Adlice forum

Software feedback => RogueKiller => Topic started by: Steve76 on December 12, 2015, 08:59:44 AM

Title: Hidden.ADS - false positive?
Post by: Steve76 on December 12, 2015, 08:59:44 AM
Hi, Roguekiller has detected two Hidden.ADS "files" - C:\Windows:s8vj4g0sk4d1 and C:\Users\Me\AppData\Roaming:lv93ja32540f.

I've got a basic understanding of what alternate data streams are - I've not allowed RogueKiller to remove them yet as I'm worried it'll remove those entire folders!  They don't seem attached to individual files but the entire directory.  Are these false positives or something to worry about?  Nothing else has been detected, I've ran several other scans which all came back clean.  The computer is used only for work and has never had so much as an unwanted toolbar installed.  I've checked via command line and they do seem attached to the actual directory itself.

Any help appreciated!
Title: Re: Hidden.ADS - false positive?
Post by: Curson on December 14, 2015, 03:46:19 PM
Hi Steve,

Welcome to Adlice.com Forum.
We are going to investigate those ADS.

Launch the command prompt windows (cmd) with admin rights and copy/paste the following command :
Code: [Select]
more < C:\Windows:s8vj4g0sk4d1 > %USERPROFILE%\Desktop\checkADS1.log && more < C:\Users\Me\AppData\Roaming:lv93ja32540f > %USERPROFILE%\Desktop\checkADS2.logTwo files named checkADS1.log and checkADS2.log will be created on your desktop. Please attach them with your next reply.

Regards.
Title: Re: Hidden.ADS - false positive?
Post by: Steve76 on December 14, 2015, 03:54:03 PM
Hi, the log files are attached, thanks!

On Windows 7 (in case that's relevant).
Title: Re: Hidden.ADS - false positive?
Post by: Curson on December 14, 2015, 04:03:34 PM
Hi Steve,

At first sight, those ADS seems to be leftovers.
Could you please attach the JSON report in your next reply ?

Regards.
Title: Re: Hidden.ADS - false positive?
Post by: Steve76 on December 14, 2015, 05:01:49 PM
Hi, report attached (the PUP on the report seems to only point to a log file from a driver installation).

When you say "leftovers" could that be from something benign?  There's never been an infection removed.
Title: Re: Hidden.ADS - false positive?
Post by: Curson on December 14, 2015, 10:42:02 PM
Hi Steve,

It's difficult to be sure about the source of those ADS but they are not malicious in any way. Maybe they were left by some security program.
I think you can leave them alone.

Regards.
Title: Re: Hidden.ADS - false positive?
Post by: Steve76 on December 15, 2015, 06:33:43 AM
OK, thanks for your help.
Title: Re: Hidden.ADS - false positive?
Post by: Curson on December 15, 2015, 11:27:35 PM
Hi Steve,

You are welcome.

Regards.