Jump to content

Malwarebytes

Rogue.WinAntiVirus and Adware.TryMedia


2 replies to this topic

#1
calonso

    New Member

  • Members
  • Pip
  • 5 posts
Hi, I've installed MalwareBytes ANti-Malware in my PC and it had detected four problems:
Rogue.WinAntiVirus , Adware.TryMedia and two Disabled.SecurityCenter.
I've also disabled the System Restore. When I open Internet Explorer it takes some seconds before showing the homepage.

Here's the MBAM log:

Malwarebytes' Anti-Malware 1.41
Versión de la Base de Datos: 3034
Windows 5.1.2600 Service Pack 2

26/10/2009 10:41:30
mbam-log-2009-10-26 (10-40-58).txt

Tipo de examen : Examen Rápido
Objetos examinados: 123784
Tiempo transcurrido: 12 minute(s), 8 second(s)

Procesos en Memoria Infectados: 0
Módulos en Memoria Infectados: 0
Claves del Registro Infectadas: 2
Valores del Registro Infectados: 0
Elementos de Datos del Registro Infectados: 2
Carpetas Infectadas: 0
Ficheros Infectados: 0

Procesos en Memoria Infectados:
(No se han detectado elementos maliciosos)

Módulos en Memoria Infectados:
(No se han detectado elementos maliciosos)

Claves del Registro Infectadas:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> No action taken.

Valores del Registro Infectados:
(No se han detectado elementos maliciosos)

Elementos de Datos del Registro Infectados:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Carpetas Infectadas:
(No se han detectado elementos maliciosos)

Ficheros Infectados:
(No se han detectado elementos maliciosos)

#2
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA

Quote

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> No action taken.

These are both traces of malware that was likely removed a long time ago .

Quote

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Some antivirus software will disable both of these because they have their own monitoring , in these cases you can have Malwarebytes ignore them .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
calonso

    New Member

  • Members
  • Pip
  • 5 posts

View Postnosirrah, on Oct 26 2009, 02:09 PM, said:

These are both traces of malware that was likely removed a long time ago .



Some antivirus software will disable both of these because they have their own monitoring , in these cases you can have Malwarebytes ignore them .

Thanks Nosirrah, so I can delete the entries without worries?





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us