Registry Keys Infected

Closed
Disa - Nov 4, 2008 at 03:41 AM
 Stanimir Todorov - Nov 30, 2008 at 12:16 AM
Hello,

I have a problem with my labtop, window XP, i scanned it with Malwarebytes' Anti-Malware and it detects 1 infected object, but when i remove it, it will say the infected object has successfully been removed or deleted. then if i repeat the scan, i will find it again still not been removed. i updated Malwarebytes' Anti-Malware again before i can scan but nothing happen. please help, below is the scan log after scanning.

Malwarebytes' Anti-Malware 1.30
Database version: 1355
Windows 5.1.2600 Service Pack 2

02/11/2008 14:50:11
mbam-log-2008-11-02 (14-50-04).txt

Scan type: Quick Scan
Objects scanned: 69681
Time elapsed: 11 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-21cx1c642131} (Trojan.Agent) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

I clicked remove infected object, but when i repeat the scan, the infected object is still not been removed.

1 response

crazy_devil Posts 124 Registration date Wednesday February 20, 2008 Status Member Last seen February 6, 2009 20
Nov 4, 2008 at 04:11 AM
Use Spyware doctor or trojan hunter this might solve the problem...because sometimes anti-virus can't do anything against these types of viruses
0
Stanimir Todorov
Nov 30, 2008 at 12:16 AM
I had got the same problem, but i solve it.
First:
I use HIJACK and in its log file i found next text:
O4 - HKCU\..\Run: [Windows Service help] C:\RECYCLER\S-1-5-21-1105904803-3096713726-146242782-7211\winservices.exe

Then i delete this with HIJACK.
After this i start Malvare. It give me again:
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-21cx1c642131} (Trojan.Agent) -> Quarantined and deleted successfully.
The next scan with Malvare was clean.
0