Solved Infected registry found by MBAM

FranzB

New member
Local time
5:52 PM
Messages
208
Hi

W7 Home 64bit - Windows firewall (highest settings) - MSE (real time protection)
Browser: Firefox in safe mode but IE is still on the computer since i use Windows Live Mail.

MBAM found an infection, quick scan, admin rights:
Malware.Trace: Registry value HKEY_current_user_software\Microsoft\currentversion\Policies\Explorer\DisallowCpl|1

I put it in quarantine.

Next day i had some time and restored the infection. Then i ran (quick) scans with MSE, MBAM and SuperAntiSpyware. Nothing found. Also a scan with Hitmanpro 3.5: nothing found. A full registry scan with SuperAS: nothing found.
A renewed scan with MBAM found it again. I put it back into quarantine.

My questions now are:
Is it a false positive?
If not, can i just delete it from quarantine and that's it? Or do i have to look at the registy entries and change/check something there too?
I also did (quick) scans with those AV programs in safe mode while the infection was in quarantine but nothing found in addition.
I am at a loss that MBAM found something that no less than 3 other AV programs did not find.
Thanks.
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Home Premium 32bit, Linux Mint Juli...Intel Celeron 900 @2.2 GHzDDR3 2048 Mbytes
Computer Manufacturer/Model Number
Acer Extensa 5235
OS
Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode
CPU
Intel Celeron 900 @2.2 GHz
Motherboard
Acer BA50-MV(U2E1)
Memory
DDR3 2048 Mbytes
Sound Card
Conexant HD Audio
You could upload the file in question to virustotal.com and see what results you get there. It will analyze the file with a bunch of different scanners.

You also might want to take a gander at Malwarebytes forums to see if there are any posts about it, particularly re false positive.
 

My Computer My Computer

At a glance

Windows 7 Home Premium SP1, 64-bitIntel Skylake i5-6600K, not overclocked8 GB HyperX DDR4-2666 (2 x 4 GB)none; graphics are integrated on CPU
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Ignatz Special; 4 speed manual gearbox; factory air conditioning; one of one
OS
Windows 7 Home Premium SP1, 64-bit
CPU
Intel Skylake i5-6600K, not overclocked
Motherboard
AsRock Z170M Extreme 4, micro ATX
Memory
8 GB HyperX DDR4-2666 (2 x 4 GB)
Graphics Card(s)
none; graphics are integrated on CPU
Sound Card
onboard: Realtek ALC1150; external: USB Behringer UF0-202
Monitor(s) Displays
Dell S2340M 23 inch IPS
Screen Resolution
1600 x 900
Hard Drives
System: Crucial MX100 series SSD, 128 GB;
Data: Samsung Spinpoint 103SJ, 1 TB;
Backup: WD Caviar Green WD30EZRX-00D8PB0, 3 TB
PSU
Rosewill SilentNight 500 watt fanless, semi-modular
Case
Antec Solo II
Cooling
Noctua NH-U12S; Noctua F12 intake, Noctua S12A exhaust
Keyboard
Microsoft 200 6JH-00001 USB
Mouse
Dell or Microsoft optical wired; USB
Antivirus
Microsoft Security Essentials and Malwarebytes Premium
Browser
Pale Moon
Other Info
All fans PWM; speeds at idle: CPU circa 500 rpm; intake circa 600 rpm; exhaust circa 600 rpm; CPU temps 27 idle and 47 C load in a warm room (27 C/81 F) when running Intel Extreme Tuning Utility stress test.
It may be just alerting you to the setting being set to "1".

DisallowCpl

Jim :geek:
 

My Computer My Computer

At a glance

Windows 8.1 Pro w/Media Center 64bit, Windows...Phenom II X6 1100TCrucial Balistic 8gb DDR3-1866 CL9MSI R6850 Cyclone IGD5 PE
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built
OS
Windows 8.1 Pro w/Media Center 64bit, Windows 7 HP 64bit
CPU
Phenom II X6 1100T
Motherboard
ASUS M5A99X EVO
Memory
Crucial Balistic 8gb DDR3-1866 CL9
Graphics Card(s)
MSI R6850 Cyclone IGD5 PE
Sound Card
On Board
Monitor(s) Displays
ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort
Screen Resolution
1920 x 1080
Hard Drives
Two WD Cavier Black 2TB Sata III, WD My Book Essential 2TB USB 3.0
PSU
Seasonic X650 80 Plus GOLD Modular
Case
Corsair 400R
Cooling
Antec Kuhler H2O 620, Two 120mm and four 140mm
Keyboard
Logitech K120
Mouse
Logitech Marble Mouse USB, Logitech Precision Game Pad
Internet Speed
15MB
Antivirus
Norton IS 2013, Malwarebytes Pro Beta 2
Browser
IE-11, FF-27
Other Info
APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program, Motorola SB6120 Gigabit Cable Modem. Brother HL-2170W Laser Printer, Epson V300 Scanner
Thanks to both of you. I did have a look at the link given (not that i understand it).
It may be something for the Malwarebyte's forum, rather than for this forum.

It may also be connected with CCleaner. I usually fix the registry problems there but once i stored a backup in my documents before fixing and left it there.
It may be wiser not to fix the registry problems found with CCleaner but up to now it has never caused any problems.
Meanwhile i decided to delete the infection from quarantine and get rid of that backup in my documents. Some icons in the start menue are now gone. No problem though.
Point remains why that setting was changed to 1 and how and by whom.
Greetings.
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Home Premium 32bit, Linux Mint Juli...Intel Celeron 900 @2.2 GHzDDR3 2048 Mbytes
Computer Manufacturer/Model Number
Acer Extensa 5235
OS
Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode
CPU
Intel Celeron 900 @2.2 GHz
Motherboard
Acer BA50-MV(U2E1)
Memory
DDR3 2048 Mbytes
Sound Card
Conexant HD Audio
You could edit the registry and change it to "0" which is the default and see if it gets changed again.

Jim :geek:
 

My Computer My Computer

At a glance

Windows 8.1 Pro w/Media Center 64bit, Windows...Phenom II X6 1100TCrucial Balistic 8gb DDR3-1866 CL9MSI R6850 Cyclone IGD5 PE
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built
OS
Windows 8.1 Pro w/Media Center 64bit, Windows 7 HP 64bit
CPU
Phenom II X6 1100T
Motherboard
ASUS M5A99X EVO
Memory
Crucial Balistic 8gb DDR3-1866 CL9
Graphics Card(s)
MSI R6850 Cyclone IGD5 PE
Sound Card
On Board
Monitor(s) Displays
ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort
Screen Resolution
1920 x 1080
Hard Drives
Two WD Cavier Black 2TB Sata III, WD My Book Essential 2TB USB 3.0
PSU
Seasonic X650 80 Plus GOLD Modular
Case
Corsair 400R
Cooling
Antec Kuhler H2O 620, Two 120mm and four 140mm
Keyboard
Logitech K120
Mouse
Logitech Marble Mouse USB, Logitech Precision Game Pad
Internet Speed
15MB
Antivirus
Norton IS 2013, Malwarebytes Pro Beta 2
Browser
IE-11, FF-27
Other Info
APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program, Motorola SB6120 Gigabit Cable Modem. Brother HL-2170W Laser Printer, Epson V300 Scanner
MBAM once found a false positive on my machine regarding a registry key. I had customized the start menu and chose to hide the "help and support" link in the start menu, and MBAM flagged it as PUM (potentially unwanted modification).
 

My Computer My Computer

At a glance

Windows 7 Home Premium x64 SP1
OS
Windows 7 Home Premium x64 SP1
I tried taking a restore point but the icons in the start menu did not return.
I'll try your suggestions above but i can live with no icons.
Everything else seems ok.
I probably posted all this too fast but you are always afraid something is really wrong.
I should swallow my own medicine and surf with Linux exclusively and also transfer my mailbox to Linux. All this looking over your shoulder constantly when online is getting on my nerves, trying to outwit tens of thousands of virus writers.
Thanks all for your replies.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 32bit, Linux Mint Juli...Intel Celeron 900 @2.2 GHzDDR3 2048 Mbytes
Computer Manufacturer/Model Number
Acer Extensa 5235
OS
Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode
CPU
Intel Celeron 900 @2.2 GHz
Motherboard
Acer BA50-MV(U2E1)
Memory
DDR3 2048 Mbytes
Sound Card
Conexant HD Audio
Back
Top