Login
▼
Register
Home
Help
Search
Login
Register
Adlice.com
Adlice forum
»
Software feedback
»
RogueKiller
»
2 .sys files flagged as File.Forged - False Positives or not ?
« previous
next »
Print
Pages: [
1
]
Author
Topic: 2 .sys files flagged as File.Forged - False Positives or not ? (Read 11301 times)
0 Members and 2 Guests are viewing this topic.
June 20, 2016, 05:21:34 PM
Kryss1621
Newbie
Offline
8
Reputation:
0
2 .sys files flagged as File.Forged - False Positives or not ?
«
on:
June 20, 2016, 05:21:34 PM »
Greetings.
As introduced in the subject, my last scan got two files flagged as File.Forged > hidparse.sys - hidusb.sys
Here is the report.
__
RogueKiller V12.3.4.0 (x64) [Jun 20 2016] (Gratuit) par Adlice Software
email :
http://www.adlice.com/contact/
Remontées :
http://forum.adlice.com
Site web :
http://www.adlice.com/fr/logiciels/roguekiller/
Blog :
http://www.adlice.com
Système d'exploitation : Windows 10 (10.0.10586) 64 bits version
Démarré en : Mode normal
Utilisateur : x [Administrateur]
Démarré depuis : C:\Users\x\Downloads\RogueKillerX64 (10).exe
Mode : Scan -- Date : 06/20/2016 15:57:23
¤¤¤ Processus : 0 ¤¤¤
¤¤¤ Registre : 0 ¤¤¤
¤¤¤ Tâches : 0 ¤¤¤
¤¤¤ Fichiers : 2 ¤¤¤
[File.Forged][Fichier] C:\Windows\System32\drivers\hidparse.sys -> Trouvé(e)
[File.Forged][Fichier] C:\Windows\System32\drivers\hidusb.sys -> Trouvé(e)
¤¤¤ Fichier Hosts : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤
¤¤¤ Navigateurs web : 0 ¤¤¤
__
I don't get anything else with any other software so I just wanted to make it sure before taking any actions.
Thanks in advance.
Logged
Reply #1
June 20, 2016, 06:17:09 PM
Curson
Global Moderator
Hero Member
Offline
2809
Reputation:
100
Re: 2 .sys files flagged as File.Forged - False Positives or not ?
«
Reply #1 on:
June 20, 2016, 06:17:09 PM »
Hi Kryss1621,
Welcome to Adlice.com Forum.
Could you please post the JSON report in your next reply ?
Regards.
Logged
Reply #2
June 20, 2016, 06:35:50 PM
Kryss1621
Newbie
Offline
8
Reputation:
0
Re: 2 .sys files flagged as File.Forged - False Positives or not ?
«
Reply #2 on:
June 20, 2016, 06:35:50 PM »
Sure, here you go.
Logged
Reply #3
June 20, 2016, 07:24:15 PM
Curson
Global Moderator
Hero Member
Offline
2809
Reputation:
100
Re: 2 .sys files flagged as File.Forged - False Positives or not ?
«
Reply #3 on:
June 20, 2016, 07:24:15 PM »
Hi Kryss1621,
At first sight, the files are harmless. However, they are not digitally signed which is really unusual.
I don't think it's absolutely necessary, but do you want them to be replaced by signed copies ?
Regards.
Logged
Reply #4
June 20, 2016, 07:55:55 PM
Kryss1621
Newbie
Offline
8
Reputation:
0
Re: 2 .sys files flagged as File.Forged - False Positives or not ?
«
Reply #4 on:
June 20, 2016, 07:55:55 PM »
First of all, thanks for the quick replies.
Secondly, if there is an easy way to replace them by signed and sure copies to avoid any problem like that in the future, I would gladly do so.
Logged
Reply #5
June 20, 2016, 08:08:06 PM
Curson
Global Moderator
Hero Member
Offline
2809
Reputation:
100
Re: 2 .sys files flagged as File.Forged - False Positives or not ?
«
Reply #5 on:
June 20, 2016, 08:08:06 PM »
Hi Kryss1621,
You are very welcome.
OK. Please follow the following process :
Please download
Farbar Recovery Scan Tool (x64)
and save it to your Desktop.
Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click
Yes
to disclaimer.
Copy/paste the following string in the Search box :
hidparse.sys*;hidusb.sys*
Press
Search Files
button.
It will produce a log called
Search.txt
in the same directory the tool is run from.
Please attach log back here.
Regards.
Logged
Reply #6
June 20, 2016, 08:43:15 PM
Kryss1621
Newbie
Offline
8
Reputation:
0
Re: 2 .sys files flagged as File.Forged - False Positives or not ?
«
Reply #6 on:
June 20, 2016, 08:43:15 PM »
Here is the txt file.
Logged
Reply #7
June 20, 2016, 09:19:39 PM
Curson
Global Moderator
Hero Member
Offline
2809
Reputation:
100
Re: 2 .sys files flagged as File.Forged - False Positives or not ?
«
Reply #7 on:
June 20, 2016, 09:19:39 PM »
Hi Kryss1621,
Download attached
fixlist.txt
file and save it to the Desktop.
NOTE.
It's important that both files,
FRST64
and
fixlist.txt
are in the same location or the fix will not work.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system !
Run
FRST
and press the
Fix
button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Regards.
Logged
Reply #8
June 20, 2016, 09:26:50 PM
Kryss1621
Newbie
Offline
8
Reputation:
0
Re: 2 .sys files flagged as File.Forged - False Positives or not ?
«
Reply #8 on:
June 20, 2016, 09:26:50 PM »
Done, and here is the fixlog.txt .
Logged
Reply #9
June 20, 2016, 09:32:41 PM
Curson
Global Moderator
Hero Member
Offline
2809
Reputation:
100
Re: 2 .sys files flagged as File.Forged - False Positives or not ?
«
Reply #9 on:
June 20, 2016, 09:32:41 PM »
Hi Kryss1621,
The files has been replaced with signed copies.
You could now delete FRST and the files linked to it.
Regards.
Logged
Print
Pages: [
1
]
« previous
next »
Adlice forum
»
Software feedback
»
RogueKiller
»
2 .sys files flagged as File.Forged - False Positives or not ?