PDA

View Full Version : Spybot antirootkit find c: \ boot.iniandox invisible to Win32



tighine
2014-06-29, 10:26
I scanned a pc with the anti-rootkit provided by SpyBot SD2, the end has come out as the title:

\ \???\C:\ boot.iniandbox
Type: File
Subject: boot.iniandbox
Location: C:\
Details: Invisible to Win32


The report indicates neither size nor other properties. The application states that it deleted but not be able to start its cleaning tools (which suggests that he is still around).
Obviously, you do not see the file, via Windows, in the directory of the disk.

I tried searching on the net, and here, too, but has been my inability, I do not think there are news about it, to read.

The curious "filename" or rather the alleged extension would seem to let think of a mispronunciation of c: \ boot.ini sandbox, ie a fragment of old files ....

Nevertheless think about that? And above all: what to do?


Thanks in advance to all.


Ps: One between the previous actions that may have "introduced" something, there have been only connected, via usb hd with HFS partitions

Jahboa
2015-03-12, 01:38
Hi,

I have the exact same thing as tighine.
Spybot finds c:\boot.iniandbox, it's invisible to Win32 and this thread is the ONLY page google can find... This is weird! What is it??

As for info, I am (still) running WinXP SP3, up to date. I am running Spybot v.2.4.40.0, and it's up to date.
I have a licensed version of Avast (maybe that's something, it looks like "sandbox", an Avast feature)
Futhermore, I have installed and run the monthly Windows Malicious Software REmoval Tool. I have not restarted yet.

Does anyone have a clue as to what is happening??
I will report back as soon as I have more elements.

Kind regards,

Jahboa

tashi
2015-03-12, 05:28
Hello Jahboa,


Hi,

I have the exact same thing as tighine.
Spybot finds c:\boot.iniandbox, it's invisible to Win32 and this thread is the ONLY page google can find... This is weird! What is it??

I'll see if I can find out, it's an unusual spelling.


As for info, I am (still) running WinXP SP3, up to date.

Unfortunately XP can't be up to date because it is no longer supported. XP: Microsoft Countdown (http://forums.spybot.info/showthread.php?70051-XP-Microsoft-Countdown)

How is the computer running, any issues?

Best regards. :)