Jump to content

Malwarebytes

hijack.controlpanelstyle


4 replies to this topic

#1
paranoidsoul

    New Member

  • Members
  • Pip
  • 11 posts
What I want to know is if this is a false positive or if not how severe is it? I have it in quarantine but is it safe for me to delete it?

Here's my log file on the issue:

Malwarebytes' Anti-Malware 1.40
Database version: 2723
Windows 5.1.2600 Service Pack 3

8/31/2009 4:55:29 PM
mbam-log-2009-08-31 (16-55-29).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 109457
Time elapsed: 16 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#2
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
That is a policy that determines if you use the newer XP style Control Panel view or the Classic View.

Removing or setting the policy to 0 should be okay. Then you can select yourself what or how you want it to be viewed instead of being forced by a policy.

You can read more about it here: http://www.insidetheregistry.com/regdataba...spx?valueid=228
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#3
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
This typically shows up with infections that force the version of the CP that is more difficult to navigate in an attempt to make certain OS functions that could remove the malware harder to access .

This can also be intentionally set to lock that same version of the CP in place if that is what the user desires .

There are no other detections in your log so it is highly unlikely that there is any actual malware in your system .

Aside from being able to change your CP from one style to another you will not notice any changes to your system if you allow MBAM to fix this .

View Postparanoidsoul, on Aug 31 2009, 07:32 PM, said:

What I want to know is if this is a false positive or if not how severe is it? I have it in quarantine but is it safe for me to delete it?

Here's my log file on the issue:

Malwarebytes' Anti-Malware 1.40
Database version: 2723
Windows 5.1.2600 Service Pack 3

8/31/2009 4:55:29 PM
mbam-log-2009-08-31 (16-55-29).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 109457
Time elapsed: 16 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#4
paranoidsoul

    New Member

  • Members
  • Pip
  • 11 posts
thanks for clearing this up

well it makes sense as i recall last week i did have a friend change the windows theme to classic mode

#5
Bobc8

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 212 posts
  • Gender:Male
  • Location:United States
  • Interests:Computers and LEGOS! Even though I am older I still LOVE LEGOS!!!
My brother has it and I hate it.
I am happy!

Dell latitude c840
1 gb ram
1.6 ghz ram
Google chrome
WIndows xp home
Symantec antivirus corporate edition 10





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us