-
Odd entry in Msconfig
What are the odd chinese looking entries in MSCONFIG? I had only 1 the other day and now I have 2? I ran virus scan at trendmicro and it says I have Sandbox.A, but I cannot find the entry in the registry to delete it. I also have Panda (my AVS) detecting viruses and it says they have been disinfected. Panda did not pick up the Sandbox.A, but it did pick up these. Are the odd looking entries in Msconfig due to a virus also? I found one other entry in Msconfig too:Yahy0W6
Virus detected: EICAR-AV-TEST-FILE 07/15/04 10:02:29 Disinfected Location: c:\documents and settings\brooke\local settings\temporary internet files\content.ie5\k31zxv8o\eicar[1].com
Virus detected: EICAR-AV-TEST-FILE 07/15/04 10:01:39 Disinfected Location: c:\documents and settings\brooke\local settings\temporary internet files\content.ie5\cgh6ywoa\eicar[1].com
Virus detected: Trj/Nedibed.A 07/15/04 09:50:13 Disinfected Location: c:\windows\system32\traon.exe
Virus detected: Trj/Siboco.A 07/15/04 06:53:42 Disinfected Location: c:\documents and settings\brooke\local settings\temporary internet files\content.ie5\v2ol17vq\hp2[1].exe
Virus detected: Trj/Siboco.A 07/14/04 20:12:37 Disinfected Location: c:\documents and settings\brooke\local settings\temporary internet files\content.ie5\spur4p6z\hp2[1].exe
Virus detected: Trj/Revop.F 07/14/04 20:06:00 Disinfected Location: c:\windows\system32\bdla4012.exe
Virus detected: Trj/Siboco.A 07/14/04 20:05:48 Disinfected Location: c:\documents and settings\brooke\local settings\temporary internet files\content.ie5\t6gz3ph0\hp2[1].exe
Virus detected: Bck/Webber.gen 07/06/04 06:19:20 Disinfected Location: C:\WINDOWS\System32\Iadgje32.dll
Virus detected: Bck/Webber.gen 06/29/04 12:26:54 Disinfected Location: C:\Program Files\Windows Media Player\mp3codec543.exe
Virus detected: Bck/Webber.gen 06/29/04 12:14:02 Disinfected Location: C:\Documents and Settings\Kermit\Local Settings\Temporary Internet Files\Content.IE5\UXOJ2DO5\mp3[1].htm
Virus detected: Bck/Webber.gen 06/29/04 11:59:38 Disinfected Location: c:\windows\system32\kojhhc32.exe
Virus detected: Trj/Briss.A 06/23/04 10:51:45 Disinfected Location: C:\Documents and Settings\Brooke\Local Settings\Temporary Internet Files\Content.IE5\N0XP7SK4\hp2[1].exe
Virus detected: Trj/Keylog.L 05/12/04 15:47:36 Disinfected Location: c:\documents and settings\brooke\local settings\temporary internet files\content.ie5\drn7t50i\infamous[1].exe
Virus detected: Trj/Keylog.L 05/12/04 15:47:36 Disinfected Location: c:\windows\infamous.exe
Virus detected: Trj/Keylog.L 05/12/04 15:37:37 Disinfected Location: c:\documents and settings\brooke\local settings\temporary internet files\content.ie5\i3u7mhez\infamous[1].exe
Virus detected: Trj/Keylog.L 05/12/04 15:37:37 Disinfected
-
Got to Control Panel and click on Internet Options. There click the buttons Clear History, Delete Files, Delete Cookies.
Chances are you will not have more of these messages. Also, consider installing Ad-Aware. Download it from here:
http://lavasoft.element5.com/support/download/#free
It will remove other things that are not cleared from internet option.
As to the sandbox.a copy the path from TrendMicro run and look it up and delete the offending files.
-