My first run of Malwarebytes

Stevekir

New member
Member
VIP
Local time
11:05 PM
Messages
231
I installed and ran the free version. It found about 11 Candy PUP stuff which it deleted. Nothing else. Good.

But, two things:

1. Just before running, Malwarebytes advised turning off my antivirus for the default 10 minutes offered by AVG Cloudcare. (I know. It came free for a year when my computer was built for me and that sevenforums describes it as rubbish and I will soon be choosing a better one.) Having told me earlier that it was compatible with AVG, Malwarebytes took about 10 minutes to complete before telling me to restart (to complete the removal of the PUPs). AVG Cloudcare re-activated itself. But 10 minutes without any antivirus running worried me. (AVG detected a MSIL Trojan Horse two days ago and neutered it.)

-- Is 10 minutes without any antivirus worrying? And what should I do next time?

2. AVG Cloudcare reported as in the attached image. I had installed Acronis, and uninstalled it about 6 weeks ago using its uninstall program. I know what a digital signature is (but not in detail). The file is Hidden. My system is 64 bit, not 32. I will never want Acronis.

--Should I simply delete the file?

Thanks.
 

Attachments

  • AVG window.JPG
    AVG window.JPG
    35.7 KB · Views: 47

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Gigabyte ATX case with 500 W power supply GZ-M1
OS
Windows 7 Home Premium 64bit
CPU
Intel Pentium Edition G3220 3.0 GHz
Motherboard
Gigabyte Socket 1150 MicroATX Mot Ultra Durable, GA-H81M-S2H
Memory
8 GB DDR3 1600 MHz DIMM
Graphics Card(s)
Not Known
Sound Card
Not known
Monitor(s) Displays
Samsung LS24D590 23.6"
Screen Resolution
1920 x 1080
Hard Drives
256 GB Solid State Drive (C: on which Windows 7 is installed)-
1 TB internal conventional HD (X:)-
Two WD "Elements" " 2TB USB drives as backups
PSU
500 W
Case
Gigabyte ATX case
Cooling
Several fans!
Keyboard
Accuratus 301 USB Compact, white.
Mouse
Microsoft Basic Optical Mouse v2.0, two-button, tethered
Internet Speed
10 to 12 Mb per second
Antivirus
Kaspersky Internet Security 2016, Malwarebytes (paid)
Browser
Firefox (ocassionally Safari)
Other Info
The 256 GB SSD (C:) also has Adobe Photoshop CS6 and InDesign CS6, MS Office, Adobe Lightroom, and other small programs.
Hi:

I installed and ran the free version. It found about 11 Candy PUP stuff which it deleted. Nothing else. Good.

But, two things:

1. Just before running, Malwarebytes advised turning off my antivirus for the default 10 minutes offered by AVG Cloudcare. (I know. It came free for a year when my computer was built for me and that sevenforums describes it as rubbish and I will soon be choosing a better one.) Having told me earlier that it was compatible with AVG, Malwarebytes took about 10 minutes to complete before telling me to restart (to complete the removal of the PUPs).

That sounds odd.
I run MBAM Premium and have never been infected, but as a longstanding volunteer helper at the MBAM forum, I've never heard of MBAM prompting a user to disable one's AV in order to run a scan or clean up after a scan. It's especially so because it sounds as if you are describing "OpenCandy", which is just a PUP, not bad malware.

MBAM Premium is designed to run alongside all major AVs, and the Free version (no real-time protection) ought not to conflict, either.

Having said all that, some PUPs can be pesky to fully remove.

>>You don't happen to be able to replicate that behavior, so that you can post a screenshot here of the message dialog?

>>Or perhaps you can export the MBAM scan log as a *.txt file and attach it to your next reply here, so we can see what it found and removed (instructions for locating and exporting the log files are HERE)?


AVG Cloudcare re-activated itself. But 10 minutes without any antivirus running worried me. (AVG detected a MSIL Trojan Horse two days ago and neutered it.)

-- Is 10 minutes without any antivirus worrying? And what should I do next time?

2. AVG Cloudcare reported as in the attached image. I had installed Acronis, and uninstalled it about 6 weeks ago using its uninstall program. I know what a digital signature is (but not in detail). The file is Hidden. My system is 64 bit, not 32. I will never want Acronis.

--Should I simply delete the file?

Thanks.
We'll need to wait for someone more qualified with malware removal and more familiar with AVG, but that looks like an AVG false-positive, unrelated to MBAM.

Thanks,
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Studio XPS 8500
OS
OEM Windows 7 Ult (x64) SP1
CPU
Intel Core-i7 3770 @ 3.4 GHz
Motherboard
"Dell" branded
Memory
16 GB DDR3 SDRAM @ 1333 MHz
Graphics Card(s)
NVidia GeForce GT620 1 GB
Sound Card
THX TruStudio PC
Monitor(s) Displays
Dell U2410 Full HD
Hard Drives
2.0 TB SATA2 @ 7200 RPM
PSU
350W
Keyboard
MS 4000 Ergon - Wired
Mouse
Logitech Anywhere MX
Internet Speed
Cable HSI w/Turbo (router)
Antivirus
KIS-MBAM Premium-MBAE Premium
Browser
Fx (current version); IE
Other Info
And a Win7/64 Pro laptop; And a Win10/64 Pro desktop.

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Skylake Special #666
OS
Windows 10 Pro x64
CPU
Intel Core i7 6700K
Motherboard
Asus Sabertooth Z170 Mark 1
Memory
GSkill TridentZ RGB 16GB 3600 16-16-16-36
Graphics Card(s)
EVGA GTX 980 Ti SC x2
Sound Card
Realtek High Definition
Monitor(s) Displays
AOC G2460PG
Screen Resolution
1920 x 1080 144Hz
Hard Drives
Samsung 860 Pro 256GB, Seagate Barracuda 4TB x2
PSU
EVGA 1000 P2, EVGA White Custom Braided Cables
Case
Corsair Vengeance C70 Gunmetal Black
Cooling
Corsair H100i v2, Corsair ML120 x2, Thermal Grizzly Kryonaut
Keyboard
Logitech G910 Orion Spectrum
Mouse
Logitech G700s
Internet Speed
Verizon Fios Quantum Gateway 75/75
Antivirus
Windows Defender, Malwarebytes Free 3.8.3
Browser
Chrome
Other Info
Corsair SP120 x4, LG Blu-ray Drive, Durabrand HT-395 100 Watt Dolby Digital Amp, Corsair H2100 Wireless 7.1 Headset

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Studio XPS 8500
OS
OEM Windows 7 Ult (x64) SP1
CPU
Intel Core-i7 3770 @ 3.4 GHz
Motherboard
"Dell" branded
Memory
16 GB DDR3 SDRAM @ 1333 MHz
Graphics Card(s)
NVidia GeForce GT620 1 GB
Sound Card
THX TruStudio PC
Monitor(s) Displays
Dell U2410 Full HD
Hard Drives
2.0 TB SATA2 @ 7200 RPM
PSU
350W
Keyboard
MS 4000 Ergon - Wired
Mouse
Logitech Anywhere MX
Internet Speed
Cable HSI w/Turbo (router)
Antivirus
KIS-MBAM Premium-MBAE Premium
Browser
Fx (current version); IE
Other Info
And a Win7/64 Pro laptop; And a Win10/64 Pro desktop.
What`s funky about it :huh:

It`s the 1st link that comes up when googled, and what I have bookmarked.

You don`t want to send someone to the paid version page :)

Yours is good too, replaced mine with yours.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Skylake Special #666
OS
Windows 10 Pro x64
CPU
Intel Core i7 6700K
Motherboard
Asus Sabertooth Z170 Mark 1
Memory
GSkill TridentZ RGB 16GB 3600 16-16-16-36
Graphics Card(s)
EVGA GTX 980 Ti SC x2
Sound Card
Realtek High Definition
Monitor(s) Displays
AOC G2460PG
Screen Resolution
1920 x 1080 144Hz
Hard Drives
Samsung 860 Pro 256GB, Seagate Barracuda 4TB x2
PSU
EVGA 1000 P2, EVGA White Custom Braided Cables
Case
Corsair Vengeance C70 Gunmetal Black
Cooling
Corsair H100i v2, Corsair ML120 x2, Thermal Grizzly Kryonaut
Keyboard
Logitech G910 Orion Spectrum
Mouse
Logitech G700s
Internet Speed
Verizon Fios Quantum Gateway 75/75
Antivirus
Windows Defender, Malwarebytes Free 3.8.3
Browser
Chrome
Other Info
Corsair SP120 x4, LG Blu-ray Drive, Durabrand HT-395 100 Watt Dolby Digital Amp, Corsair H2100 Wireless 7.1 Headset
What`s funky about it :huh:

It's a peculiar URL, even though it takes one to the right landing page

It`s the 1st link that comes up when googled, and what I have bookmarked.
When I Google "MBAM Download", these are the first links provided in the search:
https://www.malwarebytes.org/mwb-download/
https://www.malwarebytes.org/downloads/
https://www.malwarebytes.org/
https://www.malwarebytes.org/antimalware/

So perhaps it depends on one's locale???

You don`t want to send someone to the paid version page :)
The setup file is the same for Free, Trial and Premium.
It's entirely up to the consumer whether or not to purchase the Premium version.
Any MBAM download link will provide the exact same installer, and it installs as the Free version*.
So, the only way one could end up with the Premium version is by purchasing a license and then activating the program.
IOW one cannot end up paying for the Premium unless one chooses to make the purchase.

(*There is a 14-day Trial enabled by default -- unless the user opts out during the setup wizard. The current policy is one Trial per PC per MBAM program version.)

>>The OP seems to be looking for realtime protection. That is why I mentioned the Premium version.
MBAM Free is just an on-demand, manual scanner.

Ennywho, I don't seek to flagellate a deceased equine.:D

It's just that I had never seen a URL like the one you posted (despite nearly 6 years and 20K posts at the MBAM forum).

Nothing more.:D

Cheers!
MM (no affiliation with or financial interest in MBAM)
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Studio XPS 8500
OS
OEM Windows 7 Ult (x64) SP1
CPU
Intel Core-i7 3770 @ 3.4 GHz
Motherboard
"Dell" branded
Memory
16 GB DDR3 SDRAM @ 1333 MHz
Graphics Card(s)
NVidia GeForce GT620 1 GB
Sound Card
THX TruStudio PC
Monitor(s) Displays
Dell U2410 Full HD
Hard Drives
2.0 TB SATA2 @ 7200 RPM
PSU
350W
Keyboard
MS 4000 Ergon - Wired
Mouse
Logitech Anywhere MX
Internet Speed
Cable HSI w/Turbo (router)
Antivirus
KIS-MBAM Premium-MBAE Premium
Browser
Fx (current version); IE
Other Info
And a Win7/64 Pro laptop; And a Win10/64 Pro desktop.
first link

Just a comment,
most first links tend to be "sponsored" and have extra's, i never ever use them.

Roy
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
Just a comment,
most first links tend to be "sponsored" and have extra's, i never ever use them.

Roy

Excellent point, and I always check before I click search links...:)

AFAIK none of the links I provided is "sponsored" (in fact, I'm not sure if Malwarebytes Corporation even engages in that...).

Ennywho, back to the OP's original question::)

@Stevekir, I am unfamiliar with MBAM ever prompting a user to disable his/her AV to scan or to clean-up.
If you still need help, could you please shed a bit more light on what you reported, perhaps with a scan log or screen-shot?

Thanks,
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Studio XPS 8500
OS
OEM Windows 7 Ult (x64) SP1
CPU
Intel Core-i7 3770 @ 3.4 GHz
Motherboard
"Dell" branded
Memory
16 GB DDR3 SDRAM @ 1333 MHz
Graphics Card(s)
NVidia GeForce GT620 1 GB
Sound Card
THX TruStudio PC
Monitor(s) Displays
Dell U2410 Full HD
Hard Drives
2.0 TB SATA2 @ 7200 RPM
PSU
350W
Keyboard
MS 4000 Ergon - Wired
Mouse
Logitech Anywhere MX
Internet Speed
Cable HSI w/Turbo (router)
Antivirus
KIS-MBAM Premium-MBAE Premium
Browser
Fx (current version); IE
Other Info
And a Win7/64 Pro laptop; And a Win10/64 Pro desktop.
I have used Malwarebytes Free and I also have use Malwarebytes Paid for years and have never had Malwarebyte Anti Malware ever requested me to turn off my anti virus program.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Hi:

I installed and ran the free version. It found about 11 Candy PUP stuff which it deleted. Nothing else. Good.

But, two things:

1. Just before running, Malwarebytes advised turning off my antivirus for the default 10 minutes offered by AVG Cloudcare. (I know. It came free for a year when my computer was built for me and that sevenforums describes it as rubbish and I will soon be choosing a better one.) Having told me earlier that it was compatible with AVG, Malwarebytes took about 10 minutes to complete before telling me to restart (to complete the removal of the PUPs).

That sounds odd.
I run MBAM Premium and have never been infected, but as a longstanding volunteer helper at the MBAM forum, I've never heard of MBAM prompting a user to disable one's AV in order to run a scan or clean up after a scan. It's especially so because it sounds as if you are describing "OpenCandy", which is just a PUP, not bad malware.

MBAM Premium is designed to run alongside all major AVs, and the Free version (no real-time protection) ought not to conflict, either.

Having said all that, some PUPs can be pesky to fully remove.

>>You don't happen to be able to replicate that behavior, so that you can post a screenshot here of the message dialog?

>>Or perhaps you can export the MBAM scan log as a *.txt file and attach it to your next reply here, so we can see what it found and removed (instructions for locating and exporting the log files are HERE)?


AVG Cloudcare re-activated itself. But 10 minutes without any antivirus running worried me. (AVG detected a MSIL Trojan Horse two days ago and neutered it.)

-- Is 10 minutes without any antivirus worrying? And what should I do next time?

2. AVG Cloudcare reported as in the attached image. I had installed Acronis, and uninstalled it about 6 weeks ago using its uninstall program. I know what a digital signature is (but not in detail). The file is Hidden. My system is 64 bit, not 32. I will never want Acronis.

--Should I simply delete the file?

Thanks.
We'll need to wait for someone more qualified with malware removal and more familiar with AVG, but that looks like an AVG false-positive, unrelated to MBAM.

Thanks,
No. I can't replicate it. I have no other PUPs left. But attached is the MBAM scan log as a .txt (well, saved from Notepad).

Thanks for the help.
 

Attachments

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Gigabyte ATX case with 500 W power supply GZ-M1
OS
Windows 7 Home Premium 64bit
CPU
Intel Pentium Edition G3220 3.0 GHz
Motherboard
Gigabyte Socket 1150 MicroATX Mot Ultra Durable, GA-H81M-S2H
Memory
8 GB DDR3 1600 MHz DIMM
Graphics Card(s)
Not Known
Sound Card
Not known
Monitor(s) Displays
Samsung LS24D590 23.6"
Screen Resolution
1920 x 1080
Hard Drives
256 GB Solid State Drive (C: on which Windows 7 is installed)-
1 TB internal conventional HD (X:)-
Two WD "Elements" " 2TB USB drives as backups
PSU
500 W
Case
Gigabyte ATX case
Cooling
Several fans!
Keyboard
Accuratus 301 USB Compact, white.
Mouse
Microsoft Basic Optical Mouse v2.0, two-button, tethered
Internet Speed
10 to 12 Mb per second
Antivirus
Kaspersky Internet Security 2016, Malwarebytes (paid)
Browser
Firefox (ocassionally Safari)
Other Info
The 256 GB SSD (C:) also has Adobe Photoshop CS6 and InDesign CS6, MS Office, Adobe Lightroom, and other small programs.
I would suggest running Malwarebytes again and make sure you have the rootkit option selected.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
After running MBAM, run AdwCleaner. This is excellent at finding and removing PUPS and BHOs.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Hp
OS
Windows 7 64 bit Professional
CPU
AMD A 8
Motherboard
Amd
Memory
16gb
Graphics Card(s)
On board
Hard Drives
Se agate 1 tv
Antivirus
Security
Stevekir and for all if it matters, my rule for any activity to be performed with AV turned off is to disconnect from the world. I'll update MBAM and AV, disable network connection the shut down the AV permanently so that I say when it is on. After running scans and reboot then bring everything back in reverse order. Never want to be caught with my AV off when connected to anything. Just saying that's how I do it, doesn't mean you should.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Microsoft Windows 7 Ultimate 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD FX(tm)-6100 Six-Core Processor
Motherboard
ASUSTeK Computer INC. M5A78L-M LX PLUS
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6450
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Monitor(s) Displays
Toshiba 47ZV650U 47" LCD 240Hz
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
(1) HDT722516DLA380 ATA Device (2) Hitachi HDS721025CLA382 ATA Device (3) ST4000VN000-1H4168 ATA Device (4) Generic STORAGE DEVICE USB Device (5) Generic STORAGE DEVICE USB Device (6) Generic STORAGE DEVICE USB Device (7) Generic STORAGE
PSU
Corsair CX430M
Case
WMI (Waste Management Incorporated)
Cooling
Yes, it's very cool.
Keyboard
Bluetooth KB & Mousepad
Internet Speed
Fios 15/5 and it sucks when Verizon is throttling it down
Antivirus
Avast, MSE and Malwarebytes
Browser
Firefox v.41.0.2 and IE 11
Other Info
2 years old and so far this rig still kicks butt
Back
Top