Reporting a Rootkit FP in Windows 8

I am using Windows 8 RP 64-bit.

Last night, I installed Avast 7 Free, with a custom installation with Web and Network Shield only.

Changes to Avast Free (Web and Network Shield only):

  • Linked to my.avast.
  • Activated free license.
  • Enabled PUP detection on Web Shield.
  • Disabled Social/Recommended features.
  • Disabled Generate monthly report.
  • Disabled start-up rootkit scan.

Action Center reported that Avast and Windows Defender were both turned off.

Manually switched on Windows Defender. (Update: As of late last night, WD is now turned OFF)

I get an avast pop-up saying rootkit detected (see screenshot).

I chose Ignore.

Generate a log file (extracted from aswAr.log):

Service WdBoot [C:\WINDOWS\system32\drivers\WdBoot.sys]  **HIDDEN**
Service WdFilter [C:\WINDOWS\system32\drivers\WdFilter.sys]  **HIDDEN**
Service WinDefend [C:\Program Files]  **HIDDEN**

The Wd* files are related to the Anti-Malware services in Windows 8 Release Preview.

I can only assume these are False Positives and could potentially do more damage than good for the system.

(Not intended to be a copy and paste job from -http://malwaretips.com/Thread-Avast-Rootkit-FP) - Remove this line is necessary.

Obvious FP’s

send the files to virus@avast.com with subject false positives…