| Windows 7: Infected registry found by MBAM |
20 Sep 2011
|
#1 | | Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode |
Infected registry found by MBAM Hi
Windows 7 Home 64bit - Windows firewall (highest settings) - MSE (real time protection)
Browser: Firefox in safe mode but IE is still on the computer since i use Windows Live Mail.
MBAM found an infection, quick scan, admin rights:
Malware.Trace: Registry value HKEY_current_user_software\Microsoft\currentversion\Policies\Explorer\DisallowCpl|1
I put it in quarantine.
Next day i had some time and restored the infection. Then i ran (quick) scans with MSE, MBAM and SuperAntiSpyware. Nothing found. Also a scan with Hitmanpro 3.5: nothing found. A full registry scan with SuperAS: nothing found.
A renewed scan with MBAM found it again. I put it back into quarantine.
My questions now are:
Is it a false positive?
If not, can i just delete it from quarantine and that's it? Or do i have to look at the registy entries and change/check something there too?
I also did (quick) scans with those AV programs in safe mode while the infection was in quarantine but nothing found in addition.
I am at a loss that MBAM found something that no less than 3 other AV programs did not find.
Thanks.
Last edited by FranzB; 20 Sep 2011 at 01:53 PM..
Reason: text addition
| My System Specs |
| System Manufacturer/Model Number Acer Extensa 5235 OS Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode CPU Intel Celeron 900 @2.2 GHz Motherboard Acer BA50-MV(U2E1) Memory DDR3 2048 Mbytes Sound Card Conexant HD Audio |
20 Sep 2011
|
#2 | | Windows 7 SP1, Home Premium, 64-bit |
You could upload the file in question to virustotal.com and see what results you get there. It will analyze the file with a bunch of different scanners.
You also might want to take a gander at Malwarebytes forums to see if there are any posts about it, particularly re false positive. | My System Specs | | System Manufacturer/Model Number Ignatz Special; 4 speed manual gearbox; factory air conditioning; one of one OS Windows 7 SP1, Home Premium, 64-bit CPU Intel Sandy Bridge i5-2500, not overclocked Motherboard Gigabyte H67A-UD3H-B3, full ATX Memory 4 GB Crucial DDR3-1333 Graphics Card none; graphics are integrated on CPU Sound Card onboard: Realtek ALC892; external: USB Behringer UF0-202 Monitor(s) Displays NEC 90GX2-BK 19" LCD Screen Resolution 800 x 640 Keyboard Leopold Tenkeyless with Cherry Blue switches, USB Mouse Logitech or Microsoft optical wired; either USB or PS 2 PSU Seasonic SS-560KM, modular Case Antec Solo II Cooling CPU: Scythe Big Shuriken; Case: Scythe Slipstream 800 & 500 Hard Drives System: Intel 320 Series SSD, 80 GB;
Data: Samsung Spinpoint 103SJ, 1 TB;
Backup: WD Caviar Green WD15EADS-00P8B0, 1.5TB Other Info Power consumption of this system, including monitor: 68 watts at idle; 144 watts at full load |
20 Sep 2011
|
#3 | | Windows 7 HP 64bit, Windows 8 Pro w/Media Center 64bit Covington, La |
It may be just alerting you to the setting being set to "1". DisallowCpl
Jim | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Home Built OS Windows 7 HP 64bit, Windows 8 Pro w/Media Center 64bit CPU Phenom II X6 1100T Motherboard ASUS M5A99X EVO Memory Crucial Balistic 8gb DDR3-1866 CL9 Graphics Card MSI R6850 Cyclone IGD5 PE Sound Card On Board Monitor(s) Displays ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort Screen Resolution 1920 x 1080 Keyboard Logitech K120 Mouse Logitech Marble Mouse USB, Logitech Precision Game Pad PSU Seasonic X650 80 Plus GOLD Modular Case Corsair 400R Cooling Antec Kuhler H2O 620, Two 120mm and four 140mm Hard Drives Two WD Cavier Black 2TB Sata III, WD My Book Essential 2TB USB 3.0 Internet Speed 15MB Antivirus Norton IS 2012, Malwarebytes Pro Browser IE-10, FF-19 Other Info APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program, Motorola SB6120 Gigabit Cable Modem. Brother HL-2170W Laser Printer, Epson V300 Scanner |
20 Sep 2011
|
#4 | | Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode |
Thanks to both of you. I did have a look at the link given (not that i understand it).
It may be something for the Malwarebyte's forum, rather than for this forum.
It may also be connected with CCleaner. I usually fix the registry problems there but once i stored a backup in my documents before fixing and left it there.
It may be wiser not to fix the registry problems found with CCleaner but up to now it has never caused any problems.
Meanwhile i decided to delete the infection from quarantine and get rid of that backup in my documents. Some icons in the start menue are now gone. No problem though.
Point remains why that setting was changed to 1 and how and by whom.
Greetings.
Last edited by FranzB; 20 Sep 2011 at 03:06 PM..
Reason: additional text
| My System Specs | | System Manufacturer/Model Number Acer Extensa 5235 OS Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode CPU Intel Celeron 900 @2.2 GHz Motherboard Acer BA50-MV(U2E1) Memory DDR3 2048 Mbytes Sound Card Conexant HD Audio |
20 Sep 2011
|
#5 | | Windows 7 HP 64bit, Windows 8 Pro w/Media Center 64bit Covington, La |
You could edit the registry and change it to "0" which is the default and see if it gets changed again.
Jim | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Home Built OS Windows 7 HP 64bit, Windows 8 Pro w/Media Center 64bit CPU Phenom II X6 1100T Motherboard ASUS M5A99X EVO Memory Crucial Balistic 8gb DDR3-1866 CL9 Graphics Card MSI R6850 Cyclone IGD5 PE Sound Card On Board Monitor(s) Displays ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort Screen Resolution 1920 x 1080 Keyboard Logitech K120 Mouse Logitech Marble Mouse USB, Logitech Precision Game Pad PSU Seasonic X650 80 Plus GOLD Modular Case Corsair 400R Cooling Antec Kuhler H2O 620, Two 120mm and four 140mm Hard Drives Two WD Cavier Black 2TB Sata III, WD My Book Essential 2TB USB 3.0 Internet Speed 15MB Antivirus Norton IS 2012, Malwarebytes Pro Browser IE-10, FF-19 Other Info APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program, Motorola SB6120 Gigabit Cable Modem. Brother HL-2170W Laser Printer, Epson V300 Scanner |
20 Sep 2011
|
#6 | | Windows 7 Home Premium x64 SP1 SoCal USA |
MBAM once found a false positive on my machine regarding a registry key. I had customized the start menu and chose to hide the "help and support" link in the start menu, and MBAM flagged it as PUM (potentially unwanted modification). | My System Specs | | OS Windows 7 Home Premium x64 SP1 |
21 Sep 2011
|
#7 | | Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode |
I tried taking a restore point but the icons in the start menu did not return.
I'll try your suggestions above but i can live with no icons.
Everything else seems ok.
I probably posted all this too fast but you are always afraid something is really wrong.
I should swallow my own medicine and surf with Linux exclusively and also transfer my mailbox to Linux. All this looking over your shoulder constantly when online is getting on my nerves, trying to outwit tens of thousands of virus writers.
Thanks all for your replies. | My System Specs | | System Manufacturer/Model Number Acer Extensa 5235 OS Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode CPU Intel Celeron 900 @2.2 GHz Motherboard Acer BA50-MV(U2E1) Memory DDR3 2048 Mbytes Sound Card Conexant HD Audio Infected registry found by MBAM problems? All times are GMT -5. The time now is 12:33 AM. | |