PDA

View Full Version : FALSE POSITIVE False-Positive Detection



ghoulagoon
16-04-2021, 05:37 AM
RAPORT: link (<b>You have to register to ba able to see this link</b>)
ANTIVIRUS: Windows Defender
Additional information:

I play on NonSteam build from warzone.

wCD -> Cstrike (dlls/executables/scripts): roundendblock_mm.dll is marked as Unknown.
This file came along with the LAN server v4.6.5 from kz-rush.ru community.

wCD -> CFG: default.cfg (MD5: 05C06BB2F46283B8A89722D958F5CAEF) (Size: 1905) (Alias count: 2) (Lines: 111) (Binary: False) -> Whitelisted.


// zoom
alias zoom_in "sensitivity 2;fov 90;wait;fov 70;wait;fov 50;wait;fov 30;wait;fov 10;wait;fov 5;bind F11 zoom_out"
alias zoom_out "sensitivity 4;fov 5;wait;fov 10;wait;fov 30;wait;fov 50;wait;fov 70;wait;fov 90;bind F11 zoom_in; sensitivity 3"
bind F11 zoom_in

GAME MEMORY DUMP LINK: link (<b>You have to register to ba able to see this link</b>) I PM'd the password to Tiger.

P.S. - If you cover NonSteam related wCD issues and have the time, please look into it, because I don't know what triggers it, and admins are like: "Let's see... oh a 'Generic Cheat Detection', alright. Ban." I've included all the info I could find. Much appreciated!

Tiger
17-04-2021, 12:51 PM
Do you have applications which integrates with other applications (e.g.: teamviewer, fps overlays, etc.)? There are 2 (small) suspicious memory regions but I can't find out if they are a part of a cheat, malware or legit application.

Regarding roundendblock_mm.dll, you can upload it here if you want to whitelist it.

LE: From what I see you have Norton Internet Security, can you close your CS, add your CS in Norton's whitelist, run CS and test it again? I suspect that Norton Internet Security is at fault.

ghoulagoon
19-04-2021, 11:32 AM
So, I updated my Norton Internet Security Suit, and whitelisted both hl.exe and (wCD).exe. Then I did the wargods scan (<b>You have to register to ba able to see this link</b>), and good news - I'm clean! Yay! :) No need to alter your software!

But before I did the scan I managed to do some work to answer your other two questions.

Do you have applications which integrates with other applications (e.g.: teamviewer, fps overlays, etc.)? There are 2 (small) suspicious memory regions but I can't find out if they are a part of a cheat, malware or legit application.
- Nothing that I personally have installed for the purpose of running it in the background whilst I'm playing. I got this computer from my friend from Switzerland. He used to play minecraft and make content about it for youtube. Also, he and I use various music and audio related software. That's about all I can think of. I attached a list of programs I have on my pc if it helps.


Name Publisher Installed On↓
Adobe Acrobat Reader DC - Français Adobe Systems Incorporated 19/04/2021
Norton Internet Security NortonLifeLock Inc 19/04/2021
Microsoft Edge Microsoft Corporation 15/04/2021
Google Chrome Google LLC 15/04/2021
Dropbox Dropbox, Inc. 15/04/2021
Microsoft OneDrive Microsoft Corporation 10/04/2021
Mozilla Firefox 87.0 (x64 en-US) Mozilla 26/03/2021
Adobe Genuine Service Adobe 01/03/2021
Microsoft Update Health Tools Microsoft Corporation 20/02/2021
MicrosoftVisual C++ 2013 Redistributable (x86) - 12.0.30501 Microsoft Corporation 08/09/2020
MicrosoftVisual C++ 2015 Redistributable (x86) - 14.0.24215 Microsoft Corporation 08/09/2020
MicrosoftVisual C++ 2015 Redistributable (x64) - 14.0.23918 Microsoft Corporation 08/09/2020
Microsoft Visual C+ + 201 2 Redistributable (x64) - 11.0.61030 Microsoft Corporation 08/09/2020
Adobe Photoshop CC 2015 Adobe Systems Incorporated 08/09/2020
Adobe Premiere Pro CC 2015 Adobe Systems Incorporated 08/09/2020
MicrosoftVisual C++ 2012 Redistributable(x86) - 11.0.61030 Microsoft Corporation 08/09/2020
MicrosoftVisual C++ 2013 Redistributable (x64) - 12.0.30501 Microsoft Corporation 08/09/2020
WinRAR 5.31 (32-bit) win.rar GmbH 08/09/2020
WebTablet Netscape Plugin Wacom Technology Corp. 08/09/2020
WebTablet IE Plugin Wacom Technology Corp. 08/09/2020
VirtualDrive Pro FarStone Technology, Inc. 08/09/2020
TeamViewer 12 TeamViewer 08/09/2020
Steam Valve Corporation 08/09/2020
Samsung Printer Live Update Samsung Electronics Co., Ltd 08/09/2020
RStudio RStudio 08/09/2020
Microsoft Office Famille et Étudiant 2010 Microsoft Corporation 08/09/2020
Microsoft Office Language Pack 2010 - Latvian/latviski Microsoft Corporation 08/09/2020
Microsoft Office Language Pack 2010 - English Microsoft Corporation 08/09/2020
OBS Studio CBS Project 08/09/2020
Notepad + + (32-bit x86) Notepad++ Team 08/09/2020
Adobe lllustratorCC 2017 Adobe Systems Incorporated 08/09/2020
IL Download Manager Image-Line 08/09/2020
HiSuite Huawei Technologies Co.,Ltd 08/09/2020
Fraps 08/09/2020
FileZilla Client 3.26.1 Tim Kosse 08/09/2020
Canon Utilities CameraWindow DC 8 Canon Inc. 08/09/2020
Adobe Creative Cloud Adobe Systems Incorporated 08/09/2020
Adobe Audition 3.0 Adobe Systems Incorporated 08/09/2020
ASIO4ALL Michael Tippach 08/09/2020
Room EQWizard 5.19 John Mulcahy 08/09/2020
orca 1 .2.1 (only current user) Plotly, Inc. 08/09/2020
Dell Touchpad ALPS ELECTRIC CO., LTD. 08/09/2020
VLC media player VideoLAN 08/09/2020
Bamboo Wacom Technology Corp. 08/09/2020
Mozilla Maintenance Service Mozilla 08/09/2020
Mozilla Firefox 75.0 (x64 fr) Mozilla 08/09/2020
Module linguistique Microsoft Visual Studio 201 0 Tools pour Office Runtime (x64) - FRA Microsoft Corporation 08/09/2020
Microsoft Visual Studio 201 0 Tools for Office Runtime (x64) Microsoft Corporation 08/09/2020
FL Studio ASIC Image-Line 08/09/2020
Package de pilotes Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/28/2014 11.0... Google, Inc. 08/09/2020
iCloud Outlook Apple Inc. 10/07/2020
Skype version 8.60 Skype Technologies SA. 07/06/2020
Microsoft Visual Studio Installer Microsoft Corporation 24/03/2020
R for Windows 3.6.2 R Core Team 23/01/2020
Java 8 Update 241 Oracle Corporation 17/01/2020
FLStudio 12.1.3 23/04/2019
Update for Windows 1 0 for x64-based Systems (KB4480730) Microsoft Corporation 22/04/2019
Wampserver64 3.1.0 Dominique Ottello aka Otomat 15/10/2017
FonePaw Récupération De Données Android 2.2.0 Fone Paw 25/07/2017
EZdrummer 2 64-bit Toontrack 14/06/2017
Guitar Pro 6 Arobas Music 14/06/2017
Apple Application Support Apple Inc. 13/06/2017
QuickTime Apple Inc. 13/06/2017
AmpliTube 3 version 3.8.0 IK Multimedia 13/06/2017
Focusrite USB 4.15.0.172 Focusrite Audio Engineering 11/06/2017
Yousician Launcherversion 1.0 Yousician 05/06/2017
Microsoft Visual C+ + 2005 Red istributable Microsoft Corporation 19/05/2017
Transfer Utility PIXELA 12/03/2017
MicrosoftVisual C++ 2005 Redistributable Microsoft Corporation 23/08/2016
MicrosoftVisual C++ 2005 Redistributable (x64) Microsoft Corporation 23/08/2016
HTC Driver Installer HTC Corporation 23/08/2016
HTC Sync Manager HTC 23/08/2016
MicrosoftVisual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 26/06/2016
MicrosoftVisual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 26/06/2016
GIMP 2.8.16 The GIMP Team 30/05/2016
MicrosoftVisual C++ 2005 Redistributable (x64) Microsoft Corporation 30/04/2016
MicrosoftVisual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 30/04/2016
MicrosoftVïsual C++ 2005 Redistributable Microsoft Corporation 30/04/2016
MicrosoftVisual C++ 2005 Redistributable (x64) Microsoft Corporation 30/04/2016
OpenOffice 4.1.2 Apache Software Foundation 03/01/2016
MicrosoftVisual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 03/01/2016
MicrosoftVisual C++ 2008 Redistributable -x64 9.0.30729.6161 Microsoft Corporation 03/01/2016
Audacity 2.1.0 Audacity Team 30/12/2015

Regarding roundendblock_mm.dll, you can upload it here if you want to whitelist it.
- I can, but is it only going to whitelist this particular version of the file? As far as I know the author actively makes updates and a new version of this file could come out and potentially cause issues in the future if not for me then for someone else. If the file is the reason why wCD reports a Generic Cheat Detection, only then I will whitelist it (my last scan report shows it is not the case).

Tiger
20-04-2021, 09:46 PM
I suspected it's Norton's fault for causing this issue. I deleted all your false-positives.

And yes, it will be only for that file - any modification to that file will change the hash of the file, thus it won't be in whitelist anymore. And no, this file can't cause "Generic Cheat Detection" if the author doesn't implement something suspicious in this module.