Cloud13 Posted October 23, 2008 ID:32027 Share Posted October 23, 2008 I'm making sure the computer at our business is secure, so I ran a scan with Avast, which we already had on it, then I decided to dl MBAM to make sure it was clean. It came up with 3 results. I quarantined and deleted them, but then when I was looking to see wat they were about, it seemed like they could be false positives, so I came here to make sure it's safe to restore them.Malwarebytes' Anti-Malware 1.30Database version: 1310Windows 6.0.6001 Service Pack 110/23/2008 12:45:19 PMmbam-log-2008-10-23 (12-45-19).txtScan type: Quick ScanObjects scanned: 55851Time elapsed: 8 minute(s), 44 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 3Registry Values Infected: 0Registry Data Items Infected: 0Folders Infected: 0Files Infected: 0Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{cc721bba-7958-4b7e-8f88-81bc0b6dfa73} (Rogue.Installer) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{343ce214-9998-4b21-a151-ffe970167297} (Rogue.Installer) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.Registry Values Infected:(No malicious items detected)Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:(No malicious items detected) Link to post Share on other sites More sharing options...
Cloud13 Posted October 23, 2008 Author ID:32029 Share Posted October 23, 2008 I couldn't see any edit button... *tear*After posting this I saw the "Before Posting" topic, lol!If it's likely that these are false positives, I'll redo the scan in developer mode, but I won't if you're are certain these are legit results. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted October 23, 2008 Root Admin ID:32033 Share Posted October 23, 2008 They are not FP according to a Google search. They all come up as a fake installer malware entry. Link to post Share on other sites More sharing options...
mona7865 Posted October 23, 2008 ID:32039 Share Posted October 23, 2008 I too have two infections, after updating to database version 1310, both located in KEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats :Malwarebytes' Anti-Malware 1.30Database version: 1310Windows 5.1.2600 Service Pack 323/10/2008 20:29:42mbam-log-2008-10-23 (20-29-37).txtScan type: Quick ScanObjects scanned: 59848Time elapsed: 4 minute(s), 9 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 2Registry Values Infected: 0Registry Data Items Infected: 0Folders Infected: 0Files Infected: 0Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{37b85a21-692b-4205-9cad-2626e4993404} (Adware.MyWebSearch) -> No action taken. [405442373034698866837015469056706752706683687313019220246725226619181423261967142119172214266866691419231923702126262021172194]HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{37b85a2b-692b-4205-9cad-2626e4993404} (Adware.MyWebSearch) -> No action taken. [405442373034698866837015469056706752706683687313019220246725226619671423261967142119172214266866691419231923702126262021172194]Registry Values Infected:(No malicious items detected)Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:(No malicious items detected)I would appreciate it very much if someone would look into this and advise me on whether these are FP's or real infections.Heartfelt thanks. Link to post Share on other sites More sharing options...
Raid Posted October 23, 2008 ID:32040 Share Posted October 23, 2008 They are real... registry entries. We are cleaning up some of the trash left behind is all. Link to post Share on other sites More sharing options...
Cloud13 Posted October 23, 2008 Author ID:32042 Share Posted October 23, 2008 So they're harmless, but unnecessary? Link to post Share on other sites More sharing options...
Staff nosirrah Posted October 23, 2008 Staff ID:32043 Share Posted October 23, 2008 I expanded where MBAM looks for malware GUIDs today , these are old traces of long dead malware .long and short , neither malware nor anything to worry about Link to post Share on other sites More sharing options...
Cloud13 Posted October 23, 2008 Author ID:32049 Share Posted October 23, 2008 All righty.*thumb up* Link to post Share on other sites More sharing options...
mona7865 Posted October 23, 2008 ID:32052 Share Posted October 23, 2008 You have set my mind at rest, thanks. Link to post Share on other sites More sharing options...
melboy Posted October 23, 2008 ID:32058 Share Posted October 23, 2008 I got this. (I had problems with drive cleaner some time ago before i got clued up! )Registry Keys Infected:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully.It's nice to see the back of the last remnants of it, thanks Bruce! Link to post Share on other sites More sharing options...
JeanInMontana Posted October 24, 2008 ID:32188 Share Posted October 24, 2008 My Web Search is malware. Just for the record. Wouldn't it be best to just fix them? Link to post Share on other sites More sharing options...
mona7865 Posted October 25, 2008 ID:32221 Share Posted October 25, 2008 My Web Search is malware. Just for the record. Wouldn't it be best to just fix them?After posting the scan, run in developer mode, and Nosirrah's answer, I reran a quick scan and both infections are deleted now. Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now