Malwarebytes and Safe mode

jav

Security Enthusiast
Guru
Local time
10:41 PM
Messages
713
ok, guys. I know I am not the one who should tell it to you as the are lots of people more knowledgeable then me.

But I have seen this happening here and many other security forums (and not just once :( ) and I was doing the same in the past, so just to inform you.

Many of us while helping user who is infected or suspected to be infected recommend them to use our trusty Malwarebytes Anti Malware but at the same time most of us recommend to use it in safe mode.
Theoretically it is great, as safe mode loads only basic drivers and applications so there will be less things (or even malware) to interact with MBAM scan.

But no, it's not recommended to run Malwarebytes in safe mode unless normal mode fails.

Just take a look at those thread, they are from official Malwarebytes forum and aswered by their staff.
And all of them against running Malwarebytes in safe mode unless normal mode fails:
Running MBAM in Safe Mode - Malwarebytes Forum
Should i run MalwareBytes in normal or in safe mode? - Malwarebytes Forum
Should I run Malwarebytes in Safe mode? - Malwarebytes Forum
Safe Mode vs Normal Mode - Malwarebytes Forum
SAFE MODE - Malwarebytes Forum
`Safe Mode` or `Normal Mode` - Malwarebytes Forum

Some quotes:
nosirrah said:
MBAM works from safemore but it is not designed to work that way .

MBAM will work better from regular mode both in terms of what it detects and what it can remove .

Doing a safemode scan with MBAM should only be done when a regular mode scan fails .
exile360 said:
The drivers don't load in safe mode which really hinders MBAM's capabilities. If possible I and others always recommend running it in normal mode. If the scans are taking so long though, I'm guessing you're also using the Full Scan option. This is seldom required as it generally won't detect anything that the Quick Scan doesn't pick up except perhaps minor traces that are harmless (and even that is rare and I've never seen it do so myself).

So just let you know.
;)
 

My Computer

OS
Windows 7 Ultimate x86 SP1
I have used MB in safe mode (with networking) many times. It's recommended on "bleeping" I know that.

Nice links, but it's always worked fine for me. It's depends on what you're infected with I suppose.
 

My Computer

Computer Manufacturer/Model Number
Keeps changing - (Custom)
OS
Windows 7 Professional x64
CPU
Intel Core i7 860
Motherboard
Gigabyte GA-P55-UD4P
Memory
4GB DDR3 Mushkin 1600Mhz @ 7-8-7-20
Graphics Card(s)
MSI GTS250 1GB DDR3 Twin Frozr
Sound Card
Onboard realtek
Monitor(s) Displays
Samsung SyncMaster 24" P2450 + Samsung 20" 2033
Screen Resolution
1920 X 1080 and 1600 X 900 (#2 system 1440 X 900)
Hard Drives
Patriot Inferno 120GB SSD + 3 WD Blue 640GB drives
PSU
Corsair 750 HX Modular
Case
Lancool PC-K62
Cooling
Cooler Master TX3 CPU cooler and 4-140mm and 1-120mm case
Keyboard
Gigabyte USB keyboard
Mouse
Microsoft wireless laser mouse 5000
Internet Speed
7 Mb down 1.5 up
Other Info
System #2: AMD Phenom II X6 1055T (Freezer 7 Pro cooler) - Gigabyte 880GMA-UD2H - WD 500GB Black - 9500GT (1GB) 500W OCZ modular PSU - Antec 200 case. System #3 (LapTop) Core 2 Duo T6670 - 320GB 7200RPM HD - 4GB DDR3 RAM.
Actually I am not saying that it doesn't work in safe mode.

As you can read from quotes and posts in Malwarebytes,
They say Malwarebytes can work on safe mode, but it works better on normal mode both from detection and removal point of view.
 

My Computer

OS
Windows 7 Ultimate x86 SP1
What if safe mode is the only option (for boot up)? Will MWB not function as it should?
 

My Computer

OS
Windows XP - Now Windows 7 Home Premium (64-bit).
Actually I am not saying that it doesn't work in safe mode.

As you can read from quotes and posts in Malwarebytes,
They say Malwarebytes can work on safe mode, but it works better on normal mode both from detection and removal point of view.

Yea, that's good to know. Thanks for the tip man!
 

My Computer

Computer Manufacturer/Model Number
Keeps changing - (Custom)
OS
Windows 7 Professional x64
CPU
Intel Core i7 860
Motherboard
Gigabyte GA-P55-UD4P
Memory
4GB DDR3 Mushkin 1600Mhz @ 7-8-7-20
Graphics Card(s)
MSI GTS250 1GB DDR3 Twin Frozr
Sound Card
Onboard realtek
Monitor(s) Displays
Samsung SyncMaster 24" P2450 + Samsung 20" 2033
Screen Resolution
1920 X 1080 and 1600 X 900 (#2 system 1440 X 900)
Hard Drives
Patriot Inferno 120GB SSD + 3 WD Blue 640GB drives
PSU
Corsair 750 HX Modular
Case
Lancool PC-K62
Cooling
Cooler Master TX3 CPU cooler and 4-140mm and 1-120mm case
Keyboard
Gigabyte USB keyboard
Mouse
Microsoft wireless laser mouse 5000
Internet Speed
7 Mb down 1.5 up
Other Info
System #2: AMD Phenom II X6 1055T (Freezer 7 Pro cooler) - Gigabyte 880GMA-UD2H - WD 500GB Black - 9500GT (1GB) 500W OCZ modular PSU - Antec 200 case. System #3 (LapTop) Core 2 Duo T6670 - 320GB 7200RPM HD - 4GB DDR3 RAM.
What if safe mode is the only option (for boot up)? Will MWB not function as it should?

That's right, if you read some of those posts, they say it cripples it.
 

My Computer

Computer Manufacturer/Model Number
Keeps changing - (Custom)
OS
Windows 7 Professional x64
CPU
Intel Core i7 860
Motherboard
Gigabyte GA-P55-UD4P
Memory
4GB DDR3 Mushkin 1600Mhz @ 7-8-7-20
Graphics Card(s)
MSI GTS250 1GB DDR3 Twin Frozr
Sound Card
Onboard realtek
Monitor(s) Displays
Samsung SyncMaster 24" P2450 + Samsung 20" 2033
Screen Resolution
1920 X 1080 and 1600 X 900 (#2 system 1440 X 900)
Hard Drives
Patriot Inferno 120GB SSD + 3 WD Blue 640GB drives
PSU
Corsair 750 HX Modular
Case
Lancool PC-K62
Cooling
Cooler Master TX3 CPU cooler and 4-140mm and 1-120mm case
Keyboard
Gigabyte USB keyboard
Mouse
Microsoft wireless laser mouse 5000
Internet Speed
7 Mb down 1.5 up
Other Info
System #2: AMD Phenom II X6 1055T (Freezer 7 Pro cooler) - Gigabyte 880GMA-UD2H - WD 500GB Black - 9500GT (1GB) 500W OCZ modular PSU - Antec 200 case. System #3 (LapTop) Core 2 Duo T6670 - 320GB 7200RPM HD - 4GB DDR3 RAM.
What if safe mode is the only option (for boot up)? Will MWB not function as it should?

If normal mode fails and your only option is safe mode, you should go with safe mode.

It will function as it should, but still it's functionality will be more limited then normal mode.

1. So your choice will be normal mode (number one priority)
2. If number one fails, safe mode
3. try normal mode again after safe mode cleaning (atleast do quick scan)

Yea, that's good to know. Thanks for the tip man!


no problems. ;)
 

My Computer

OS
Windows 7 Ultimate x86 SP1
Thanks jav :)
 

My Computer

OS
Windows XP - Now Windows 7 Home Premium (64-bit).
It is also not necessary to run a Full Scan. Malwarebytes' developers recommend a Quick Scan:

As Marcin said here
The full scan is very thorough, but 99.99% not necessary.
or as Bruce said here:
BTW , full scan has 0 ability to catch live malware and only a slight chance of catching traces
There are other examples by Marcin and Bruce, but you get the picture. For a first-time cleanup scan with MBAM, a full scan is fine. However, for "live malware", all that is needed is a quick scan.

It is also recommended that temp files be cleaned first -- actually a good practice regardless of the anti-malware software being used.
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Yes, thanks Corrine for that. Temp files? Will ccleaner suffice?
 

My Computer

OS
Windows XP - Now Windows 7 Home Premium (64-bit).
Yes, CCleaner will work. My recommendation is to leave the registry section alone though -- too much of a chance of problems. Although based on an old version of CCleaner, I put this recommendation together for someone I was helping showing my preferences and explaining why some of the areas were not recommended: Tidbits: CCleaner
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Thanks for that Corrine, and what a lovely guide that is :)
 

My Computer

OS
Windows XP - Now Windows 7 Home Premium (64-bit).
It is also not necessary to run a Full Scan. Malwarebytes' developers recommend a Quick Scan:

As Marcin said here
The full scan is very thorough, but 99.99% not necessary.
or as Bruce said here:
BTW , full scan has 0 ability to catch live malware and only a slight chance of catching traces
There are other examples by Marcin and Bruce, but you get the picture. For a first-time cleanup scan with MBAM, a full scan is fine. However, for "live malware", all that is needed is a quick scan.

It is also recommended that temp files be cleaned first -- actually a good practice regardless of the anti-malware software being used.

I have used Malwarebytes to remove a lot of nasties for people & have found everything detected has been picked up in a quick scan.

I have run full scans after the fact and always come back clean. :)

Edit; BTW thank you Jav for the initial Post
 

My Computer

Computer Manufacturer/Model Number
Hewlett Packard Compaq Presario CQ60-305au
OS
Windows Seven Home Premium 32bit SP1
CPU
AMD Athlon QI46 2.1Ghz
Motherboard
Wistron 303c
Memory
2048 Mb DDR2 SD RAM
Graphics Card(s)
NVidea GE GoForce 8200M G/256mb dedicated graphics memory
Sound Card
MCP78S NVidea high definition
Monitor(s) Displays
15.6" High definition Brightview Widescreen
Screen Resolution
1336x768
Hard Drives
Toshiba MK2555GSX ATA
You are all welcome :)
 

My Computer

OS
Windows 7 Ultimate x86 SP1
Back
Top