Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Locked registry keys


  • Please log in to reply
1 reply to this topic

#1 PCMan55

PCMan55

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:39 PM

Posted 11 September 2014 - 10:17 AM

Greetings everyone.

 

I am not exactly a computer expert, and I recently had a trojan which was listed as "Win32/Small" by Microsoft Security Essentials.

 

After removing it I ran Combofix, and the log looks really weird.

 

There are many locked registry keys.

 

The majority of them are from Acdsee (quite a few), for example this one:

 

[HKEY_USERS\S-1-5-21-1942616502-260430014-267345241-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 3.xmp"

 

Then there is one that I have never seen before:

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)

 

Should I be worried, or is this normal?

 

Any input would be much appreciated.

 

PS. Just realised I posted this in the wrong section. Sorry about that. :blush: DS.


Edited by PCMan55, 11 September 2014 - 10:25 AM.


BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  • Moderator
  • 55,545 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:04:39 AM

Posted 11 September 2014 - 10:26 AM

Please...follow Steps 6-8 of Preparation Guide, Before Using Malware Removal Tools and Requesting Help - http://www.bleepingcomputer.com/forums/topic34773.html and paste the requested DDS log, along with your ComboFix log, into the body of your post/topic.

 

Once that is done, this topic will be closed and the personnel handling your new topic will assist you.

 

Thanks :).

 

Louis






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users