Jump to content

Will not ignore windows system 32 drivers

Recommended Posts

Each scan finds the same 7 windows system 32 drivers after I tell it to always ignore.  These are all part of windows 7, but it alerts me Malware Detected after each scan, though I uncheck the boxes and tell it to Always Ignore.


Unknown.Rootkit.Driver, C:\WINDOWS\SYSTEM32\drivers\afd.sys, , [fa886682cfc5d36718d3e436aacf10b9],

Unknown.Rootkit.Driver, C:\WINDOWS\SYSTEM32\drivers\appid.sys, , [90c53bd47979fb8814f465a08b885102],

Unknown.Rootkit.Driver, C:\WINDOWS\SYSTEM32\drivers\drmk.sys, , [e0d3cd5841e5c7be7b94ba946af1e498],

Unknown.Rootkit.Driver, C:\WINDOWS\SYSTEM32\drivers\drmkaud.sys, , [9b19f34400d24df84c858a421c205754],

Unknown.Rootkit.Driver, C:\WINDOWS\SYSTEM32\drivers\portcls.sys, , [1e0b4cbba91c6b041a14ecc2186f7e24],

Unknown.Rootkit.Driver, C:\WINDOWS\SYSTEM32\drivers\rmcast.sys, , [caf88d6573d21cd2aa27001ddbfdc74d],

Unknown.Rootkit.Driver, C:\WINDOWS\SYSTEM32\drivers\stream.sys, , [001cc10fa5e71ae1119115e126c8750d],


Link to post
Share on other sites

I don't know for sure but my hunch is that ignoring anything in %windir%\SYSTEM32\drivers  would be too dangerous to allow.

FYI... I just reinstalled Rollback Rx to have the latest build of the software and then ran a scan.  It has solved the problem sure enough.  It no longer finds the system32 files as malware when it scans rootkits.  We'll see if that stays the case as the program takes new snapshots.  Thanks for the help!

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.