Jump to content

Malwarebytes

MBAM new "*.sys" once after each malware removal

MBAM sys drive malware removal autorun once

7 replies to this topic

#1
sdasfjkd221

    New Member

  • Members
  • Pip
  • 46 posts
after removing a malware a new drive created, ex:

drive name      Publisher          path
ebxi                          c:\windows\system32\drivers\pktdpx.sys
gmrqy                      c:\windows\system32\drivers\cgpyout.sys


then mbam asks to restart to apply removal
Is that normal?
it seems every time a random drive name is created!! there is no publisher.

#2
daledoc1

    Forum Deity

  • Spam Hunters
  • PipPipPipPipPipPip
  • 7,757 posts
  • Gender:Not Telling
Hi:

Sorry to hear you might be infected.
We cannot work on malware removal in this sub-section of the forum, so please read below for assistance with cleaning your system.

IMPORTANT: Please do NOT use any temporary file cleaners unless instructed to do so - they can cause data loss, making recovery difficult.

IF YOU WOULD LIKE EXPERT HELP WITH MALWARE REMOVAL, PLEASE CHOOSE ONE OF THE FOLLOWING 3 OPTIONS:
OPTION 1: Free, one-on-one, expert assistance in the Malware Removal Forum.
OPTION 2: For licensed users of MBAM PRO, there is free, one-on-one, expert assistance from the MBAM support helpdesk.
OPTION 3: Fee-based, one-on-one, expert assistance from Premium Support.

OPTION 1:
  • When starting your new post, please note the following:
  • Please do NOT post in a topic started by someone else, even if their problem sounds similar.
  • Please COPY/PASTE the requested logs directly into your post, rather than attaching them.
  • Under options, please be sure to select "track this topic" and "immediate email notification", so you'll know when a helper responds.
  • Please be patient - it may be 48 hours or more before a helper can assist you, especially when the forum is very busy.
  • Please do NOT "bump" your topic or reply back to it for at least 48 hours.
  • Doing so may cause your topic to be overlooked, as it will appear that you are already being helped.
OPTION 2:
If you are a paid user of MBAM PRO and would like support via the helpdesk, please contact them here.

OPTION 3:
If you prefer the Malwarebytes Premium Services (comprehensive solutions to all your computer support needs – from installation and set-up to troubleshooting and tune-ups), please go to the Premium Support site here.

Please be patient – someone will assist you as soon as possible.

Thank you very much,

daledoc1
Just a home user & forum volunteer
DT1: Win7/Ult/64 SP1; Intel Core i7-3770 @3.4 GHz; 16 GB RAM; NVidia GeForce GT620; IE9; Fx 21.0; TB 17.0.6; Cable HSI; MBAM PRO 1.75.0.1300; KIS2013; SAS Free; CCleaner
DT2: Win7 Ult/64 SP1; Intel Core i7-860 @2.8 GHz; 8 GB RAM; ATI Radeon HD 5770; IE 9, Fx 21.0; TB 17.0.6; Cable HSI; MBAM PRO 1.75.0.1300; KIS2013; SAS Free; CCleaner.
LT: Win7 Pro/32 SP1; Intel Core 2 Duo @2.8 GHz; 4 GB RAM; NVIDIA Quadro NVS 160M; IE 9; Fx 21.0; TB 17.0.6; WLAN; MBAM PRO 1.75.0.1300; KIS2013; SAS Free; CCleaner.

#3
sdasfjkd221

    New Member

  • Members
  • Pip
  • 46 posts
wohhh, i am not infected

those .sys files are created only once after mbam remove anyfile
after restart those .sys files are no longer exist

#4
daledoc1

    Forum Deity

  • Spam Hunters
  • PipPipPipPipPipPip
  • 7,757 posts
  • Gender:Not Telling

View Postsdasfjkd221, on 17 August 2012 - 10:20 PM, said:

after removing a malware <snip>
then mbam asks to restart to apply removal
Is that normal?

I'm sorry that I misunderstood your question, since you twice mentioned "malware removal".

We'll need to wait for an MBAM staffer to provide a more specific answer to your question.

Thanks for your patience,

daledoc1
Just a home user & forum volunteer
DT1: Win7/Ult/64 SP1; Intel Core i7-3770 @3.4 GHz; 16 GB RAM; NVidia GeForce GT620; IE9; Fx 21.0; TB 17.0.6; Cable HSI; MBAM PRO 1.75.0.1300; KIS2013; SAS Free; CCleaner
DT2: Win7 Ult/64 SP1; Intel Core i7-860 @2.8 GHz; 8 GB RAM; ATI Radeon HD 5770; IE 9, Fx 21.0; TB 17.0.6; Cable HSI; MBAM PRO 1.75.0.1300; KIS2013; SAS Free; CCleaner.
LT: Win7 Pro/32 SP1; Intel Core 2 Duo @2.8 GHz; 4 GB RAM; NVIDIA Quadro NVS 160M; IE 9; Fx 21.0; TB 17.0.6; WLAN; MBAM PRO 1.75.0.1300; KIS2013; SAS Free; CCleaner.

#5
exile360

    exile

  • Administrators
  • PipPipPipPipPipPip
  • 15,087 posts
  • Gender:Male
Greetings :)

Those are the randomly named drivers that Malwarebytes Anti-Malware creates when performing a DoR (Delete on Reboot) in order to remove an infection. They're quite harmless.

If you need anything else, please let us know.

Thanks :)
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#6
daledoc1

    Forum Deity

  • Spam Hunters
  • PipPipPipPipPipPip
  • 7,757 posts
  • Gender:Not Telling

View Postexile360, on 18 August 2012 - 05:28 AM, said:

Greetings :)

Those are the randomly named drivers that Malwarebytes Anti-Malware creates when performing a DoR (Delete on Reboot) in order to remove an infection. They're quite harmless.

Thanks :)

That's what I thought. ;)
Thanks for the explanation! :)

daledoc1
Just a home user & forum volunteer
DT1: Win7/Ult/64 SP1; Intel Core i7-3770 @3.4 GHz; 16 GB RAM; NVidia GeForce GT620; IE9; Fx 21.0; TB 17.0.6; Cable HSI; MBAM PRO 1.75.0.1300; KIS2013; SAS Free; CCleaner
DT2: Win7 Ult/64 SP1; Intel Core i7-860 @2.8 GHz; 8 GB RAM; ATI Radeon HD 5770; IE 9, Fx 21.0; TB 17.0.6; Cable HSI; MBAM PRO 1.75.0.1300; KIS2013; SAS Free; CCleaner.
LT: Win7 Pro/32 SP1; Intel Core 2 Duo @2.8 GHz; 4 GB RAM; NVIDIA Quadro NVS 160M; IE 9; Fx 21.0; TB 17.0.6; WLAN; MBAM PRO 1.75.0.1300; KIS2013; SAS Free; CCleaner.

#7
sdasfjkd221

    New Member

  • Members
  • Pip
  • 46 posts
thx, i thought that, but want to make sure.

:D
:D

#8
exile360

    exile

  • Administrators
  • PipPipPipPipPipPip
  • 15,087 posts
  • Gender:Male
You're welcome, I'm glad I could help :).
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us