Jump to content

MB won't run(Fix)


Recommended Posts

Hi all,

Symptoms are very obvious. Fake alert screens,fake security software activity and browser Hijacking.

totalsecurity.jpg

Recent variants of Total Security have been blocking MBAM from running and subsequently preventing the software from detecting and removing it B)

It dose this by terminating the process(mbam.exe) when it is loaded into memory inorder to run.

Inorder to get MBAM to run we will need to turn the tables on Total Security and kill's its active process first!

This can be done very easily by the following walkthrough :)

Download ProcessExplorer and install.Please use only as directed*

http://technet.microsoft.com/en-us/sysinte...s/bb896653.aspx

We need to identify which is the Total Security entry....very easy at the moment as it is tsc.exe and the little shield icon is a give away should they change the name of the .exe file.

Next up goto the entry tsc.exe in Process Explorer main window by hovering your mouse pointer over it.

When there use right click on your mouse to select it next choose kill process and then confirm(yes).

peversusts.jpg

Finally update and run quickscan with MBAM and Total Security will be no more :)

We hope our application has helped you eradicate this malicious Malware.

If your current anti-virus solution let this infection through please consider purchasing the PRO version of Malwarebytes' Anti-Malware for additional protection against these types of malware.

Disclaimer to the more learned readers-

Taskmanager can also be used to terminate tsc.exe but in some of the installs of this rogue then TM has been disabled by the infection.Hence why the use of imported Process Explorer :(

Link to post
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.