![]() |
|
#1
|
|||
|
|||
|
well prevx and dr web av 5 realtime give this pc a clean bill of health but gmer scan has a scary tale to tell....so can i trust prevx or am i missing something ?
screen shot: |
|
#2
|
||||
|
||||
|
Hi, not really scary, but if you're not used to ARK's then they sure can be !
Looks like legit entries to me. sr.sys = Sytem Restore which appears to be disabled ? svchost = i imagine are normal windows files You could always upload them to VT & Jotti to check |
|
#3
|
||||
|
||||
|
I agree with SteveO - this looks like a false positive from GMER because the files are in the correct paths and under the correct service names. It might be worth installing and trying another antirootkit program to see if it finds anything as well.
Also note that some system protection programs (not Prevx, however) prevent antirootkit programs from functioning properly so you may want to double check with them disabled/uninstalled. Let me know what you find ![]() |
|
#4
|
|||
|
|||
|
Quote:
Quote:
![]() |
|
#5
|
||||
|
||||
|
Could you let us know what other security software you're using? (Mostly just so we prevent any FPs in the future which could be similar to GMER's
) |
|
#6
|
|||
|
|||
|
Quote:
alias prevx to check its wellbeing all seemed well but windows update icon in the tool bar with 0% update got the hercule poirot in me to investigate the net result .... to to i think i need to look for something else than rollback rx for my pcs it seems to cause a lot more fp warnings any suggestions? |
|
#7
|
||||
|
||||
|
Quote:
@thathagat can you scan with MBAM, SAS, HitmanPro and esp pls try RootRepeal.
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#8
|
|||
|
|||
|
Quote:
SAS:quick scan clean Mbam:quick scan clean Hitman pro:clean RootRepeal:Among other hidden files about prevx/dr web this too Quote:
Quote:
|
|
#9
|
||||
|
||||
|
Often when using ARK's they highlight normal files etc that can behave in an RK fashion. Nothing to worry about generally, but i agree it's very alarming at first until you get more used to it. The danger is, deleting legit files that show up. Always try and cross reference with other Apps, and using a search www before even thinking of doing anything.
I still feel they are FP's, but if you send them to Prevx they'll soon tell you. Try to copy them to a new folder etc, via one of your ARK's. PSCHED.SYS = Safe to use The filename PSCHED.SYS is used by objects that are classified as safe. It has not yet been seen to be associated with malicious software. http://www.prevx.com/filenames/33884...SCHED.SYS.html cryptsvc = Microsoft seclogon = Secondary Logon Microsoft |
|
#10
|
||||
|
||||
|
I agree that these are most likely FPs - thathagat: can you try removing the other security software you have installed to see if they are FPs caused by other product's protection? We had an FP a while back with our rootkit detection because of Comodo's disk protection making us think that files were rootkits which may be similar to what is happening here.
|
|
#11
|
||||
|
||||
|
Thanks. I just wonder why gmer is doing this. I will still like to post it over sysinternals.
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#12
|
|||
|
|||
|
Quote:
gmer-now shows only one entry no hidden services etc Quote:
Quote:
|
|
#13
|
||||
|
||||
|
Quote:
What program are you using for taking installation snapshots? Many of them hide the MBR which would explain the warning you're receiving. |
|
#14
|
||||
|
||||
|
Quote:
From the screenshot looks like he's using Returnil, which would explain the false positive
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes Check your PC in about a minute |
|
#15
|
||||
|
||||
|
Quote:
|
|
#16
|
||||
|
||||
|
Quote:
Rollback Rx would most likely be the culprit for the rootkit warning as it does hide the MBR. A word of caution: don't use the fix MBR utilities on your system as you may lose your snapshots if they think they're cleaning the rootkit which is actually your rollback software ![]() |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|