PDA

View Full Version : FALSE POSITIVE Generic Cheat Detection



S9OUL.
11-08-2023, 04:56 PM
REPORT: <b>You have to register to ba able to see this link</b>
ANTIVIRUS: Normal Windows antivirus, I made a quick scan, but it didn't find anything.
Additional information: -
GAME MEMORY DUMP LINK: <b>You have to register to ba able to see this link</b>

Tiger
11-08-2023, 09:37 PM
Please upload file called dataexchange.dll.

S9OUL.
11-08-2023, 11:11 PM
Hello,

Sorry but I tried to search for the file, and I got nothing. Could you please explain where to search specifically?

-----

I tried to search on this path "C:\Windows\System32" and I got the file "link below" If this is not the file, please let me know to get the right one!

<b>You have to register to ba able to see this link</b> (same pw)

Greetings.

Tiger
11-08-2023, 11:55 PM
"This folder does not contain any files."

S9OUL.
12-08-2023, 12:13 AM
I'm sure i archived the dll file.

Here is another link for the file, but it is not archived. (<b>You have to register to ba able to see this link</b>).

If you are aware of the viruses, here is another archived file uploaded. (<b>You have to register to ba able to see this link</b>).

Tiger
12-08-2023, 05:56 AM
This is not the file I was looking for, has different sha256 hash than the one from your detection (0B2F4C09A06D5392BCB126F85CD68128AB24F13D2757A3021 08AD7547BA12425). Check C:\Windows\SysWOW64 instead.

S9OUL.
12-08-2023, 11:26 AM
Here is the file after searching on the path (C:\Windows\SysWOW64)

<b>You have to register to ba able to see this link</b> (same pw)

----

I used the hash provided from the wCD report to search for the file but I didn't find anything.

tupo luchshiy
13-08-2023, 01:42 AM
report <b>You have to register to ba able to see this link</b>
ANTIVIRUS - Dr, Web32 Cure It

--------------- Added after 11 minutes ---------------

<b>You have to register to ba able to see this link</b>

Tiger
15-08-2023, 04:17 PM
The md5 hashes for cheat files are encrypted to avoid webscrappers to collect data without my permission.

False-positive, detections removed.