short mbam-log please help

xFenGz

Member
i did a scan with malwarebyte anti malware and got these. is it okay to remove?
thanks!


log---

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
C:\Windows\svchost.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\powermanager (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\powermanager (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\powermanager (Trojan.Agent) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\svchost.exe (Trojan.Agent) -> No action taken.
 
may i ask what it does?

i removed it.. restarted the computer and scanned them again.. the same 5 things come up.
 
Try scanning with another scanner such superantispyware. I have a feeling those are false postives. You can get it here. Click where it says download free version home users. Let us know what it finds.
 
A lot more finds.


Trojan.SVCHost/Fake
C:\WINDOWS\SVCHOST.EXE
C:\WINDOWS\SVCHOST.EXE
C:\Windows\Prefetch\SVCHOST.EXE-5857FD59.pf
C:\Windows\Prefetch\SVCHOST.EXE-5BD37FE0.pf

Virus.HiddenDragon
HKLM\SYSTEM\CurrentControlSet\Services\PowerManager
HKLM\SYSTEM\CurrentControlSet\Services\PowerManager#Type
HKLM\SYSTEM\CurrentControlSet\Services\PowerManager#Start
HKLM\SYSTEM\CurrentControlSet\Services\PowerManager#ErrorControl
HKLM\SYSTEM\CurrentControlSet\Services\PowerManager#ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\PowerManager#DisplayName
HKLM\SYSTEM\CurrentControlSet\Services\PowerManager#WOW64
HKLM\SYSTEM\CurrentControlSet\Services\PowerManager#ObjectName
HKLM\SYSTEM\CurrentControlSet\Services\PowerManager#Description

Trojan.Dropper/Gen
C:\USERS\KEVIN\APPDATA\LOCAL\TEMP\AACDEC2.EXE
 
Back
Top