Tough to say without more information. There are countless attack vectors here, from desktop malware targeting sysadmin credentials, to local vulnerabilities on the platform.
Any process can write there, that and /tmp are the easiest/most obvious places to go.
clamscan -R /, but I wouldnt put...