password, should work here

Reply #4November 13, 2014, 08:20:30 PM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Possible false positive?
« Reply #4 on: November 13, 2014, 08:20:30 PM »
Not detected at all with last version?
Can you confirm?

Reply #5November 13, 2014, 08:52:29 PM

bokhe

  • Guest
Re: Possible false positive?
« Reply #5 on: November 13, 2014, 08:52:29 PM »
No this is the timeline
1-run rogue10.5,detects in preliminary scan, prompts to update
2-update
3-reboot the pc
4-run rogue10.6, does not detect
5-possible that i have tried to run the file sorry i forgot, however the process was on since rebooting
6-run kaspersky with cloud on
7-re-run rogue10.6, it detects this
 [Proc.Injected] IAStorDataMgrSvc.exe -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[7] -> Killed [TermProc]

Reply #6November 14, 2014, 07:31:17 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: Possible false positive?
« Reply #6 on: November 14, 2014, 07:31:17 AM »
Ok, sounds like Kaspersky is injecting some code in your process.
So could you dump it after it's injected by Kaspersky (with process hacker)?