Jump to content

Malwarebytes

should i remove these probably FP please?


5 replies to this topic

#1
deejay2

    New Member

  • Members
  • Pip
  • 6 posts
hi
i just scanned my system.
can someone tell me if i should remove these or not please?
especially logon.exe seems to me like stability issue of winxp...

Malwarebytes' Anti-Malware 1.41
Database version: 3183
Windows 5.1.2600 Service Pack 2

Files Infected:
C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll (Virus.Mariofev) -> No action taken.
C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll (Virus.Mariofev) -> No action taken.
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\6d23b8f719dc5412ac7aeb7db3387c36\backup\sp2gdr\user32.dll (Virus.Mariofev) -> No action taken.
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\6d23b8f719dc5412ac7aeb7db3387c36\backup\sp2qfe\user32.dll (Virus.Mariofev) -> No action taken.
C:\WINDOWS\system32\logon.exe (Worm.Emold) -> No action taken.
C:\WINDOWS\system32\dllcache\user32.dll (Virus.Mariofev) -> No action taken.
C:\WINDOWS\$NtUninstallKB890859$\user32.dll (Virus.Mariofev) -> No action taken.
C:\Documents and Settings\All Users\Desktop\AntiMalware.lnk (Rogue.AntiMalware) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe logon.exe) Good: (Explorer.exe) -> No action taken.



thanks for help guys, only malwarebytes found these, other programs not.

#2
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
Update and scan again , there is a FP in there that has already been fixed .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
deejay2

    New Member

  • Members
  • Pip
  • 6 posts

View Postnosirrah, on Nov 17 2009, 06:46 PM, said:

Update and scan again , there is a FP in there that has already been fixed .

thanks...will do and let you know.....please keep me informed...thanks

#4
marktreg

    Elite Member

  • Trusted Advisors
  • PipPipPipPipPip
  • 834 posts
I would not remove all these entries yet. There may be some false positives in there. Update Malwarebytes to the latest database. It should be database version 3188 or higher. Then run another scan and see what it finds.

EDIT: Oops, nosirrah beat me to it. Sorry about that. :)

#5
deejay2

    New Member

  • Members
  • Pip
  • 6 posts

View Postnosirrah, on Nov 17 2009, 06:46 PM, said:

Update and scan again , there is a FP in there that has already been fixed .


so i have updated and there is this left for FP:

Malwarebytes' Anti-Malware 1.41
Database version: 3188
Windows 5.1.2600 Service Pack 2


Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe logon.exe) Good: (Explorer.exe) -> No action taken.


Files Infected:
C:\WINDOWS\system32\logon.exe (Worm.Emold) -> No action taken.
C:\Documents and Settings\All Users\Desktop\AntiMalware.lnk (Rogue.AntiMalware) -> No action taken.


so should i still wait for fixing?
seems to be that worm.emold logon.exe is still there......

thanks guys

#6
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
What is there needs to be removed .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us