Jump to content

daledoc1

Honorary Members
  • Posts

    22,820
  • Joined

  • Last visited

Posts posted by daledoc1

  1. Hi:

     

    FRST is perfectly safe.

    The developer, farbar, is an Expert member at this forum.

    The FRST tool is used 100s or 1000s of times daily here, at bleepingcomputer.com and at other malware removal forums.

    It is essentially a "false positive" detection by Norton.

     

    If you TEMPORARILY disable Norton, you should be able to download and run the tool.

    Then, re-enable Norton.

    Then, please post back with the 3 requested logs from both scanning tools attached to your next reply, as previously suggested.

    Without diagnostic logs, it's impossible for anyone to determine the cause or the solution for the issue you reported. :(

     

    Alternatively, you may wish to seek free, expert help over in the malware removal section of the forum or at the help desk for email support.

    These options are explained in this pinned topic: Available Assistance for Possibly Infected Computers

    (However, the helpers in either venue are likely to ask for the same FRST logs to start the troubleshooting process.)

     

    Thank you,

  2. Hello and :welcome: :

     

    Unfortunately, there is currently no way to completely disable such notifications.

     

    The IP blocking module and the real-time Malware protection modules are both critical components of MBAM Premium.

    So, as with any other security application, the program *will* notify the user when a key component has been disabled.

    This is for safety.

    Disabling either or both modules greatly reduces the real-time protection afforded by MBAM Premium; doing so is NOT recommended.

     

    Having said that, the developers have mentioned that more granular control of certain, non-critical popup tray notifications will be provided with a future program version.

    The reminder in the GUI will likely remain.

     

    More detailed explanations about this from the Product Manager may be found here:

    https://forums.malwa...on/#entry813524

    https://forums.malwa...on/#entry894565

     

     

    Well, to be frank, I do not believe that most of our customers permanently disable one of the major components of protection that our application provides. It is quite true that some do, and that we do intend to make some allowances for that, including the ability to specify which tray notifications are displayed, however I have yet to see any security application which allows the user to have the application display a 'green' or 'everything is OK' status when one of its major protection components is disabled (and we tested many when determining what the best practices were for the functionality of our application).

    The fear is that, as I mentioned earlier, a user might forget that they turned it off, and of course it's also possible that malware may have disabled it, and not alerting the user to something like that would be a critical failure on our part for those customers because if malware were able to disable the protection, it could just as easily also disable all status indicators and notifications that the protection were turned off if we provided the functionality to disable all such indicators, meaning a user could be infected, with all protection turned off, yet our application says nothing to indicate to those customers that there's any problem at all, which would be far worse than the annoyance you guys are getting from the status indicator as it is.

    We will provide a way to disable the notification from the tray though, so you won't have to deal with the pop-up any more when we re-work all of our notification settings to make them all granular as I said earlier.

    You may easily revert to the Free, manual, on-demand scanner version by opening the GUI > My Account > Deactivate, or by cleanly uninstalling and then reinstalling as the Free version.
    This would defeat the purpose of having the paid, Premium version of MBAM, as you will have no real-time protection.

    But you would no longer receive notifications about disabled protection components.

     

    Thank you,

  3. Addendum:

     

    MBAM works best and is designed to be installed and run on the OS boot drive.

    Routine, "custom", full system scans of all system drives will be slow.

    Moreover, such scans are neither necessary nor recommended on a routine basis.

    It's a task better suited to your anti-virus.

     

    For routine scanning (especially on systems running MBAM Premium alongside a robust anti-virus), Threat scans are all that are needed or recommended.

     

    Cheers,

  4. Hello --

     

    Does "ms defender" try to do the same as  malware-bytes?

    Yes, but it is not nearly as robust.

    There is no comparison, IMHO.

     

    Also, with the free version, the "quick scan to grayed out -- is this by design?

    I think you might be referring to the "Hyper" scan?

    The different types of scans were renamed in version 2.

    "Flash" is now "Hyper"

    "Quick" is now "Threat"

    "Full" is now "Custom"

    YES, Hyper scan is available only to paid, PREMIUM (and Trial version) users and is not routinely needed or recommended -- if anything is found, a subsequent Threat scan will be needed anyway.

    THREAT scan is the most important and most useful scan -- it is the one that ought be run on a regular basis (daily is the default setting now in 2.0).

    Custom depends on what drives, folders and files are selected -- routine use of a "full" system scan is neither necessary nor recommended, as it's a task better suited to your antivirus.

    ALSO, for additional information:

    There is an FAQ Section here: Common Questions, Issues, and their Solutions

    And here are links to the MBAM 2.0 User Guide: Online and PDF

    And there are many useful KB topics and videos at the helpdesk support page

     

    Thanks,

  5. Hi:

     

    First, none of this is "mine", as I do not work for Malwarebytes. As my signature block clearly states, I am just another home user and forum volunteer.

    Second, there was no snark.  I apologize if you interpreted my reply that way.

    Finally, I was only trying to help by taking time to craft a detailed, individual reply to address your specific concerns.  The steps suggested for a reinstall work for the vast majority of users. When they don't, the diagnostic logs provide a bit of needed information to assist with troubleshooting.

     

    Clearly, my efforts did not meet your expectations.  As such, please wait for assistance from a Malwarebytes staff member.

     

    Thank you,

  6. Hello and :welcome: :

     

     

    Please start here: Malicious Website Protection disabled

    If that advice and restarting the computer don't resolve the issue, please continue with these steps:

    • Please follow the steps in this pinned topic to uninstall your current version of MBAM and reinstall the latest build - MBAM Clean Removal Process 2x
    • If that does not correct the issue, then please read the following and attach to your next reply the 3 requested logs - Diagnostic Logs (the 3 logs are: FRST.txt, Addition.txt and CheckResults.txt)
    • NOTE: There is an FAQ section with valuable information located here - Common Questions, Issues, and their Solutions

    Please let us know how it goes.

    Thanks,

  7. Hi:

     

    I am not normally permitted to reply in this area of the forum.

    However, as this post will likely be moved to a more suitable area >>here<<, I will take the liberty of replying. :)

     

    It appears from your other, open, working thread >>HERE<< that you might have recently reinstalled MBAM?

    If so, a 14-day Trial version is enabled by default during installation.

    At the end of the 14-day Trial, the program reverts back to the Free version UNLESS the user ****activates*** the program with the license ID/key.

    Activating the program with the license ID and key will "turn on" the Premium features.

     

    To do that, please take a look at this KB topic and video: How do I activate Malwarebytes Anti-Malware?

    The license ID/key were sent to you by email when you first purchased MBAM Pro/Premium.

    If you do not have that email and if you purchased directly from the Malwarebytes online store, you can contact the e-commerce partner, cleverbridge.

    They will look up and send you the license ID and key.

    More info here: How do I obtain my license key or confirmation email?

     

    Once you have activated the program, you will be back to the Premium version, with all of the added features.

     

    Then, please continue with "Twin" in your other, open, working topic >>HERE<<.

    Please stay with that topic until your helper gives you the "all clear".

     

    I hope this helps,

  8. Hello and welcome:
     

    In 2 years your software never found a single mailicious software on my computer so I decided to disable it. I mean why bog things down running a program that doesn't do anything at all?


    Most users are pleased not to be infected. :)

    As for bogging down the system, that is not the case for nearly all users with modern systems that are properly configured and not infected.
    We would need to know more about your system specs, hardware and software to be able to help with "bogging down" issues (see step #2 below). :)
     

    Now your program starts itself up every single time I boot my PC regardless of whether it's disabled or not.


    That is a known (EDIT: known to the developers, i.e. previously reported and "expected") behavior in MBAM 2.x, if the user has scheduled tasks (update checks or scans).
    Those tasks trigger one of the mbam services, even if the *protection modules* are configured not to start with Windows.
    It is pretty much a cosmetic issue, but the developers have mentioned that the behavior may be changed in a future version, such that disabling "start with Windows" will disable ALL mbam services.
    Having said that, disabling "start with Windows" significantly reduces one's real-time protection, so it's not recommended.

     

    It also schedules itself to run scans even though it's disabled and even though nothing was ever scheduled.
     
    In fact while I was forced to sit thru a scan this morning that I never asked for I noticed it said another scan was scheduled for tomorrow at 1:30am. I never scheduled that scan nor is it listed under automated scheduling.
     
    Maybe you can explain to me how to fix your program so that it stops acting like the malware I wanted to avoid?


    Clean scheduled scans run silently from the system account.

    It sounds as if your automated scheduled tasks settings are messed up, especially the "recover if missed by" settings.

     

    The standard recommendations to resolve these sorts of issues start here:

    • Please follow the steps in this pinned topic to uninstall your current version of MBAM and reinstall the latest build - MBAM Clean Removal Process 2x
    • If that does not correct the issue, then please read the following and attach to your next reply the 3 requested logs - Diagnostic Logs (the 3 logs are: FRST.txt, Addition.txt and CheckResults.txt)
    • NOTE: There is an FAQ section with valuable information located here - Common Questions, Issues, and their Solutions

    Thanks,

  9. Hi:
     
     
    Preliminary review of your logs suggests that you are probably infected.

    We can't work on malware diagnostics and removal in this sub-section of the forum.

    So, for expert assistance, I suggest that you please follow the advice in this pinned topic: Available Assistance For Possibly Infected Computers.
    It explains the options for free, expert help >>AND<< the preliminary steps to expedite the process.
    A malware analyst will guide you through the cleanup process.

    >>>As you have already run FRST, you just need to start a NEW topic in the malware removal section -- please attach the same logs to that new post.

    Then, please wait for a helper to assist you.

    Thanks,

  10. Hi:
     
    There are several possible reasons for this behavior, one of them being malware infection.
     
    If rebooting the system doesn't resolve your issue:

    • Please carefully follow the steps in this pinned topic to uninstall your current version of MBAM and reinstall the latest build - MBAM Clean Removal Process 2x
    • If that does not correct the issue, then please read the following and attach to your next reply the 3 requested logs - Diagnostic Logs (the 3 logs are: FRST.txt, Addition.txt and CheckResults.txt)
    • NOTE: There is an FAQ section with valuable information located here - Common Questions, Issues, and their Solutions

    Please let us know how it goes.

    Thanks,

  11. Hi:

     

    I see that you started a new topic in the malware removal section here: https://forums.malwarebytes.org/index.php?/topic/162626-100-disk-usage-request-log-analysis/

     

    It would have been a good idea to follow the advice in the pinned topic to include the requested FRST scan logs with your post.

    Doing so would have permitted the malware helpers to get off to a head start with identifying your issue.

    HOWEVER, at this point, it would be best NOT to reply to that other topic with logs or any other information or a "bump" for at least 48 hours.

    Doing so will change the reply count from "0".

    That could lead to delay in getting help, as the experts look for threads with "0" replies.

     

    Bottom line: please wait for a helper to respond to your thread in the malware removal section.

    Then, please stay with it until the helper gives you the "all clear".

    Please be patient: the forum is busy, most of the expert helpers are volunteers, and it is a holiday week.

     

    Thanks,

  12. Hi:

     

    Until Firefox returns...

    Preliminary review of your scan logs suggests that you could be infected.

    We cannot work on possible malware-related issues in this area of the forum.

    So I suggest that you might want to please follow the advice in this pinned topic: Available Assistance For Possibly Infected Computers.
    It explains the options for free, expert help >>AND<< the preliminary steps to expedite the process.
    A malware analyst will assist you with looking into your issue.

    >>As you have already run FRST, you just need to start a NEW topic in the malware removal section (attaching the same logs).

    Then, please wait for one of the expert helpers to pick up your thread.

    Thanks,

  13. Hi:

     

    Welcome.

     

    The behavior you describe could be a sign of malware infection.

     

    I suggest that you please follow the advice in this pinned topic: Available Assistance For Possibly Infected Computers.
    It explains the options for free, expert help >>AND<< the preliminary steps to expedite the process.
    A malware analyst will assist you with looking into your issue.

     

    >>Important: if you have more than one computer, please start a new topic (with the requested scan logs) in the malware removal section of the forum for only ONE system at a time.

    Thanks,

  14. Hi:
     
    Yes, you can reinstall MBAM and use the same license ID/key to activate the Premium version.
    If rebooting the computer doesn't resolve the issue with the anti-rootkit driver, the steps to cleanly reinstall are here: MBAM Clean Removal Process 2x.

    More tips are here: How do I activate Malwarebytes Anti-Malware?

     

    Having said that, your system may still have malware remnants or damage from the malware.
    Even if you are able to reinstall MBAM, you might want to have an expert assist you with a deeper look at the system.
    We can't work on malware diagnostics and removal in this sub-section of the forum.

    So, for expert assistance, I suggest that you might want to please follow the advice in this pinned topic: Available Assistance For Possibly Infected Computers.
    It explains the options for free, expert help >>AND<< the preliminary steps to expedite the process.
    A malware analyst will assist you with looking into the issue.

    Thanks,

  15. Hi:

     

    The steps suggested in my previous reply are typically the most efficient way to get back up and running, which is what most users want.

    If the clean reinstall doesn't resolve the problem reported (unable to update to the current version), then the diagnostic logs often shed light into the underlying cause.

     

    Your specific questions:

     

    1) No, please follow the recommended best practices for a clean reinstall using the Malwarebytes removal tool, rather than a 3rd-party uninstaller. Please be sure to reboot the system when prompted. (You didn't say what this other program is. But, whatever program it is, in fact, it may be contributing to the updating problems you report, if it is somehow blocking the upgrade. So, you might want to disable or temporarily uninstall this other program in order to facilitate the MBAM upgrade.)

     

    2) If the program is working properly after a clean upgrade, then no further diagnostics need to be run.

     

    3) If you do run into problems with the program at any point, then the Diagnostic Logs mentioned in my original reply would help to shed light on many possible causes. If they do not reveal the source of a problem, then the user is typically referred to another area of the forum, where other tools can be used with the help of trained experts to more deeply scan the system for issues (malware, corruption, failing hard drive, etc.).

     

    Honestly, you might be over-thinking all of this and making it harder than it needs to be. :)

     

    Thanks,

  16. Hi:

     

    No, that's not normal, if you did not manually set those particular IP exclusions.
     

    You might want to have one of the malware experts assist you with checking the system.
    I suggest that you please follow the advice in this pinned topic: Available Assistance For Possibly Infected Computers.
    It explains the options for free, expert help >>AND<< the preliminary steps to expedite the process.
    A malware analyst will assist you with looking into the issue.

    Thanks,

  17. Hi:

     

    You wrote:

     

    Same problem here, loging in after nearly an year & had to reset password to get in......

     

    That's because all forum members were asked to reset their passwords after the forum problem several weeks ago. :)

    Members were notified by email about this, but you may not have gotten the email about it, for some reason.

     

    Thanks,

  18. Hi:

    For Malwarebytes Anti-Malware (MBAM), let's start here:

    • Please follow the steps in this pinned topic to uninstall your current version of MBAM and reinstall the latest build - MBAM Clean Removal Process 2x
    • If that does not correct the issue, then please read the following and attach to your next reply the 3 requested logs - Diagnostic Logs (the 3 logs are: FRST.txt, Addition.txt and CheckResults.txt)
    • NOTE: There is an FAQ section with valuable information located here - Common Questions, Issues, and their Solutions

     

    You mention the "beta of Exploit".

    MBAE (Malwarebytes Anti-Exploit) is no longer in beta. :)

    So, you might want to uninstall whatever version you have, reboot the computer, and then cleanly reinstall the current version (1.05.1.1016) from >>HERE<<.

    If you still have issues with MBAE after that, then I suggest that you might want to start with the posting instructions >>HERE<<, followed by a new post with the requested diagnostic logs in the MBAE support area >>HERE<<.

     

    Please let us know how it goes.

    Thanks,

  19. Hi:

     

    Unfortunately, there is currently no way to completely disable such notifications.

    The IP blocking module is a critical component of MBAM.

    So, as with any other security application, the program *will* notify the user when a key component has been disabled.

    This is for safety.

    Disabling the IP blocking module greatly reduces the rea-ltime protection afforded by MBAM Premium; doing so is NOT recommended.

    https://helpdesk.malwarebytes.org/hc/en-us/articles/202325608-What-does-it-mean-when-I-get-an-alert-that-Malwarebytes-Anti-Malware-has-blocked-a-malicious-site-

    https://helpdesk.malwarebytes.org/hc/en-us/articles/201948317-Why-does-Malwarebytes-Anti-Malware-block-BitTorrent-or-other-Peer-to-Peer-Programs-

     

    Having said that, the developers have mentioned that more granular control of certain, non-critical popup notifications will be provided with a future program version.

    The reminder in the GUI will likely remain.

     

    More detailed explanations about this from the Product Manager may be found here:

    https://forums.malwarebytes.org/index.php?/topic/144984-disable-notification-when-i-choose-to-disable-website-protection/#entry813524

    https://forums.malwarebytes.org/index.php?/topic/144984-disable-notification-when-i-choose-to-disable-website-protection/#entry894565

     

    Thank you,

  20. Hi:

    Please read the following and attach to your next reply the 3 requested logs - Diagnostic Logs (the 3 logs are: FRST.txt, Addition.txt and CheckResults.txt)

    It would also be helpful to see the SCAN log you mentioned, with the PUP detections. Instructions for posting the SCAN log (in addition to the other 3 logs) follow below.
     
    Thanks,

    -----------------

    How to get scan logs:
    (Export log to save as a txt file for posting in the forum when requested)

    • Open MBAM.
    • Click on the HISTORY tab > APPLICATION LOGS.
    • Double-click on the SCAN LOG which shows the date and time of the scan just performed (or the one you are asked to post).
    • Click EXPORT.
    • Click TEXT FILE (*.txt)
    • In the "Save File" dialog box which appears, click on DESKTOP.
    • In the FILE NAME box, type a name for your scan log.
    • A message box named "File Saved" should appear, stating that "Your file has been successfully exported".
    • Click OK.
    • Attach the saved log to your next reply.
  21. Hello and welcome back:

     

    Let's start here:

    • Please follow the steps in this pinned topic to uninstall your current version of MBAM and reinstall the latest build - MBAM Clean Removal Process 2x
    • If that does not correct the issue, then please read the following and attach to your next reply the 3 requested logs - Diagnostic Logs (the 3 logs are: FRST.txt, Addition.txt and CheckResults.txt)
    • NOTE: There is an FAQ section with valuable information located here - Common Questions, Issues, and their Solutions

    Please let us know how it goes.

    Thanks,

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.