Windows 8
There’s a hidden file at C:\DkHyperbootSync. I can’t view it in the C:, but other programs are able to detect it. I can’t seem to scan it with Comodo, nor submit it for online scanning. Searching on google brings up many pages about malware, the first of which being on these forums with the troubling text:
“Rootkit.HiddenFile[at]0 c:\DkHyperbootSync.”
The file is currently in use and appears to be constantly updated. It appears to be used by ExpressCache.exe. Comodo Cleaning Essentials found nothing. Malwarebytes Anti-Rootkit found nothing. Is this a false positive?
Edit: I was able to unhide it with the help of another program. Scanning the file locally says it comes up clean. Trying to use Valkyrie doesn’t work, as it says that the file is already in use. Two new hidden temp files showed up around the same time. I tried to scan them, and ended up with the same results.