Solved Should malware removal programs be renamed for security reasons?

FranzB

New member
Local time
9:34 PM
Messages
208
On internet i have seen several times the advice to change the name by which a particular malware removal program is known since some malware recognizes the files
or the ---.exe and then prevents its installation onto an infected computer or its execution, even if the program was installed on the computer before the infection took place.
This was advised for TDSSKiller (tdss.exe should be renamed to e.g. whatever.com)
Malwarebytes AntiMalware should be renamed before using it on an infected computer.
See e.g.
How To Easily Remove Google Redirect Virus
www.usenetmessages.com/view.php?c=alternative&g=964&id=476887&p=C

Can anyone say anything about this? And should this also be done routinely with other malware removal programs? If that would really be necessary/advisable then why wouldn't the providers give you the choice of renaming by asking if you want to, or simply give you no choice but rename their product? Probably not many people would ever think of doing it themselves.
 

My Computer My Computer

Computer Manufacturer/Model Number
Acer Extensa 5235
OS
Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode
CPU
Intel Celeron 900 @2.2 GHz
Motherboard
Acer BA50-MV(U2E1)
Memory
DDR3 2048 Mbytes
Sound Card
Conexant HD Audio
I'm perhaps being rather cynical, but I'm very suspicious of articles that have a link to a 'registry cleaner' or any other so-called utility that claims to clean or speed up your computer.

I'm of the opinion that some of these can easily corrupt your registry or your system.

Microsoft Security Essentials along with Malwarebytes and ignoring suspicious web pages or links has kept my computer free of viruses so far.

As for renaming Malwarebytes, I certainly wouldn't do it. If the door is already open, the undesirable alien is already in and only its removal will suffice.

The door needs to be locked, not just have its name changed. :)
 
Last edited:

My Computer My Computer

Computer Manufacturer/Model Number
HP Pavilion Elite 495UK
OS
Windows 7 Ultimate SP1 64-Bit
CPU
Intel Core i7 870 @ 2.93GHz
Motherboard
MSI 2A9C (CPU1)
Memory
8Gb Dual-Channel DDR3 @ 664MHz
Graphics Card(s)
nVidia GeForce GTX 460 1024MB dedicated RAM
Sound Card
Realtek HD Audio
Monitor(s) Displays
HP2310i
Screen Resolution
1920 x 1080
Hard Drives
1x1954GB Hitachi HDS22020ALA 330 (RAID), 1x1954GB Hitachi External for backup and storage
PSU
460W
Case
HP Elite
Cooling
Air cooled
Keyboard
Logitech K750 solar-powered keyboard
Mouse
Logitech Wireless M180 mouse
Internet Speed
2Mb
Other Info
Pure Avanti Flow Internet Radio with iPod Dock, 64Gb iPod, HP USB Speakers, Sony MDR-V500 Headphones, Sony Vaio F-Series Laptop
I'm not a lawyer and I don't even play one on TV. So this is just personal opinion. :)

I think that most software companies (not just the antimalware companies) tend to err on the side of caution when it comes to their products. They "dumb down" their instructions, or lack thereof, to accomodate the average user. The default instructions apparently work for the vast majority of people. For those relatively few folks who need more advanced instructions, the specific product help forum, product customer support, or sites like this one provide additional ways to circumvent the malware.

I consider my computer knowledge to be slightly above average. I'll try using the software product "as is". If it doesn't work, then I'll dig into the bag of tricks I've learned for an alternate method. So I don't think it's necessary or advisable to routinely rename antimalware programs. IMHO.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
The only times you need to change the names of the anti-malware program's executable is in the specific instance where a virus prevents the running of a program based solely on the executables name. I do not see the point in doing it in the case discribed in the second link since the person already advised running MBAM in safe mode (ie virus probably won't be running anyways). Also, he left out what I consider to be an important step. You can download a stand-alone update for mbam which will update the database version to the newest one without having to go online. Viruses are becoming more advanced and can know what something is even if the executable is named differently, so that method is becoming less likely to work over time anyways.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba P775-S7100
OS
Windows 7 Professional SP1 64-bit
CPU
Intel Core i5-2450M @2.5 GHz
Memory
6 GB DDR3 1333MHz
Graphics Card(s)
Intel HD 3000
Monitor(s) Displays
Built-in 17.3" LED; 22" Insignia NS-L22Q-10A
Screen Resolution
1600x900; 1360x768
Hard Drives
750 GB Hitachi
1TB Seagate FreeAgent External
Internet Speed
Verizon DSL Speed(Down/Up): 3360 Kbps / 800 Kbps
Antivirus
MSE and MBAM Pro
Browser
IE10
Petey7 is correct:

The only times you need to change the names of the anti-malware program's executable is in the specific instance where a virus prevents the running of a program based solely on the executables name.
 

My Computer My Computer

OS
Windows 7 & Windows Vista Ultimate
Nice and to the point answer by petey7.
 

My Computer My Computer

Computer Manufacturer/Model Number
Sony VAIO VPCSB25FG/B
OS
Windows 7 Professional x32
CPU
Intel® Core™ i3-2310M Processor 2.10 GHz*1
Motherboard
Asus
Memory
4GB
Graphics Card(s)
AMD Radeon™ HD 6470M (SPEED MODE) / Intel® HD Graphics 3000
Sound Card
Intel® High Definition Audio
Monitor(s) Displays
13.3 (33.8cm) wide (WXGA: 1366x768) TFT colour display (VAIO
Screen Resolution
1366x768
Hard Drives
500 GB*4 (Serial ATA, 5400 rpm)
With thanks to all for your information and advice.
 

My Computer My Computer

Computer Manufacturer/Model Number
Acer Extensa 5235
OS
Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode
CPU
Intel Celeron 900 @2.2 GHz
Motherboard
Acer BA50-MV(U2E1)
Memory
DDR3 2048 Mbytes
Sound Card
Conexant HD Audio
Back
Top