Jump to content

Malwarebytes

Leftover Settings From Detected Threat - 2nd Attempt



1 reply to this topic

#1
davidford365

    New Member

  • Members
  • Pip
  • 3 posts
Hi,


I have recently been infected by two rogue web add-ons, Babylon search and General Crawler. I have cleaned most of these off the system however there are still some elements left over. I have exported parts of the registry that will interest you (Current Control Set and Internet Explorer settings for Network Service) as well as my NETSTAT log and the two recent scans that I performed on my system.


There are 8 extra services that start using SVCHOST -k netsvcs and these appear to be random names that are generated. On my system they are:


ATIBTCAP

Mvserver

Nmea

Pimsgss

RTL8169

Szserver

Tga

Wm


I have removed these manually from my system and all is OK now, but am making you aware so these can be removed automatically in the future.


Regards


David Ford

Attached Files



#2
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 18,856 posts
  • Gender:Male
  • Location:127.0.0.1
Many thanks davidford365,

I will take a look at the data shortly :)
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us