Jump to content

Trojan Agent Registry Browser Settings Cannot remove


Recommended Posts

Malwarebytes log all clean except for following entries under heading:

Registry Values Infected

Entries are:

HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\EXPLORER\Browser Settings\bf (Trojan.Agent) -> Delete on Reboot

HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\EXPLORER\Browser Settings\bk (Trojan.Agent) -> Delete on Reboot

HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\EXPLORER\Browser Settings\iu (Trojan.Agent) -> Delete on Reboot

HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\EXPLORER\Browser Settings\mu (Trojan.Agent) -> Delete on Reboot

Other Symptoms for this system

Windows 5.1.2600 Service Pack 3

No other infections reported on malware bytes scan

On boot up repeated showing of "svchost.exe - Application error The memory could not be read and

"Generic Host Process for win 32"

Action taken

Repeated Removal attempts for svhost exe and Generic host processes problems by reference to support.microsoft.com/kb/821690 & 927385

all resulted in failure to deal with those issues.

As to the reported registry entry all forms of removal fail.

Delete on reboot does not appear to succeed.

I have tried deleting using regedit but deletion fails with "unable to delete all specified values" when attempting to delete one or all of these values.

I have even tried to delete all Browser Settings values without success.

Can anyone please point me in right direction

Thanks

David

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.