Author Topic: Hidden.ADS - false positive?  (Read 10897 times)

0 Members and 1 Guest are viewing this topic.

December 12, 2015, 08:59:44 AM

Steve76

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Hidden.ADS - false positive?
« on: December 12, 2015, 08:59:44 AM »
Hi, Roguekiller has detected two Hidden.ADS "files" - C:\Windows:s8vj4g0sk4d1 and C:\Users\Me\AppData\Roaming:lv93ja32540f.

I've got a basic understanding of what alternate data streams are - I've not allowed RogueKiller to remove them yet as I'm worried it'll remove those entire folders!  They don't seem attached to individual files but the entire directory.  Are these false positives or something to worry about?  Nothing else has been detected, I've ran several other scans which all came back clean.  The computer is used only for work and has never had so much as an unwanted toolbar installed.  I've checked via command line and they do seem attached to the actual directory itself.

Any help appreciated!

Reply #1December 14, 2015, 03:46:19 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Hidden.ADS - false positive?
« Reply #1 on: December 14, 2015, 03:46:19 PM »
Hi Steve,

Welcome to Adlice.com Forum.
We are going to investigate those ADS.

Launch the command prompt windows (cmd) with admin rights and copy/paste the following command :
Code: [Select]
more < C:\Windows:s8vj4g0sk4d1 > %USERPROFILE%\Desktop\checkADS1.log && more < C:\Users\Me\AppData\Roaming:lv93ja32540f > %USERPROFILE%\Desktop\checkADS2.logTwo files named checkADS1.log and checkADS2.log will be created on your desktop. Please attach them with your next reply.

Regards.

Reply #2December 14, 2015, 03:54:03 PM

Steve76

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Re: Hidden.ADS - false positive?
« Reply #2 on: December 14, 2015, 03:54:03 PM »
Hi, the log files are attached, thanks!

On Windows 7 (in case that's relevant).

Reply #3December 14, 2015, 04:03:34 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Hidden.ADS - false positive?
« Reply #3 on: December 14, 2015, 04:03:34 PM »
Hi Steve,

At first sight, those ADS seems to be leftovers.
Could you please attach the JSON report in your next reply ?

Regards.

Reply #4December 14, 2015, 05:01:49 PM

Steve76

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Re: Hidden.ADS - false positive?
« Reply #4 on: December 14, 2015, 05:01:49 PM »
Hi, report attached (the PUP on the report seems to only point to a log file from a driver installation).

When you say "leftovers" could that be from something benign?  There's never been an infection removed.

Reply #5December 14, 2015, 10:42:02 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Hidden.ADS - false positive?
« Reply #5 on: December 14, 2015, 10:42:02 PM »
Hi Steve,

It's difficult to be sure about the source of those ADS but they are not malicious in any way. Maybe they were left by some security program.
I think you can leave them alone.

Regards.

Reply #6December 15, 2015, 06:33:43 AM

Steve76

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Re: Hidden.ADS - false positive?
« Reply #6 on: December 15, 2015, 06:33:43 AM »
OK, thanks for your help.

Reply #7December 15, 2015, 11:27:35 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Hidden.ADS - false positive?
« Reply #7 on: December 15, 2015, 11:27:35 PM »
Hi Steve,

You are welcome.

Regards.