![]() |
|
#1
|
|||
|
|||
|
PrevX CSI detected 3 rootkits on my system partition :
1. C:\WINDOWS\system32\drivers\OADriver.sys (Hidden data) 2. C:\WINDOWS\system32\drivers\OAmon.sys (Hidden data) 3. C:\WINDOWS\system32\drivers\OAnet.sys (Hidden data) When scanners detect something on my system partition, I always report it at Wilders, because these objects are supposed to be false positives in theory. IMO these files are related to Online Armor Free Firewall, which I recently installed, but I would like to have an intelligent opinion, rather than a artificial intelligent opinion of a scanner. Are these 3 object rootkits or false positives ? Yes or No. |
|
#2
|
||||
|
||||
|
Yup, they look like FPs
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder". "Perfect is the enemy of good enough". Voltaire. |
|
#3
|
|||
|
|||
|
Quote:
![]() Computers can't "think", they only "compare". Last edited by ErikAlbert : April 4th, 2008 at 05:58 PM. |
|
#4
|
||||
|
||||
|
OA's drivers are digitally signed?
Also, you can compare checksums with other OA users.
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder". "Perfect is the enemy of good enough". Voltaire. |
|
#5
|
|||
|
|||
|
Quote:
On occasion it sucks ,but how many are actually saved by it. ![]() user intelligence sucks even more ! |
|
#6
|
||||
|
||||
|
Quote:
No they are not intelligent, they dont know how another HIPS works, if they did what would prevent malware to mimic a HIPS? As I understand it HIPS like software do hook them selves to the same places as malware do, and sort of behaves like malware in a way. So to me it is no big surprise, it is actually a good sign imo, that behavior based antimalware identifies them as suspicious. I would be more worried (if I ever were to use two HIPS like software at the same time, which I would never do) if it didnt detect another HIPS. It is annoying, yes. But they just do their job. |
|
#7
|
|||
|
|||
|
I reported this to Prevx, to avoid scaring people for nothing in the future.
|
|
#8
|
||||
|
||||
|
Thanks for your report.
It should be now fixed ![]()
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute |
|
#9
|
|||
|
|||
|
Quote:
I hate it, when a scanner reports a Windows object as malware, but all f/p's of other softwares are acceptable for me. |
|
#10
|
|||
|
|||
|
Quote:
Skynet, anyone? ![]() |
|
#11
|
||||
|
||||
|
Quote:
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder". "Perfect is the enemy of good enough". Voltaire. |
|
#12
|
|||
|
|||
|
Quote:
__________________
useful tools:cure it SAS Hitman Pro mbam KL Eset windows defender offline Sophos |
|
#13
|
||||
|
||||
|
Quote:
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3. |
|
#14
|
|||
|
|||
|
Quote:
|
|
#15
|
||||
|
||||
|
Thanks.
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3. |
|
#16
|
|||
|
|||
|
A smart scanner provides a function in the scanner to report false/positives and makes it as easy as possible and TIME-SAVING for the user to report false/positives.
|
|
#17
|
||||
|
||||
|
Right. I'll need to re-install it before using the "support" button, which is only available when it's installed.
Unfortunately, I don't know for sure that what I have are FP's. Certainly the files referred to in the scan report can't be found. (Or, I can't find them.)
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3. |
|
#18
|
|||
|
|||
|
Quote:
If a vendor does that to me, I take the first link I find on the website, even when that link is not the right one. The vendor must be glad, I take the time to report these and I'm certainly not paid to do this. ![]() I couldn't even copy/paste the f/p's to my email. |
|
#19
|
||||
|
||||
|
Quote:
Absolutely, that's the smart thing to do.
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness |
|
#20
|
||||
|
||||
|
Quote:
It's already in the Todo list ![]() We're going to release a big update in about a week and this one will include the requested feature too.
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute |
|
#21
|
||||
|
||||
|
Will there be an update for the 2.0 version also?
|
|
#22
|
|||
|
|||
|
Quote:
|
|
#23
|
||||
|
||||
|
Quote:
MBAM has this also. ![]()
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness |
|
#24
|
|||
|
|||
|
Quote:
As far I know SUPERAnti-Spyware has also this function.I'm telling this already for 2 year at Wilders. Once it is marked as a f/p by the user, the scanner knows all the information of these objects, because it's on the harddisk and knows where to send that info. Why do users have to collect all this manually ? TrojanHunter is the worst I've seen, they make an art of it to report f/p's, including a complete guide, how to report f/p's. Crazy !!! Last edited by ErikAlbert : April 6th, 2008 at 12:42 PM. |
|
#25
|
||||
|
||||
|
Yes, SUPERAntiSpyware dows also have such a function. Very usefull indeed. I'm hoping more security softwares will have this function in the future - which I am sure they will.
__________________
Microsoft Security Essentials |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|