PUA.malwareBot what is it?

my norton finds this  and says it removes it  atleast 4 times a day. i have viewed my history and went to the  symantec malware bot removal page that  said how to  remove   but i cant find any  of what is listed (list below) any idea what to do now?   and i have also ran super anti  spyware and ccleanr on my registry   thanks for any help


 

 

 

  1. Navigate to and delete the following registry subkeys:

    • HKEY_CURRENT_USER\Software\MalwareBot
    • HKEY_CLASSES_ROOT\CLSID\{C5D60FD5-9CCB-403c-9ED7-A5E1676C38CE}
    • HKEY_CLASSES_ROOT\Installer\Features\42FDF858096D3024DB1A97FFAAB0D6B3
    • HKEY_CLASSES_ROOT\Installer\Products\42FDF858096D3024DB1A97FFAAB0D6B3
    • HKEY_CLASSES_ROOT\Installer\UpgradeCodes\8BF9CD9F316AF4348A9E5930114224AF
    • HKEY_LOCAL_MACHINE\SOFTWARE\MalwareBot
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DisabledRun
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DisabledUninstall
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{C5D60FD5-9CCB-403c-9ED7-A5E1676C38CE}
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DisabledBHO
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{858FDF24-D690-4203-BDA1-79FFAA0B6D3B}
  2. Exit the Registry Editor

festis12 wrote:

my norton finds this  and says it removes it  atleast 4 times a day. i have viewed my history and went to the  symantec malware bot removal page that  said how to  remove   but i cant find any  of what is listed (list below) any idea what to do now?   and i have also ran super anti  spyware and ccleanr on my registry   thanks for any help


 

 

 

  1. Navigate to and delete the following registry subkeys:

    • HKEY_CURRENT_USER\Software\MalwareBot
    • HKEY_CLASSES_ROOT\CLSID\{C5D60FD5-9CCB-403c-9ED7-A5E1676C38CE}
    • HKEY_CLASSES_ROOT\Installer\Features\42FDF858096D3024DB1A97FFAAB0D6B3
    • HKEY_CLASSES_ROOT\Installer\Products\42FDF858096D3024DB1A97FFAAB0D6B3
    • HKEY_CLASSES_ROOT\Installer\UpgradeCodes\8BF9CD9F316AF4348A9E5930114224AF
    • HKEY_LOCAL_MACHINE\SOFTWARE\MalwareBot
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DisabledRun
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DisabledUninstall
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{C5D60FD5-9CCB-403c-9ED7-A5E1676C38CE}
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DisabledBHO
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{858FDF24-D690-4203-BDA1-79FFAA0B6D3B}
  2. Exit the Registry Editor

Definitely follow Dbris' advice.

 

Also, do you get a message where it is finding it?  Click on options when you call it up and click on it in the History listing.  It sounds as though it is finding the malware but not that it is installed.  For example, it could be coming as an attachment on some email you are being bombarded with.  The fact that Norton has found and quarantined or deleted it has probably kept it from ever infecting your computer.

 

Example of a possible scenario (happening to my wife's computer over the past three days):

You are on the address list of someone whose computer is infected or being attacked.

Email with mal-attachments are being sent/forwarded to you on a regular basis; and will continue to happen until that computer is cleaned up and properly filters its forwards.

So day after day, Norton intercepts the attachments, deletes/quarantines the file, and notifies you of what it has done.

my norton finds this  and says it removes it  atleast 4 times a day. i have viewed my history and went to the  symantec malware bot removal page that  said how to  remove   but i cant find any  of what is listed (list below) any idea what to do now?   and i have also ran super anti  spyware and ccleanr on my registry   thanks for any help


 

 

 

  1. Navigate to and delete the following registry subkeys:

    • HKEY_CURRENT_USER\Software\MalwareBot
    • HKEY_CLASSES_ROOT\CLSID\{C5D60FD5-9CCB-403c-9ED7-A5E1676C38CE}
    • HKEY_CLASSES_ROOT\Installer\Features\42FDF858096D3024DB1A97FFAAB0D6B3
    • HKEY_CLASSES_ROOT\Installer\Products\42FDF858096D3024DB1A97FFAAB0D6B3
    • HKEY_CLASSES_ROOT\Installer\UpgradeCodes\8BF9CD9F316AF4348A9E5930114224AF
    • HKEY_LOCAL_MACHINE\SOFTWARE\MalwareBot
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DisabledRun
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DisabledUninstall
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{C5D60FD5-9CCB-403c-9ED7-A5E1676C38CE}
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DisabledBHO
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{858FDF24-D690-4203-BDA1-79FFAA0B6D3B}
  2. Exit the Registry Editor

Hi festis12:

 

This might interest you...

 

PUA.MalwareBot is an adware that falsely detects legitimate network programs as a computer threat. PUA.Malware.Bot displays a number of infected files and prompts the user to register the program before the threat will be removed.

 

As instructed, please follow the steps to use MBAM, which should remove this adware from your system.

 

Please do not touch the System Registry and report back with the results.

 

TIA.

 

malwarebytes worked  thanks for the help

Hi festis

 

Since you are pleased with the information you received, please mark the post which gave you the correct answer. This way we and others will know that this problem has been solved. You can do that by clicking the green button in the post that had the best answer for you. If you want, you can also give people a kudo if that answer was particularly helpful. Thanks for coming back and telling us your problem has been solved. Please feel free to come back again any time you have a problem and just open up another thread. Thanks