Windows 10: Spybot picked up Malware in System32

Discus and support Spybot picked up Malware in System32 in AntiVirus, Firewalls and System Security to solve the problem; [img] This si what was picked-up from spybot. I'm hesitant to fix the selected items since is in system32. Should i go ahead with the clean up? 54112 Discussion in 'AntiVirus, Firewalls and System Security' started by jman1505, Jun 21, 2016.

  1. jman1505 Win User

    Spybot picked up Malware in System32


    Spybot picked up Malware in System32 [​IMG]

    This si what was picked-up from spybot. I'm hesitant to fix the selected items since is in system32.
    Should i go ahead with the clean up?

    :)
     
    jman1505, Jun 21, 2016
    #1

  2. Spybot Search and Destroy is picking up HKUS which is says is in Microsoft items

    Hi everyone

    I need some assistance... when I run the program "Spybot: Search and Destroy" it keeps picking up HKUS\S-1-5-21 where the location is set as a Microsoft item.

    Screenshot:


    Spybot picked up Malware in System32 [​IMG]


    For instance, the first "Internet Explorer" option includes Software\Microsoft\CurrentVersion\Internet Settings\User Agent (is not)

    When I click "Fix selected" it doesn't remove them; if I re-run Spybot they're still there.

    My question is - from searching the internet I've received conflicting results. In some cases HKUS is supposed to be a terrible virus or malware, but other results say that it's nothing to worry about and is erroneously being reported by Spybot. I know that
    Microsoft isn't Malware but it's possible that it's been infected.

    Can someone please advise what action I should take regarding this (if any)? I've run Windows Defender and it doesn't pick up anything, same with other anti-malware programs I have.
     
    JediMasterYoda, Jun 21, 2016
    #2
  3. Trogan Virus

    i have installed Spybot-Search and Destroy. does a very complete scan of your entire system. it is free, they will accept donations. Spybot will clean up any type of virus and prevent any more to access your system. The alternative malware removal would
    be Malwarebytes, which isn't quite as thorough as Spybot,
     
    dedra scarbeau, Jun 21, 2016
    #3
  4. Spybot picked up Malware in System32

    Hi:

    Is this the same computer?
    Solved Strange Registry Key- Possible spyware - Windows 10 Forums

    If so, it's probably advisable to stick with support in one thread in one place at a time.
    Malware removal can be tricky, picky and sticky.
    And it can be -- at best -- confusing or -- at worst -- dangerous to work simultaneously in multiple places.
    A step advised by one helper may be unknown to another helper and that can lead to problems.
    So, it might be a good idea to resume that existing thread.
    And no two computer disinfection tools/scanners will pick up the same, exact things.

    Having said all, that Spybot S&D is not one of the more highly-regarded anti-malware scanners these days.
    And, without a scan log or more data, it would be hard to say if this detection might or might not be a false positive.

    Just my thoughts,
    MM
     
    MoxieMomma, Jun 21, 2016
    #4
  5. simrick Win User
    You've already done a full scan with Malwarebytes, TDSSKiller, ADWCleaner and Avast - nothing found. Did you do the ESET Online Scanner as well? (you never mentioned that.) I see ESET found 1 thing, which you deleted.

    I agree with MM - Spybot should be uninstalled. If you want something, use SuperAntiSpyware Free.
     
    simrick, Jun 21, 2016
    #5
  6. Google search winemt.dat turns up a lot of results for Mountain and wine, but I didn't see winemt.dat

    Visit VirusTotal - Free Online Virus, Malware and URL Scanner, upload the file and have them check it.

    If it is a virus, yes remove it
    Then launch Command Prompt (Admin)
    enter the following commnad

    SFC /ScanNow

    that makes sure that system files from the component store are in the right place. It will put the correct file back if it is needed.
     
    Slartybart, Jun 21, 2016
    #6
  7. jman1505 Win User
    Sorry about that, i'm used to using new threads for new issues so that it helps others when searching for similar problems
     
    jman1505, Jun 21, 2016
    #7
  8. jman1505 Win User

    Spybot picked up Malware in System32

    VirusTotal found nothing suspicious

    Spybot picked up Malware in System32 [​IMG]

    Here's a picture of the file (The file is in a different place than what Spybot reported. Additionally, I had to "Show hidden files" in order to find this)


    Spybot picked up Malware in System32 [​IMG]

    I've scanned it with Avast and Malwarebytes and they found nothing either
    (If it helps, I don't use Norton. I have a hunch that the Norton symbol is there because of the Norton free trial that was pre-installed in my computer when i got it a few years back)

    SuperAntiSpyware only found tracking cookies

    Spybot picked up Malware in System32 [​IMG]
     
    jman1505, Jun 21, 2016
    #8
  9. simrick Win User
    Just looking at that screenshot of the file - in a different position than what Spybot says? That's odd. But, the fact that it has a Norton icon would lead me to believe it's possibly a leftover from Norton? It's all of 1 byte.
     
    simrick, Jun 22, 2016
    #9
  10. jman1505 Win User
    Yhea, i dunno what to do. I know that, they type of malware spybot picked up is very nasty, but none of the other programs picked it up, nor can i manually find it either.
    I'm at a loss of what to do
     
    jman1505, Jun 22, 2016
    #10
  11. simrick Win User
    Add the extension .old to it - renaming a file's extension makes it unusable. I doubt you'll find any issues. I think it's a leftover from Norton to be honest, and a FP from Spybot.
     
    simrick, Jun 22, 2016
    #11
  12. jman1505 Win User
    k thanks for the help
     
    jman1505, Jun 22, 2016
    #12
  13. simrick Win User

    Spybot picked up Malware in System32

    You're welcome. Give it a few days and if everything seems fine, you can delete it, and mark the thread as solved.
     
    simrick, Jun 22, 2016
    #13
  14. I want to amplify MoxiMomma's and simrick's impression of Spybot S&D as not being your best choice in Virus protection.

    Spybot uses the Hosts file (or it used to) to mitigate some malware. If you don't have any special needs for a non-standard Hosts file, then when you uninstall Spybot to replace it with a different AV product, you should also reset the hosts file

    # C:\Windows\System32\drivers\etc\hosts
    # Copyright (c) Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host
    #
    # localhost name resolution is handled within DNS itself.
    # 127.0.0.1 localhost
    # ::1 localhost
    See: How can I reset the Hosts file back to the default?
    Don't worry about the Windows versions - the Hosts file is standard. The only difference being the addition of IPv6 and letting the DNS handle the localhost name resolution.
    There are ample choices available that are superior, or at least less problematic for Windows, to Spybot.
    It comes down a preference really. I'm comfortable with Microsoft's Defender, but have used others in the past.

    AV products used by other members include:
    Avast Free,
    AVG Free,
    Malwarebytes Free (manual scan as a 2nd line of defense)
    --> Malwarebytes Premium is real time protection but is not free,
    Panda Free
    Super Anti-Spyware Free

    But there are more (some might not offer free real-time protection):
    Partners in consumer antivirus software for Windows - Microsoft Windows

    I've recently been looking at Bitdefender Free.
    Bitdefender is always in the top ranks along with Kaspersky (no free product that I know of).
    The free version of Bitdefender is 2014 - it's unclear that it is compatible with Win10. There is conflicting information on the Bitdefender 2016 page - probable just an oversight while they were updating the software.
    A buy Bitdefender 2016 pop-up has this:


    Spybot picked up Malware in System32 [​IMG]

    So, I have to ask myself ... what about 2014 - the free version? I have not tried it, so I can't answer my own question.
     
    Slartybart, Apr 5, 2018
    #14
Thema:

Spybot picked up Malware in System32

Loading...
  1. Spybot picked up Malware in System32 - Similar Threads - Spybot picked Malware

  2. Same malware Picked Up By Windows 11 Defender

    in Windows 10 Gaming
    Same malware Picked Up By Windows 11 Defender: The Same Malware/RAT Keeps popping up wth the file name "Backdoor:MSIL/AsyncRAT.N!MTB". And Is detected in the discords cache and files. It has only showed up when I downloaded a few files from discord for my visual studio project. Ive tried: -reinstalling discord-redoing my...
  3. Same malware Picked Up By Windows 11 Defender

    in Windows 10 Software and Apps
    Same malware Picked Up By Windows 11 Defender: The Same Malware/RAT Keeps popping up wth the file name "Backdoor:MSIL/AsyncRAT.N!MTB". And Is detected in the discords cache and files. It has only showed up when I downloaded a few files from discord for my visual studio project. Ive tried: -reinstalling discord-redoing my...
  4. SpyBot

    in AntiVirus, Firewalls and System Security
    SpyBot: Hello, On occasions I ran "SpyBot" program. The findings results are cookies and some registry entries - they all are Green color (Registry). How much reliable is it ? Normally I run once a day "CCleaner" Answers will be appreciated. Thanks 140521
  5. SpyBot

    in Windows 10 Support
    SpyBot: Hello, On occasions I ran "SpyBot" program. The findings results are cookies and some registry entries - they all are Green color (Registry). How much reliable is it ? Normally I run once a day "CCleaner" Answers will be appreciated. Thanks 140521
  6. SSD not being picked up by windows but picked up in bios

    in Windows 10 BSOD Crashes and Debugging
    SSD not being picked up by windows but picked up in bios: My OS is installed on my SSD so every time i try boot my PC it takes me to recovery, I cant use diskpart commands because it doesnt show any storage devices, but in BIOS i can choose to load from it. If I use a bootable USB with the installation stuff on it, it doesnt allow...
  7. Windows Defender not picking up win erx03 malware

    in AntiVirus, Firewalls and System Security
    Windows Defender not picking up win erx03 malware: Windows defender not stopping this pop up that is impossible to get out of except with c+alt+del. Quick scan doesn't find it, full scan does but will reinfect? Pop up warns that files will be deleted in a number of seconds that count down if don't press update. Any advice?...
  8. Possible Malware that Malwarebytes hasn't picked up?

    in AntiVirus, Firewalls and System Security
    Possible Malware that Malwarebytes hasn't picked up?: Hey, I recently installed a new SSD and did a clean install of Windows 10 onto it. I've had Windows Defender and Malwarebytes on the machine, and roughly used about 94/232 available GB on my drive. All of a sudden, I get a notification saying my SSD is full - which...
  9. Spybot

    in AntiVirus, Firewalls and System Security
    Spybot: Spybot will shortly be bringing out Spybot 2.5 for win 10, but 2.4 works fine anyway. If, like me, you have some passwords saved, spybot will remove them BUT, there is a solution: - Open Spybot by right clicking on the Spybot icon and choosing "Run as administrator". -...
  10. Spybot

    in AntiVirus, Firewalls and System Security
    Spybot: I just ran Spybot, but I had not done it for a couple of weeks. It found loads of spyware all labelled within Firefox folders. These must have crept in on a recent update. Very naughty Firefox. I cleaned them out and spybot reminded me I had not run immunization. So I did,...