Author Topic: Reporting a Rootkit FP in Windows 8  (Read 3819 times)

0 Members and 1 Guest are viewing this topic.

stormer

  • Guest
Reporting a Rootkit FP in Windows 8
« on: June 22, 2012, 03:26:35 PM »
I am using Windows 8 RP 64-bit.

Last night, I installed Avast 7 Free, with a custom installation with Web and Network Shield only.

Changes to Avast Free (Web and Network Shield only):

- Linked to my.avast.
- Activated free license.
- Enabled PUP detection on Web Shield.
- Disabled Social/Recommended features.
- Disabled Generate monthly report.
- Disabled start-up rootkit scan.

Action Center reported that Avast and Windows Defender were both turned off.

Manually switched on Windows Defender. (Update: As of late last night, WD is now turned OFF)

I get an avast pop-up saying rootkit detected (see screenshot).

I chose Ignore.

Generate a log file (extracted from aswAr.log):
Code: [Select]
Service WdBoot [C:\WINDOWS\system32\drivers\WdBoot.sys]  **HIDDEN**
Service WdFilter [C:\WINDOWS\system32\drivers\WdFilter.sys]  **HIDDEN**
Service WinDefend [C:\Program Files]  **HIDDEN**

The Wd* files are related to the Anti-Malware services in Windows 8 Release Preview.

I can only assume these are False Positives and could potentially do more damage than good for the system.

(Not intended to be a copy and paste job from -http://malwaretips.com/Thread-Avast-Rootkit-FP) - Remove this line is necessary.
« Last Edit: June 22, 2012, 03:32:18 PM by Av-As-T »

true indian

  • Guest
Re: Reporting a Rootkit FP in Windows 8
« Reply #1 on: June 22, 2012, 03:38:11 PM »
Obvious FP's

send the files to virus@avast.com with subject false positives..