Jump to content

MBAM found malware, what now?

Recommended Posts

I run constant scans with MBAM. However, the lastest one found some stuff. The moment before I decided to run a scan, Win10 was running weird, with Firefox not being able to open up and immediately crashing after starting, Chrome able to start but not able to load tabs and MBAM not having enough memory to start. These things disappeared after a reboot and then I could run the scan. The logs are attached and together with the FRST and Addition.

Addition.txt FRST.txt mbam log.txt

Link to post
Share on other sites

After 20 hours, MBAM scan came out clean. No idea why it is taking longer than usual. I also ran ESET online scanner for the hell of it and it only flagged one remaining file of a previous Avast installation in a secondary drive. I'm still curious about those [Atention] details in the FRST log.

Link to post
Share on other sites

I don't ever recall tampering with things to make these things appear:

HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION

GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION


Or whatever this means:

Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\Temp\aswa2b4b00da4490296.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Link to post
Share on other sites

  • Root Admin

Good day, @Scanzie

Policies get set on purpose by Microsoft and sometimes by the settings of a program. The listing by Microsoft Safety Scanner is normal to find and remove that setting. The file detections during scan are not real detections. They are traces of "potential" threat. Microsoft gathers all of them locally, then uploads them to their Cloud Artificial Intelligence to determine if, in fact, they're actual threats or just traces. The final written log is the valid result.

Please restart your computer again, then run the Farbar scanner and post back both new logs and I will review for any other potential issues.

  • FRST.txt
  • Addition.txt




Link to post
Share on other sites



I wonder why the Event Log and below shows up quite a bunch of errors. I have to run /sfc scannow and /dism quite frequently because there is always some corruption getting (successfuly) fixed, Chkdsk never finds anything, I do have drivers updated and yet sometimes this PC goes a bit weird and for example, an important excel file I need got damaged and Windows cannot extract from some compressed folders. I thought it might be some sort of malware, but nothing is coming out either.

FRST.txt Addition.txt

Link to post
Share on other sites

  • Root Admin

The computer doesn't show signs of obvious infection and issues in the Event Logs is not always corrected by SFC or DISM. In many cases you need a specific fix.

It could be that you've damaged the computer at some point too due to infection or modifications to the registry that were invalid, etc. If you have ongoing issues then you might want to consider doing a CLEAN INSTALL of Windows.

Basically backup all your personal data to an external USB drive. Then build a USB thumb drive of the Windows 10 or 11 installers. Boot from it and remove the current partition and install Windows.



Greg Carmack - MVP 2010-2020 -Clean Install Windows 10

How to Create a Local Account While Setting Up Windows 10


Or if you want Windows 11

How to make clean install of Windows 11


You currently have a service install in a Temp folder which does not belong.

S3 GPU-Z-v2; \??\C:\Users\USER\AppData\Local\Temp\GPU-Z-v2.sys [X] <==== ATTENTION

If you like we can try to do a bit of clean up of the current computer, but in the long run, taking the time to do a clean install of Windows would be a much better choice.

Let me know how you'd like to proceed.


Link to post
Share on other sites

Thing is, this is already a new fresh installation and I never had infections before nor do I tamper the registry.


You currently have a service install in a Temp folder which does not belong.

Interestingly enough, it isn't appearing in the Temp folder.


If you like we can try to do a bit of clean up of the current computer,

I'd rather prefer this, TBH as I don't have a thumb drive large enough to back up things and cannot buy one either.

Link to post
Share on other sites

  • 4 weeks later...
  • Root Admin

Glad we could help.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread.

Please review the following to help you better protect your computer and privacy Tips to help protect from infection

Thank you



Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.