[RESOLVED] win32:malware-gen
i have the malware-gen in quarantine in avast. also win32:toggleA
i ran the three scans....here's the mbam log
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Database version: v2013.01.17.05
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Owner :: DELL-PC1 [administrator]
1/17/2013 9:52:39 AM
mbam-log-2013-01-17 (09-52-39).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 279573
Time elapsed: 21 minute(s), 21 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|StartMenuLogoff (PUM.Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
here's the aswMBR.txt
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-01-17 10:47:28
-----------------------------
10:47:28.531 OS Version: Windows 5.1.2600 Service Pack 3
10:47:28.531 Number of processors: 1 586 0x209
10:47:28.531 ComputerName: DELL-PC1 UserName: Owner
10:47:30.093 Initialize success
10:47:37.421 AVAST engine defs: 13011700
10:47:41.062 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
10:47:41.062 Disk 0 Vendor: Maxtor_2F040L0 VAM51JJ0 Size: 39205MB BusType: 3
10:47:41.093 Disk 0 MBR read successfully
10:47:41.093 Disk 0 MBR scan
10:47:41.109 Disk 0 Windows XP default MBR code
10:47:41.109 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 31 MB offset 63
10:47:41.156 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 39166 MB offset 64260
10:47:41.171 Disk 0 scanning sectors +80276805
10:47:41.296 Disk 0 scanning C:\WINDOWS\system32\drivers
10:48:07.140 Service scanning
10:48:43.531 Modules scanning
10:49:18.453 Disk 0 trace - called modules:
10:49:18.484 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
10:49:18.484 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a0e6ab8]
10:49:18.484 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a0e7b00]
10:49:18.859 AVAST engine scan C:\WINDOWS
10:49:52.203 AVAST engine scan C:\WINDOWS\system32
10:53:24.375 AVAST engine scan C:\WINDOWS\system32\drivers
10:53:46.609 AVAST engine scan C:\Documents and Settings\Owner
11:04:17.609 AVAST engine scan C:\Documents and Settings\All Users
11:05:47.718 Scan finished successfully
11:06:29.828 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
11:06:29.843 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"
will send next 2 next post
TIA