PDA

View Full Version : 2 dodgy results in deep rootkit scan



justinius23
2013-05-16, 18:24
so for old time sake (i hadn't used spybot in a while) i decided to download and run a scan today. program has improved greatly and was impressed to see a rootkit scanner.

unfortunately, i got two results i;m not sure what to with

Type: File
Object: Temp:07BF512B:$DATA
Location: C:\Users\All Users\
Details: Unknown ADS

Type: File
Object: Temp:56E2E879:$DATA
Location: C:\Users\All Users\
Details: Unknown ADS

these files were originally created back in 2012 and i am having NO trouble with my PC. my question is - what are they? malware? spyware? a rootkit? and should i get rid of them? tdsskiller didn't catch them or malwarebytes. anything needed (logs etc.) is fine

cheers in advance.

thanks for any help

spybotsandra
2013-05-17, 12:01
Hello,

That are temp files.
They can be bad, but do not need to.

Malware sometimes uses rootkit technology to hide itself at system level.
This makes it undetectable by standard tools. Our plugins help Spybot – Search & Destroy to detect this form of malware.
Our Rootkit Scanner tool shows anything that uses certain rootkit technologies. But items with rootkit properties detected here are not necessarily malware. Sometimes, legit software uses rootkit technologies to hide registration data or other things it does not want the user to see in any case. So please keep in mind that the Rootkit Scanner only flags suspicious stuff, not identifying just bad stuff.

The deletion is final and can not be recovered through the Quarantine. If you still want to remove the found items it is strongly recommend to create a system restore point (http://windows.microsoft.com/en-US/windows-vista/System-Restore-frequently-asked-questions) before doing that.

Best regards
Sandra
Team Spybot

justinius23
2013-05-17, 12:14
thank you kindly for the reply. as i said, im not having any problems with my pc so i think i'll just leave them for now.