Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Free Anti Rootkit

I've downloadeed and run the free anti rootkit. It noted it could not query one registry key. It also noted 22 "unknown hidden files," saying no information is available and it does not recommend cleaning them. I have no idea what to do next. I tried sending a mail message with the logs attached from https://secure.sophos.com/support/query/, but that doesn't seem to be going anywhere. Any advice?

:331


This thread was automatically locked due to age.
Parents
  • Hello, 

              I ran your anti rootkit software on a computer that does not show any sign of infection, but I did it because another computer in the lab, running AVG free 8.5 was infected with a rootkit.mrb, as identified by malwarebytes' anti-malware. I have Sophos installed on my computer and is up to date.

    The result of the scan was 32 unknown hidden files. One of them was related to firefox, and I guess it was found because I was running mozilla firefox while the scan was performed. The other 31 were all internet temporary files for Internet Explorer 5 in a different account on the same computer. I think that other account has been used probably two times ever.

    So my question is, based on the location of the files can I be confident they are not an indication of a threat?

    After I found this, I started a full and in depth scan with regular Sophos. I still don't know what the result is because I came home.

    Thanks for your time and advice.

    :602
Reply
  • Hello, 

              I ran your anti rootkit software on a computer that does not show any sign of infection, but I did it because another computer in the lab, running AVG free 8.5 was infected with a rootkit.mrb, as identified by malwarebytes' anti-malware. I have Sophos installed on my computer and is up to date.

    The result of the scan was 32 unknown hidden files. One of them was related to firefox, and I guess it was found because I was running mozilla firefox while the scan was performed. The other 31 were all internet temporary files for Internet Explorer 5 in a different account on the same computer. I think that other account has been used probably two times ever.

    So my question is, based on the location of the files can I be confident they are not an indication of a threat?

    After I found this, I started a full and in depth scan with regular Sophos. I still don't know what the result is because I came home.

    Thanks for your time and advice.

    :602
Children
No Data