Jump to content

Infected Registry Key or something else?


Recommended Posts

Hello,

I've been a long time user of MalwareBytes and it's saved me on numerous occasions. This time though after doing full scans, quick scans, etc. and coming up clean, this came up:

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_STISVC32 (Trojan.Tracur) -> Quarantined and deleted successfully.

I scan at startup, that registry key is found and the above action is taken. I reboot and it's gone. However when I shutdown and startup later it's back. The whole process ends up repeating.

I've been hunting down what it may be related to & so far the only thing close is W32/Agobot-TX worm. None of the exe.'s or startup issues related to that are on my system though.

Doing a search online for the exact key bring up another users log file oddly enough but little else, can't figure out if this may be a false positive or something deeper?

Everything else comes up clean, virus scans, etc.

Early in the weekend my system did get hit with something but my security software kicked in to prevent any real damage. The only issue was I did have to manually delete the malicious exe's AFTER the scans (easy enough to find since they all had the same DATE CREATED timestamp). Subsequent full system scans however have proved clean & no threats. (the log for this event is mbam-log-2011-06-18 (16-46-29)

mbam-log-2011-06-20 (13-02-38).txt

mbam-log-2011-06-18 (16-46-29).txt

Link to post
Share on other sites

Hello Zaire, and welcome to Malwarebytes.org

Sounds like you have something that keeps on recreating itself. Let's get an expert to take a look at that.

As we don't deal with malware removal in the General Malwarebytes' Anti-Malware Forum, you need to start a topic in the Malware Removal forum so a qualified helper can help you fix any malware related problems/infections you may have.

You can follow the directions below and someone will assist you with running scans on your system to see if they can detect anything.

Please print out, read and follow the Directions HERE, skipping any steps you are unable to complete. Then post a NEW topic here.

One of the expert helpers there will give you one-on-one assistance when one becomes available.

After posting your new post make sure under options that you select Track this topic and choose one of the Email options so that you're alerted when someone has replied to your post.

Alternatively, as a paying customer, you can contact the help desk at support@malwarebytes.org

Thank you very much.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.