Author Topic: What is this?  (Read 7095 times)

0 Members and 1 Guest are viewing this topic.

March 05, 2016, 04:56:18 AM

stuckinarutt

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
What is this?
« on: March 05, 2016, 04:56:18 AM »
not sure if this the right place but anyone know what this is?
[SSDT:Inl(Hook.SSDT)] ZwDeleteAtom[119] : C:\Windows\System32\win32k.sys @ 0xffffffffa295abd9 (call dword [0x81cf7b84])
it showed up on my last scan.

Reply #1March 05, 2016, 04:08:16 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: What is this?
« Reply #1 on: March 05, 2016, 04:08:16 PM »
Hi stuckinarutt,

Which security softwares are you using ?
Could you please attach the JSON report in your next post ?

Regards.

Note : This thread has been moved to the "RogueKiller" section for clarity.

Reply #2March 05, 2016, 11:53:08 PM

stuckinarutt

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Re: What is this?
« Reply #2 on: March 05, 2016, 11:53:08 PM »
I use Iolo system mechanic Pro paid as my main AV.
someone suggested i also install  RUbotted a couple years ago.
also I run malwarebytes a couple times a month.
I get the roguekiller false Zeus warning on my antivirus component of Iolo. I think Iolo is currently using Commtouch antivirus 5.
I run TDSSKiller occasionally too.

Reply #3March 07, 2016, 01:07:43 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: What is this?
« Reply #3 on: March 07, 2016, 01:07:43 PM »
Hi stuckinarutt,

Thanks for your feedback.
These detections are false positives and they will be whitelisted as soon as possible.

Regards.

Reply #4March 07, 2016, 03:51:33 PM

stuckinarutt

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Re: What is this?
« Reply #4 on: March 07, 2016, 03:51:33 PM »
Thank You!! 8)

Reply #5March 07, 2016, 04:58:09 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: What is this?
« Reply #5 on: March 07, 2016, 04:58:09 PM »
Hi stuckinarutt,

You are welcome.

Regards.