Hello guys,i use malwarebytes to scan my laptop and everytime lately finds the same problems which deletes but reappear.
Here are the results:
Malwarebytes' Anti-Malware 1.46
Malwarebytes
Database version: 4288
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
08/07/2010 03:26:02
mbam-log-2010-07-08 (03-26-02).txt
Scan type: Quick scan
Objects scanned: 126992
Time elapsed: 4 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hkcu (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\mina\AppData\Roaming\msconfig\msconfig.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\mina\AppData\Roaming\logs.dat (Bifrose.Trace) -> Quarantined and deleted successfully.
C:\Users\mina\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\mina\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> Delete on reboot.
i typed msconfig the first time and appeared:
Yes HKCU:Run BrowserChoice "C:\Windows\System32\browserchoice.exe" /run
Yes HKLM:Run IAStorIcon C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
Yes HKLM:Run ISBMgr.exe "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
Yes HKLM:Run McENUI C:\PROGRA~2\McAfee\MHN\McENUI.exe /hide
Yes HKLM:Run NortonOnlineBackupReminder "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
Yes HKLM:Run PMBVolumeWatcher C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
Yes HKLM:Run MarketingTools C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
Yes HKLM:Run mcagent_exe "C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe" /runkey
Yes HKLM:Run Adobe Reader Speed Launcher "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Yes HKLM:Run Adobe ARM "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
Yes HKLM:Run SunJavaUpdateSched "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
Yes HKLM:Run Malwarebytes Anti-Malware (reboot) "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
Yes HKLM:Run IgfxTray C:\Windows\system32\igfxtray.exe
Yes HKLM:Run HotKeysCmds C:\Windows\system32\hkcmd.exe
Yes HKLM:Run Persistence C:\Windows\system32\igfxpers.exe
Yes HKLM:Run RtHDVCpl C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
Yes HKLM:Run Apoint %ProgramFiles%\Apoint\Apoint.exe
Yes Startup Common Bluetooth.lnk C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
plus another HKCU(which i try to unclick at the startup) where it said No next to it but i can't find it anymore.It was
somekind of msconfig.exe facebook hack..a programm like that
and i also deleted a file folder :msconfig,size:432KB and origin:Roaming
Any suggestions?
Tha antivirus can't find anything.