I'm using Bitdefender AV 2010 with Comodo Firewall and Defense+. I've changed the path of the My Documents folder, so that while it was earlier in the same partition where XP is installed, now it is in another partition on a second HDD. On that partition, I've used Defense+ to block access to certain folders where I store a lot of stuff, but the My Documents folder isn't blocked.
Since the past few days, I've noticed the computer being sluggish. I generally don't scan with the AV regularly, about once a month, since the real-time detection is enabled and it is supposed to take care of malware right in the beginning, from what I understand.
Anyway, I started a scan of the XP partition (on HD1) with the rootkit option selected. It scanned the partition pretty quick, but then it said it was scanning for rootkits and went on for two hours without showing any path of where it was scanning. I finally got tired and stopped it, and when I opened the log file, which actually doesn't open fully in Internet Explorer because it is too long, it showed that there 14080 hidden items, and it said in Threat Name: Rootkit - Hidden items. All of these are files in the other partition (on HD2) which houses the My Documents folder, but these files are not in the My Documents folder, and I had only selected the XP partition for scanning. BitD has found rootkits in every single file, including jpegs, word files, flvs and mp3s, etc. None of them is actually hidden, since I can see them in explorer.
1. When we scan for a rootkit, does it always scan the whole computer, or can we scan an individual file? In this case, a whole lot of files not in the scan path got scanned.
2. There is a special tool from BitDefender for rootkits, though I haven't downloaded it yet. Is there any need to scan with it, or is it the same that is there in the main AV?
3. I used other tools, like Sophos Anti-Rootkit, and it found "Unknown Hidden File" in places like "Program Files\Foxit Reader.exe", "Program Files\Common Files\Bitdefender\Setup Information\{blahblahblah}\pluginsx86.exe", etc, and finally recommended not doing anything. Can anyone suggest a tool for the home dummies, that detects and deletes rootkits without asking too many questions? Or suppose I unblock all folders from Defense+ and scan the whole hard disk (200 GB + 1 TB) with BitD, how much time should I expect it take?
I'm trying to understand what rootkits are, and I've understood a bit, but to tell the truth it is way too complicated.