Author Topic: rootkit HKU\S-1-5-21  (Read 2227 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
rootkit HKU\S-1-5-21
« on: May 04, 2017, 03:43:55 PM »
I have a recurring problem.  Found a few glitches in my computer so I ran Malwarebytes and identified 2 threats:  HKU\S-1-5-21-2645729826-27...66-2386374640-1000_Classes, both with the same number.  I removed the threats to quarantine, then deleted them.  A couple hours later the exact same threat is back.   I have removed 4 time so far and it returns every time.   Can anyone help with this???   

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: rootkit HKU\S-1-5-21
« Reply #1 on: May 04, 2017, 03:52:34 PM »
Since this is detected by Malwarebytes i suggest Malwarebytes forum

Malware Removal for Mac  >>  https://forums.malwarebytes.com/forum/165-malware-removal-for-mac/


REDACTED

  • Guest
Re: rootkit HKU\S-1-5-21
« Reply #2 on: May 04, 2017, 04:04:41 PM »
Malwarebytes doesn't seem to be working.  Can anyone assist with how to tackle this problem

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: rootkit HKU\S-1-5-21
« Reply #3 on: May 04, 2017, 04:06:54 PM »
The malwarebytes webboard is working.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: rootkit HKU\S-1-5-21
« Reply #4 on: May 04, 2017, 05:43:29 PM »
I think he means the program... (Which isn't a good thing really...)

Have you tried launching MBAM as Chameleon mode?

https://www.malwarebytes.com/chameleon/
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: rootkit HKU\S-1-5-21
« Reply #5 on: May 04, 2017, 06:06:14 PM »
I think he means the program... (Which isn't a good thing really...)

Have you tried launching MBAM as Chameleon mode?

https://www.malwarebytes.com/chameleon/
He has posted in MBAM forum   ;)