Jump to content

Search the Community

Showing results for tags 'SrvID'.

  • Search By Tags

    Type tags separated by commas.
  • Search By Author

Content Type


Forums

  • Announcements
    • Malwarebytes News
    • Beta Testing Program
  • Malware Removal Help
    • Windows Malware Removal Help & Support
    • Mac Malware Removal Help & Support
    • Mobile Malware Removal Help & Support
    • Malware Removal Self-Help Guides
  • Malwarebytes for Home Support
    • Malwarebytes for Windows Support Forum
    • Malwarebytes for Mac Support Forum
    • Malwarebytes for Android Support Forum
    • Malwarebytes for iOS Support
    • Malwarebytes Privacy
    • Malwarebytes Browser Guard
    • False Positives
    • Comments and Suggestions
  • Malwarebytes for Business Support
    • Malwarebytes Endpoint Protection
    • Malwarebytes Incident Response (includes Breach Remediation)
    • Malwarebytes Endpoint Security
    • Malwarebytes Business Products Comments and Suggestions
  • Malwarebytes Tools and Other Products
    • Malwarebytes AdwCleaner
    • Malwarebytes Junkware Removal Tool Support
    • Malwarebytes Anti-Rootkit BETA Support
    • Malwarebytes Techbench USB (Legacy)
    • Malwarebytes Secure Backup discontinued
    • Other Tools
    • Malwarebytes Tools Comments and Suggestions
  • General Computer Help and Security Updates
    • BSOD, Crashes, Kernel Debugging
    • General Windows PC Help
  • Research Center
    • Newest Rogue-Ransomware Threats
    • Newest Malware Threats
    • Newest Mobile Threats
    • Newest IP or URL Threats
    • Newest Mac Threats
    • Report Scam Phone Numbers
  • General
    • General Chat
    • Forums Announcements & Feedback

Find results in...

Find results that contain...


Date Created

  • Start

    End


Last Updated

  • Start

    End


Filter by number of...

Joined

  • Start

    End


Group


AIM


MSN


Website URL


ICQ


Yahoo


Jabber


Location


Interests

Found 1 result

  1. I recently downloaded Malwarebytes after Norton 360 kept telling me that I was getting attacked by a worm. I thought with Norton 360 I was protected from everything, but it appears not. After downloading Malwarebytes I ran a few scans and had to restart my computer a few times. I have run into 8 files that keep coming up on the scan. Here is the log: Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.05.25.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Owner :: OWNER-PC [administrator] 26/05/2012 3:07:26 PM 1.txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 207390 Time elapsed: 2 minute(s), 22 second(s) Memory Processes Detected: 3 C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 3412 -> No action taken. C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 3424 -> No action taken. C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 2776 -> No action taken. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> No action taken. Registry Values Detected: 2 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|msvcnp (Backdoor.Agent) -> Data: C:\Users\Owner\AppData\Roaming\msvcnp .exe -> No action taken. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|csrss (Trojan.Agent) -> Data: C:\Users\Owner\AppData\Roaming\csrss .exe -> No action taken. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\Windows\Temp\svchost.exe (Trojan.Agent) -> No action taken. C:\Users\Owner\AppData\Roaming\csrss .exe (Trojan.Agent) -> No action taken. (end) Here is the removal log of the same files. A popup also appears telling me to restart my computer. Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.05.25.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Owner :: OWNER-PC [administrator] 26/05/2012 3:07:26 PM mbam-log-2012-05-26 (15-07-26).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 207390 Time elapsed: 2 minute(s), 22 second(s) Memory Processes Detected: 3 C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 3412 -> Delete on reboot. C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 3424 -> Delete on reboot. C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 2776 -> Delete on reboot. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Quarantined and deleted successfully. Registry Values Detected: 2 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|msvcnp (Backdoor.Agent) -> Data: C:\Users\Owner\AppData\Roaming\msvcnp .exe -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|csrss (Trojan.Agent) -> Data: C:\Users\Owner\AppData\Roaming\csrss .exe -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\Windows\Temp\svchost.exe (Trojan.Agent) -> Delete on reboot. C:\Users\Owner\AppData\Roaming\csrss .exe (Trojan.Agent) -> Quarantined and deleted successfully. (end) After restarting my computer, the same 8 files appear in the next scan. Is there anything I can do to stop this? I had problems before with a file called update.exe appearing in my Roaming folder. When I deleted it, it would just appear again after a few seconds. So I deleted it and then put a folder in Roaming called update.exe. This stopped the file from appearing. Any input or help is appreciated.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.