Jump to content

MBAM.exe not found

Recommended Posts

I am trying to install MBAM on XP. Everything looks fine and looks finished, but when I click on the icon on the desktop to open it, I get this Windows cannot find mbam.exe with an option to browse with the cute little flashlight.

I have MBAM installed at work and it works just fine.

While I'm at it, my problem with my computer are these "ads" that pop up. For example: Congratulations Facebook User! you have won $1000 Wal Mart card!

I have AVG paid version and it tells me no virus but on my last scan it dumped a lot of tracking cookies in the vault.

I usually use Firefox, but other users might use IE. I've checked the pop up blockers and they are both on.

Any help on the best way to stop these ads and to figure out MBAM would be appreciated.

Link to post
Share on other sites

Hello and Welcome to Malwarebytes.....

Seems that perhaps the malware on your computer is deleting the mbam.exe file. You can try the steps mentioned in the link below see if it helps....

mbam will not install - Code 2 error, mbam.exe not found

It looks like some malware may be deleting the file when it installs. Please see if the below instructions help you.

Please go here:


And see if that might help get Malwarebytes running for you :P

Link to post
Share on other sites

That worked and I was able to run the scan. I am very concerned though, it says Vundo trojan.

This is my log file:

Malwarebytes' Anti-Malware 1.44

Database version: 3877

Windows 5.1.2600 Service Pack 2

Internet Explorer 6.0.2900.2180

3/17/2010 4:04:40 PM

mbam-log-2010-03-17 (16-04-40).txt

Scan type: Quick Scan

Objects scanned: 122126

Time elapsed: 5 minute(s), 40 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 3

Registry Keys Infected: 3

Registry Values Infected: 4

Registry Data Items Infected: 4

Folders Infected: 0

Files Infected: 11

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

c:\WINDOWS\SYSTEM32\boyimeta.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\SYSTEM32\leduhuma.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\SYSTEM32\sokazoya.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:

HKEY_CLASSES_ROOT\CLSID\{3bcd4056-4f2f-4c61-8d80-7b742d93332e} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pezemewik (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{3bcd4056-4f2f-4c61-8d80-7b742d93332e} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\mobinugun (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{98279c38-de4b-4bcf-93c9-8ec26069d6f4} (Adware.SelectRebates) -> Quarantined and deleted successfully.

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: sokazoya.dll -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\boyimeta.dll -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\boyimeta.dll -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\SYSTEM32\berinege.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\SYSTEM32\boyimeta.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\SYSTEM32\hubobazi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\SYSTEM32\jijivafo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\SYSTEM32\kabifoti.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\SYSTEM32\kusewovi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\SYSTEM32\leduhuma.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\SYSTEM32\lezaromo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\SYSTEM32\sokazoya.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\SYSTEM32\sosazeri.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\Documents and Settings\\Local Settings\Temp\n.exn (Trojan.Dropper) -> Quarantined and deleted successfully.

Link to post
Share on other sites

  • Root Admin

We don't work on Malware removal here in the General forum.. Just reboot the computer as requested and then do another scan to see if it finds anything else. Then update your Anti-Virus and scan with it as well.

If you do continue to have any Malware related issues then please follow the directions below.

We don't work on Malware removal in the general forums.

Please print out, read and follow the directions here, skipping any steps you are unable to complete. Then post a NEW topic here.

One of the expert helpers there will give you one-on-one assistance when one becomes available.

After posting your new post make sure under options that you select Track this topic and choose one of the Email options so that you're alerted when someon has replied to your post.

Alternatively, as a paying customer, you can contact the help desk at support@malwarebytes.org

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.