Jump to content

Infected Registry Keys or False Positives?


Recommended Posts

In my usual scan with MBAM today, I was confronted with the following log. I have taken no action as yet, since I could not establish if these are False Positives or not. I say this, because only MBAM finds these entries. I have scanned with NIS09, SAS Pro, Kaspersky 7 on-Line Scanner, and none of these scanners find anything.

I would therefore appreciate your input as to how as I should proceed. Here is the log:

Malwarebytes' Anti-Malware 1.37

Database version: 2227

Windows 6.0.6001 Service Pack 1

4/6/2009 6:38:51 πμ

mbam-log-2009-06-04 (06-38-36).txt

Scan type: Quick Scan

Objects scanned: 77780

Time elapsed: 6 minute(s), 15 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 6

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\bfast.com (Adware.BHO) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\commission-junction.com (Adware.BHO) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.com (Adware.BHO) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.net (Adware.BHO) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\linksynergy.com (Adware.BHO) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\qksrv.net (Adware.BHO) -> No action taken.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Finally, when I don't see the "Quarantine" option available. Only the remove option. Should this be the case?

Thank you very much in advance.

TrDo.

Link to post
Share on other sites

Hi Thanks for your reply.

I updated and scanned again. Here is the log:

Malwarebytes' Anti-Malware 1.37

Database version: 2229

Windows 6.0.6001 Service Pack 1

4/6/2009 9:06:41 μμ

mbam-log-2009-06-04 (21-06-41).txt

Scan type: Quick Scan

Objects scanned: 78269

Time elapsed: 4 minute(s), 13 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Does that mean they were False Positives? Please let me know. I'm sure you understand that I'm a bit concerned if my pc was actually infected or not.

Thanks again.

TrDo.

Link to post
Share on other sites

  • Staff

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.