Jump to content

Question about rogue.evidence eliminator

Recommended Posts

I use Malwarebytes in several different locations. I ran Malwarebytes on all my computers today and found the rogue.evidence eliminator infection (registry only) on all the computers. Problem is, I don't use and never have used Evidence Eliminator.

It hasn't shown up before and suddenly it's on all 10 computers that I checked.

I use CA anti-virus on 7 of my computers and MSE on 3. CA and MSE never mentioned anything.

Sorry if this has been covered in the past but can someone explain why I'm getting these rogue.evidence eliminator hits?

Here are the log entries:

Registry Keys Infected:

HKEY_CLASSES_ROOT\Interface\{f272845d-cec2-4f95-92ee-6d08fdfbd471} (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Typelib\{0e6117e2-c367-4be3-8045-52669e71b5df} (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Eeshellx.ShellExt (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.

Thanks in advance.

Link to post
Share on other sites

  • Root Admin


Please run a Quick Scan on one of the computers again where you've not quarantined the items but use the /developer switch when you launch it.

Click on START - RUN and type in: mbam /developer then do your Quick Scan and post that back in the False Positive forum.

Also post your link here in that forum when you do post your log.


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.