Author Topic: registry problem  (Read 9885 times)

0 Members and 1 Guest are viewing this topic.

Offline krypton

  • Poster
  • *
  • Posts: 426
registry problem
« on: August 26, 2010, 07:06:22 AM »
hello

i buy new laptop with windows xp and i scan for viruses and i not get any virus in scanning. i scan with mbam and i got 3 infeced files.

wat i do. see this mbam file.  thnks
LAPTOP: LENOVO G50, 4 GB RAM, 500 GB HARD DISK, AVAST PREMIUM SECURITY 2020, WINDOWS 8.1

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: registry problem
« Reply #1 on: August 26, 2010, 07:27:46 AM »
it is only registry trace. update MBAM scan again and click remove selected button to quarantine

Offline krypton

  • Poster
  • *
  • Posts: 426
Re: registry problem
« Reply #2 on: August 26, 2010, 07:36:37 AM »
i tried to remove it but it goes in quarantine. and then i thought if i remove any file from registry then may be my pc will give error anytime in future. so i again restore them all.


can u tell me if i delete those registry infected files then is this ok?
LAPTOP: LENOVO G50, 4 GB RAM, 500 GB HARD DISK, AVAST PREMIUM SECURITY 2020, WINDOWS 8.1

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: registry problem
« Reply #3 on: August 26, 2010, 08:01:47 AM »
it will be okey to let malwarebytes remove them because it first makes a back up on the file in its quarantine and then remove it. if it should turn out to be an false threat you can easily restore the file from the quarantine option in malwarebytes antimalware.
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

SafeSurf

  • Guest
Re: registry problem
« Reply #4 on: August 26, 2010, 09:25:59 AM »
krypton,

The MBAM scan you just did was only a Quick Scan.  Ironically, it looks very similar to the one you had on 8/22/2010, which was a full scan and had the same problems but also identified a Trojan as well in this previous thread: http://forum.avast.com/index.php?topic=63076.15.  Is this a new machine or the same machine?  If you bought a new machine, why did it only come with XP SP2 instead of XP SP3?

I also suggest you update MBAM and run a FULL scan.  Thank you.

Offline krypton

  • Poster
  • *
  • Posts: 426
Re: registry problem
« Reply #5 on: August 26, 2010, 12:02:16 PM »
krypton,

The MBAM scan you just did was only a Quick Scan.  Ironically, it looks very similar to the one you had on 8/22/2010, which was a full scan and had the same problems but also identified a Trojan as well in this previous thread: http://forum.avast.com/index.php?topic=63076.15.  Is this a new machine or the same machine?  If you bought a new machine, why did it only come with XP SP2 instead of XP SP3?

I also suggest you update MBAM and run a FULL scan.  Thank you.

hey there

yes i bought new laptop. i have desktop also as my last topic i said.

i updated mbam today and then i scan. then also infected registry shown.i done full scan. see file plz.wat i do. can i move them in qurantine? and then i delete those files from quarantine. is those infected files are important or can make problem in future if i delete them from qurantine?
LAPTOP: LENOVO G50, 4 GB RAM, 500 GB HARD DISK, AVAST PREMIUM SECURITY 2020, WINDOWS 8.1

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: registry problem
« Reply #6 on: August 26, 2010, 12:18:36 PM »
you move them to quarantine and let them stay there for 30 days, if the machine works okay then you can delete form quarantine
that is why you should never delete, always move to quarantine first

Clean, Quarantine, or Delete?
http://antivirus.about.com/b/2007/03/11/clean-quarantine-or-delete.htm

Offline krypton

  • Poster
  • *
  • Posts: 426
Re: registry problem
« Reply #7 on: August 26, 2010, 12:30:14 PM »
if i move them into quarantine. then also it performs its work or it get useless?


if mbam shows false postive and if i move important file which is important for my pc to get work then how my pc will work if i move those files in qurantine?
LAPTOP: LENOVO G50, 4 GB RAM, 500 GB HARD DISK, AVAST PREMIUM SECURITY 2020, WINDOWS 8.1

Offline superhacker

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 979
  • superhacker != super mario
Re: registry problem
« Reply #8 on: August 26, 2010, 02:27:47 PM »
Pondus,SafeSurf,mikaelrask,and krypton:
May be no one of you read the log"sorry to say that"the infected items are just bad policies to disable security center and mbam will not remove any thing it will set new clean values(0=>1,1=>0) ;)
Dreams don't die, they just fall asleep.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: registry problem
« Reply #9 on: August 26, 2010, 04:46:16 PM »
@ krypton
These all relate to the Windows Security Center (WSC), have you made any changes in there relating to not notifying you about Windows Updates, Firewall and Antivirus not being enabled/running, etc. ?

These settings should by default be set to notify you if any of them are not running/enabled.

If they set 'not to notify you' as these are it could be a pre-emptive measure for malware to try and disable your security so that the WSC doesn't warn you they aren't running/enabled.

As has been said in this case they aren't deleted or moved to quarantine but the values are set their default setting so you are warned if any of the three are nor running/enabled.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline superhacker

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 979
  • superhacker != super mario
Re: registry problem
« Reply #10 on: August 26, 2010, 05:22:00 PM »
@ krypton
These all relate to the Windows Security Center (WSC), have you made any changes in there relating to not notifying you about Windows Updates, Firewall and Antivirus not being enabled/running, etc. ?

These settings should by default be set to notify you if any of them are not running/enabled.

If they set 'not to notify you' as these are it could be a pre-emptive measure for malware to try and disable your security so that the WSC doesn't warn you they aren't running/enabled.

As has been said in this case they aren't deleted or moved to quarantine but the values are set their default setting so you are warned if any of the three are nor running/enabled.
Sorry DavidR to say that but after re-install windows xp mbam always detect those "infected" values so  krypton dont do anything that is mbam and default system setting"BUT even before mbam detect those security center is fully working,may be something wrong ::) ???"
Dreams don't die, they just fall asleep.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: registry problem
« Reply #11 on: August 26, 2010, 05:27:03 PM »
Some firewalls and AV's set those keys automatically - notably Norton - Did your re-install have a trial version AV on it ?

Offline superhacker

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 979
  • superhacker != super mario
Re: registry problem
« Reply #12 on: August 26, 2010, 05:32:34 PM »
Hi essexboy even The Fresh Copy of win xp will lead mbam to detect those registry values and note that security center is fully working  ???,"I test it my self"
Dreams don't die, they just fall asleep.

Offline krypton

  • Poster
  • *
  • Posts: 426
Re: registry problem
« Reply #13 on: August 26, 2010, 05:51:43 PM »
@ krypton
These all relate to the Windows Security Center (WSC), have you made any changes in there relating to not notifying you about Windows Updates, Firewall and Antivirus not being enabled/running, etc. ?

These settings should by default be set to notify you if any of them are not running/enabled.

If they set 'not to notify you' as these are it could be a pre-emptive measure for malware to try and disable your security so that the WSC doesn't warn you they aren't running/enabled.

As has been said in this case they aren't deleted or moved to quarantine but the values are set their default setting so you are warned if any of the three are nor running/enabled.


i got msg to put automatic update for my windows. 

my firewall in already on

my antivirus also updated.
LAPTOP: LENOVO G50, 4 GB RAM, 500 GB HARD DISK, AVAST PREMIUM SECURITY 2020, WINDOWS 8.1

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: registry problem
« Reply #14 on: August 26, 2010, 06:25:30 PM »
<snip>
Sorry DavidR to say that but after re-install windows xp mbam always detect those "infected" values so  krypton dont do anything that is mbam and default system setting"BUT even before mbam detect those security center is fully working,may be something wrong ::) ???"

Well I don't know how that can be as the default setting is for WSC to 'notify' rather than disable the notifications.

I don't reinstall my system on a regular basis, and it is around 18 months or so since I got this system with winXP Pro SP3 installed and no changes to the defaults and at that time I will have also installed avast, SAS Pro and MBAM free, yet I never had any alerts from any of them on what was a clean install of XP Pro.

So since then something has changed in MBAM (as I don't think it has in XP) that is mis-identifying this, but even so I can't recall ever having MBAM flag these on this system.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security