PDA

View Full Version : FALSE POSITIVE False Detection



fr33r1d3r
12-04-2021, 09:20 PM
RAPORT: <b>You have to register to ba able to see this link</b>

ANTIVIRUS: AdGuard and Dr Web Security Space

Additional information: Early I was false positive because of Dr Web demo client that I had in my comuter... I deleted a Dr Web demo client and then everything was going well. But now I was scanned again and it says "generic cheat detection". Why??

GAME MEMORY DUMP LINK: <b>You have to register to ba able to see this link</b>

Tiger
12-04-2021, 10:08 PM
Did you rebooted your system after you uninstalled Dr.Web? Did you had your CS opened before this action?

fr33r1d3r
12-04-2021, 10:10 PM
I reboot my laptop but not immediatly after deleting a Dr Web demo client. I deleted it client while cs was opened I think...

Tiger
12-04-2021, 10:26 PM
Well, then you answered your question. This is the reason why I tell everyone that Dr.Web uses the same memory injection mechanism as malware/cheats. They use this method in order to avoid being detected by malware. That memory region persists until the process exits or the system is rebooted. A normal antimalware product won't do this kind of memory injection, there are better ways to deal with malware...

fr33r1d3r
12-04-2021, 10:35 PM
What antivirus you could advise me?

Tiger
22-04-2021, 10:05 PM
I am sorry, I didn't see your post. I recommend Bitdefender Free Antivirus (<b>You have to register to ba able to see this link</b>) because it's lightweight and have a very high detection rate despite it lacks ransomware protection.