Jump to content

MBAM can't remove this threat - nothing else finds it

Recommended Posts

I've 5 machines that continue to come up with the following threats: (there are a between 50 and 150 per machine, only showing a few because they are basically all the same name and folder path only differing on username)

c:\documents and settings\skiziroglou\application data\microsoft windows products updater\iexplore.exe (Trojan.Agent) -> Delete on reboot.

c:\documents and settings\smuhammad\application data\microsoft windows products updater\iexplore.exe (Trojan.Agent) -> Delete on reboot.

c:\documents and settings\swright\application data\microsoft windows products updater\iexplore.exe (Trojan.Agent) -> Delete on reboot.

c:\documents and settings\ttodd\application data\microsoft windows products updater\iexplore.exe (Trojan.Agent) -> Delete on reboot.

c:\windows\system32\config\systemprofile\application data\microsoft windows products updater\iexplore.exe (Trojan.Agent) -> Delete on reboot.

c:\windows\system32\windupdt\firefox.exe (Backdoor.Agent.DC) -> Delete on reboot.

c:\documents and settings\acetech\application data\help\iexplore.exe (Trojan.Agent) -> Delete on reboot.

c:\documents and settings\administrator.w4w\application data\help\iexplore.exe (Trojan.Agent) -> Delete on reboot.

c:\documents and settings\administrator\application data\help\iexplore.exe (Trojan.Agent) -> Delete on reboot.

c:\program files\javascript\iexplore.exe (Backdoor.Agent) -> Delete on reboot.

c:\program files\system23\iexplore.exe (Backdoor.Bot) -> Delete on reboot.

c:\program files\temp\firefox.exe (Backdoor.Bifrose) -> Delete on reboot.

c:\program files\windows\firefox.exe (Backdoor.Bifrose) -> Delete on reboot.

c:\windows\system32\webb\iexplore.exe (Backdoor.SpyNet) -> Delete on reboot.

c:\documents and settings\all users\local settings\iexplore.exe (Trojan.Dropper) -> Delete on reboot.

c:\windows\internetexplorer\iexplore.exe (Backdoor.Agent) -> Delete on reboot.

c:\windows\sxs1\iexplore.exe (Trojan.Agent) -> Delete on reboot.

c:\system32\firefox.exe (Misused.Legit) -> Delete on reboot.

c:\windows\system32\iexplore.exe\iexplore.exe (Trojan.Backdoor) -> Delete on reboot.

c:\windows\temp\history\firefox.exe (Trojan.Downloader) -> Delete on reboot.

c:\usernk\user\pps\firefox.exe (Backdoor.Agent) -> Delete on reboot.

MBAM finds them each time, but after rebooting they reappear. The users have roaming profiles and I've scanned at the server and they don't show there. I've also scanned with OTS, Kaspersky (installed AV), rKill, ComboFix, ESET OnLine scanner, PrevX, And Kaspersky tools - TDSSKiller, SalityKiller, VirutKiller, KidoKiller, and KatesKiller. MBAM is the ONLY one that even finds these detections.

The really weird thing is that in all the cases of the (Trojan.Agent) folder path - it doesn't exist! The path is non-existent, at least as far as I can tell. So are these systems infected or is this a false positive from MBAM?

Any help is appreciated. I'm about ready to completely wipe and re-install them.

Link to post
Share on other sites

Hello and welcome to Malwarebytes

Since you are infected, here are the steps needed to get your computer cleaned....

Please read the following so that you can begin the cleaning process:

Don't use any temporary file cleaners unless requested - this can cause data loss and make recovery difficult

You have 3 Options that you can choose from as listed below:

  • Option 1 —— Free Expert advice in the Malware Removal Forum
  • Option 2 —— Paying customer -- Contact Support via email
  • Option 3 —— Premium, Fee-Based Support


As we don't deal with malware removal in the
General Malwarebytes' Anti-Malware Forum
, you need to start a topic in the

Malware Removal forum
so a qualified helper can help you fix any malware related problems/infections you may have.

  • Please read and follow the
    , skipping any steps you are unable to complete.

  • After posting your new post, make sure under
    , you select
    Track this topic
    and choose
    Immediate Email Notification

    so that you're alerted when someone has replied to your post.

Please do not post back to (bump) your topic within the first 48 hours.

Replying to your own posts changes the post count and helpers are looking for topics with zero replies.

If you reply to your own post helpers may think that you're already being helped and thus overlook your post.

    • If there is no reply from any experts after 48 hours, you can reply to the topic, asking for help again.


    • You may send a Private Message to a Moderator asking for assistance.


Alternatively, as a paying customer, you can contact the help desk at


If you would like to use our
Malwarebytes Premium Services
, Comprehensive solutions to all your computer support needs—from installation and set-up to troubleshooting and tune-ups go to our
support site.

Please be patient, someone will assist you as soon as possible.

PS: Please use the "Add Reply" Add-Reply.png button not the Reply button when you start replying.

Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.