Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Question about Malwarebytes and the registry

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU
 
ohheckyeah Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-04-09 10:33 PM
Original message
Question about Malwarebytes and the registry
Edited on Tue Aug-04-09 10:40 PM by ohheckyeah
I use Malwarebytes to scan for malware, etc. and it has come up with the result that in the registry is a disabled security entry in HKEY_LOCAL_MACHINE.
It is something from Microsoft.

The question is do I dare let the software delete that in the registry. A computer tech who works where my sister does and uses Malwarebytes says he trusts it.

What say you?

thanks for any help.
Refresh | 0 Recommendations Printer Friendly | Permalink | Reply | Top
Duer 157099 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-04-09 11:09 PM
Response to Original message
1. Personally I have plenty of "disabled security entries" from Microsoft in my registry
Like Auto Updates, Windows Firewall, etc.

And whenever Malwarebytes scans, it alerts me to that and I put it in my "ignore" list so it doesn't keep telling me.

The thing is, if you *do* have those things enabled (or think you do) but your registry shows it disabled, then it *might* be an issue.

What is the specific key?
Printer Friendly | Permalink | Reply | Top
 
ohheckyeah Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-05-09 12:02 AM
Response to Reply #1
3. Here it is:
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/SecurityCenter|Bad:(1)Good:0

There are two entries that are identical.
Printer Friendly | Permalink | Reply | Top
 
Why Syzygy Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-04-09 11:18 PM
Response to Original message
2. Hey .. I'm just about to sign off for tonight.
And don't have a lot of time to research more than this ... Malwarebytes may not "delete" it, but rather just change the settings. It would be helpful to see the log entry for that item. Is it in the Security Center? It is also necessary to make sure you have updated to the latest definitions before any scan (update).

This is the Malwarebytes forum discussing *a* security setting:
http://www.malwarebytes.org/forums/index.php?showtopic=12624

If it were me, I would back up the registry and create a new restore point and just let MBAM do its thing. Everything I've read suggested it can be trusted explicitly. It has never found much on my system, after the initial first run, but I'm pretty sure MBAM should have a reversal feature should you decide it did the wrong thing.
Printer Friendly | Permalink | Reply | Top
 
ohheckyeah Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-05-09 12:05 AM
Response to Reply #2
4. Thanks
Here's the log:

Malwarebytes' Anti-Malware 1.39
Database version: 2502
Windows 5.1.2600 Service Pack 3

7/26/2009 12:37:15 AM
mbam-log-2009-07-26 (00-37-15).txt

Scan type: Quick Scan
Objects scanned: 92135
Time elapsed: 7 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Printer Friendly | Permalink | Reply | Top
 
ohheckyeah Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-05-09 12:10 AM
Response to Reply #4
5. I re-set those notifies in the Security Center.
Edited on Wed Aug-05-09 12:13 AM by ohheckyeah
Thanks for the link. It explained those two keys have to do with the notification settings and two were disabled. I reset them to enable. If they don't cause any conflicts I will leave them enabled.

Thanks to you both for the quick response.
Printer Friendly | Permalink | Reply | Top
 
canetoad Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-05-09 01:54 AM
Response to Reply #5
6. I have the MS security centre
disabled in Services and always get a message from Spybot or Malwarebytes. I just untick and go on my merry way.
Printer Friendly | Permalink | Reply | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-05-09 04:28 AM
Response to Reply #6
7. That's what I do too.
Printer Friendly | Permalink | Reply | Top
 
Why Syzygy Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-05-09 07:00 AM
Response to Reply #5
8. Well, but
one of them may have turned on automatic updates. Check the Security Center settings in Control Panel to make sure they are set as you intend. Most if not all of us who offer advice, recommend NO to automatic updates.
Printer Friendly | Permalink | Reply | Top
 
ohheckyeah Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Aug-05-09 06:10 PM
Response to Reply #8
9. Thanks. I decided to
turn them back off. It seemed to me that having them on slowed down my computer. I'll just tell Malwarebytes to ignore in the future.

I appreciate the help!
Printer Friendly | Permalink | Reply | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed Apr 24th 2024, 08:12 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC