Jump to content

FP on msconfig.exe


DaveM

Recommended Posts

Hard to believe. I downloaded MBAM, installed, updated, and ran a quick scan. It found four files. I decided to remove/quarantine all, but it turned out three of them could not be quarantined. They were deleted on reboot. The fourth was msconfig.exe. I restored it from quarantine and submitted it to Jotti -- it came out clean. Then ran a quick scan in developer mode. Here's the log of that scan:

Scan type: Quick Scan

Objects scanned: 87434

Time elapsed: 5 minute(s), 0 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\msconfig.exe (Trojan.Agent) -> No action taken. [385753513430362761788468807971747215708970]

Link to post
Share on other sites

Update. I ran fc and the file is identical to the one in the normal place (...pchealth\helpctr\binaries). I think it must have been flagged based on its location. Now if only I knew how a copy got put in the root directory. Probably I did it myself but when or why I have no recollection.

To the Malwarebytes wizards, sorry I wasted your time. Feel free to close this topic.

Link to post
Share on other sites

Update. I ran fc and the file is identical to the one in the normal place (...pchealth\helpctr\binaries). I think it must have been flagged based on its location. Now if only I knew how a copy got put in the root directory. Probably I did it myself but when or why I have no recollection.

To the Malwarebytes wizards, sorry I wasted your time. Feel free to close this topic.

it's a hueristics hit. Essentially the file is in the wrong location. No waste of time on our part, We're here to help!

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.