SpywareBlaster Need Developer Help

Discussion in 'SpywareBlaster & Other Forum' started by _Kim_, Jun 24, 2010.

Thread Status:
Not open for further replies.
  1. _Kim_

    _Kim_ Registered Member

    Joined:
    Jun 24, 2010
    Posts:
    4
    Hello,
    At this moment I'm getting help from a security expert on an issue I'm having with an alternate data stream. We are investigating the file 5C321E34.tmp that can be found in the /ProgramData/TEMP and Users/All Users/TEMP directories. I found a link when reseraching this file that states it is created by SpywareBlaster, can a developer confirm or deny this please, because I dont want to waste this guys time on a false positive.

    Thank you. Kim.
     
  2. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
  3. _Kim_

    _Kim_ Registered Member

    Joined:
    Jun 24, 2010
    Posts:
    4
    The first link you posted was created by me and yes OA++ has detected it. OTL and ADSspy are both detecting it also, the reason I think it was created by SpywareBlaster is this thread https://www.wilderssecurity.com/showthread.php?t=218483 It makes alot of sense for it to be a FP but I just want it confirmed.
     
  4. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
    Thanks for the link. I see it on Win7 as well. I have deleted the file and on SB restart the file comes back.
     
    Last edited: Jun 24, 2010
  5. _Kim_

    _Kim_ Registered Member

    Joined:
    Jun 24, 2010
    Posts:
    4
    Interesting Cudni, can I ask if you used ADSspy to scan for it? Alternate data streams can not be seen by explorer even with "show hidden files and folders" "hide protected operating system files" selected/unselected. I'm using Vista myself, there could be some difference there too.
     
  6. Cudni

    Cudni Global Moderator

    Joined:
    May 24, 2009
    Posts:
    6,956
    Location:
    Somethingshire
    No, I used AlternateStreamView from Nirsoft
     
  7. _Kim_

    _Kim_ Registered Member

    Joined:
    Jun 24, 2010
    Posts:
    4
Loading...
Thread Status:
Not open for further replies.