Author Topic: Strange virus filepath within ADNM  (Read 3593 times)

0 Members and 1 Guest are viewing this topic.

StormsEdge

  • Guest
Strange virus filepath within ADNM
« on: March 03, 2009, 05:44:16 PM »
I currently have the ADNM console run weekly bootscans of a network we manage.  This past week, it returned an infection filepath of (computername)\*RAW:C:\Windows\System\Update.exe on an XP Pro SP3 machine.  Not too familiar with the *RAW portion of this filepath, anyone have any suggestions?

Thanks

av-outsource

  • Guest
Re: Strange virus filepath within ADNM
« Reply #1 on: March 08, 2009, 11:33:00 PM »
well the RAW is the rootkit scanner i think, its a command line scanner. example if you were to run aswquick RAW: C:\ it would run a command line scan with rootkit detection.

avosec.com