Jump to content

Rogue.NetCom3 - Dell eSMART


Recommended Posts

Please remove this FP -

After some initial research, the registry key referenced contains this thread:

ImagePath REG_EXPAND_SZ \??\C:\Program Files\Asset Services Management\ProcObsrv.sys

This belongs to Dell's eSMART client, which is used for system and software tracking (which we use to keep our licensing trued-up)

I have confirmation from Dell that the registry key/file referenced is one of theirs (I can provide email conversation if necessary).

Initially we were told to allow MWB to remove this item, however we've noticed that select machines we do this to stop polling to the remote server.

Malwarebytes' Anti-Malware 1.44

Database version: 3842

Windows 5.1.2600 Service Pack 3

Internet Explorer 6.0.2900.5512

3/10/2010 3:03:09 PM

mbam-log-2010-03-10 (15-02-42).txt

Scan type: Quick Scan

Objects scanned: 185617

Time elapsed: 9 minute(s), 33 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 1

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ProcObsrv (Rogue.NetCom3) -> No action taken. [E3270D361F3073780E55C2595A80C6CF]

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.