Jump to content

deleted item not in quarentine


Recommended Posts

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

ani idea wht this is and why it would not be in quarentine?

is it a symptom of anything else?

this was the only item found

subsequent Spybot and avast scans found nothing

system has windows defender

vista 32 bit comodo firewall IE (former AOL) user

Link to post
Share on other sites

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

ani idea wht this is and why it would not be in quarentine?

is it a symptom of anything else?

If this is something you set yourself, just right click ignore in the future. Quarantining these is really resetting back to default value, no restriction. If you want to re-enable it, just set the policy key back. Which was disable ShowSearch from your start menu. If you didn't set it, then you probably wouldn't want to re-enable it. The long and short, we don't store the policy key settings; We detect some, and offer the user the choice to remove them or tell the software to ignore them in the future and not bother you with detecting them.

most antivirus programs that I know of do not alert on policy settings being enforced on the PC from which they run. It's a dilemma for us, as we have no way of knowing if the policy is something the administrator of the PC wants, or if some malware set the policies to make things more difficult for the administrator and/or users of the machine.

Link to post
Share on other sites

Thanks for the responses yardbird

Raid Jean Beck et all

First

I read Quarantined and removed as removed from the registry not removed from quarantine

why would MBAM quarantine something and then remove it- just remove it already

second kind of hard to reverse if not in quarantine

in this case I know nothing of this policy change

all instences I could find on google were mixed in with so many other problems that it was not possible to identify

Friends computer seems to be working fine without whatever this was

Link to post
Share on other sites

I will have to ask on this one but it could be that this is not a removal . All BAD:/GOOD: detections are a data swap , nothing is actually removed .

This is also not a file here , MBAM is reactivating the search button in the start menu , a common component disabled by malware .

MBAM cant tell if the user has done this intentionally so if you have , remove the search button again , run a scan and then tell MBAM to ignore this detection in the future .

Link to post
Share on other sites

Hm,

Here's one with a named filed and nothing ever showed up in quarantine.

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\Downloaded Program Files\uninst.bat (Trojan.Agent) -> Quarantined and deleted successfully.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.