Jump to content

Rootkit.ADS, c:\Windows\syswow64:win32app?


Recommended Posts

Hello StephenCWLL and :welcome:
 
In as much as this involves W10, the Experts/Staffers may wish to analyze your diagnostic reports:

  • Please read the topic Diagnostic Logs and then individually ATTACH the 3 requested logs in your next reply to this thread only.
  • The 3 files, from Step 1, to be individually ATTACHED from your desktop are CheckResults.txt, FRST.txt and Addition.txt. Please do not Zip or Copy and Paste them into a reply. Please do not alter, any FRST categories as they are pre-configured for this forum.

Thank You.

Link to post
Share on other sites

The file is an Alternate Data Stream.

 

It is not the normal disk file that we deal with on a day to day basis.  While there are legitimate uses of ADS, such as working with other Operating Systems, it is also a way to mask malicious activity.

 

Based upon this detection, the chances you are infected are high enough to warrant seeking one-on-one assistance from a trained Malware Removal Helper in;  Malware Removal Help

 

Malware Removal assistance can't be provided in this sub-forum.

Link to post
Share on other sites

The file is an Alternate Data Stream.

 

It is not the normal disk file that we deal with on a day to day basis.  While there are legitimate uses of ADS, such as working with other Operating Systems, it is also a way to mask malicious activity.

 

Based upon this detection, the chances you are infected are high enough to warrant seeking one-on-one assistance from a trained Malware Removal Helper in;  Malware Removal Help

 

Malware Removal assistance can't be provided in this sub-forum.

 

Jeez, don't scare me now :) I'm still leaning towards it not being anything too bad, but I'm curious as to what it is.

Link to post
Share on other sites

Hello StephenCWLL and :welcome:

 

In as much as this involves W10, the Experts/Staffers may wish to analyze your diagnostic reports:

  • Please read the topic Diagnostic Logs and then individually ATTACH the 3 requested logs in your next reply to this thread only.
  • The 3 files, from Step 1, to be individually ATTACHED from your desktop are CheckResults.txt, FRST.txt and Addition.txt. Please do not Zip or Copy and Paste them into a reply. Please do not alter, any FRST categories as they are pre-configured for this forum.

Thank You.

 

Here's the MBAM one for a mo. The other file creates a shed load of stuff that I'm not fully happy putting online as some of the files it lists are named with personal titles. I might have to tweak that file before posting!

CheckResults.txt

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.