Jump to content

Malwarebytes

Remove Selected - What happens?


16 replies to this topic

#1
sergelepine

    New Member

  • Members
  • Pip
  • 21 posts
Once the Scan is completed, what happens to the infected file is "Remove Selected" is chosen? Will the infected file be deleted or quarantine?

Serge

#2
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
A copy is made to the quarantine and then it is either immediately removed or removed on reboot.

:D
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#3
sergelepine

    New Member

  • Members
  • Pip
  • 21 posts
After 2 days, considering if it was a false positive, I finally decided to click on "Remove Selected". I do not know if a copy went to quarantine or not but "Adware.MyWebSearch" was immediately removed. I ran malwarebytes again, no spyware was found.

Thanks

Serge

View PostRubbeR DuckY, on Aug 16 2008, 06:39 AM, said:

A copy is made to the quarantine and then it is either immediately removed or removed on reboot.

:D


#4
melboy

    True Member

  • Experts
  • PipPipPipPip
  • 290 posts
Serge,

Open MBAM, click on the quarantine tab. Do you see the file you had MBAM remove there?

You will see options Delete, delete all, restore, restore all. As Rubber Ducky said , copy's of files MBAM removes/deletes are sent to quarantine. Whilst in quarantine it (the copy of the original file) can do no harm to your pc. If at a later date you find MBAM has removed/deleted a legitimate file (a false positive), it can be restored from quarantine back to your pc, by clicking the restore button. If however, you know for certain that it is a malicious file then choosing delete, deletes it for good, and cannot then be restored.

Hope this helps. :D

#5
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
Even better, the copies in the quarantine are renamed, encrypted and password protected. Even if somebody attempted to run a file it would error.
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#6
sergelepine

    New Member

  • Members
  • Pip
  • 21 posts

View PostRubbeR DuckY, on Aug 16 2008, 09:24 PM, said:

Even better, the copies in the quarantine are renamed, encrypted and password protected. Even if somebody attempted to run a file it would error.


Thanks for the info.

Now how do I delete all these messages in my in box?

Serge

#7
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
Click the quarantine tab and click delete all.
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#8
sergelepine

    New Member

  • Members
  • Pip
  • 21 posts
My question was: "Now, how do I delete all these messages in my in box?" The reply does not seem to match my question.
This board has a hard learning curve.

Serge


Thanks for your Help!


View PostRubbeR DuckY, on Aug 17 2008, 08:04 PM, said:

Click the quarantine tab and click delete all.


#9
JeanInMontana

    Delete this account!!

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,867 posts
  • Interests:would love to see some honesty around this site.
Open the program and you will see several tabs. Quarantine is one. You might want to have someone have a look at your logs too, after you follow the instructions here http://www.malwarebytes.org/forums/index.p...;st=0#entry9894 and start your own topic.

#10
sergelepine

    New Member

  • Members
  • Pip
  • 21 posts
I did follow your instructions from your previous message. I submitted the 3 logs as requested on 17 Aug 08. I did start a new topic. Did I place the logs in the wrong forum? I do not know.

Should I re-submit them if so where?

Serge




View PostJeanInMontana, on Aug 19 2008, 08:28 PM, said:

Open the program and you will see several tabs. Quarantine is one. You might want to have someone have a look at your logs too, after you follow the instructions here http://www.malwarebytes.org/forums/index.p...;st=0#entry9894 and start your own topic.


#11
melboy

    True Member

  • Experts
  • PipPipPipPip
  • 290 posts

View Postsergelepine, on Aug 19 2008, 09:04 PM, said:

My question was: "Now, how do I delete all these messages in my in box?" The reply does not seem to match my question.


Serge,

Was this question specifically about MBAM, or your E-mail inbox ?

#12
JeanInMontana

    Delete this account!!

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,867 posts
  • Interests:would love to see some honesty around this site.

View Postsergelepine, on Aug 20 2008, 03:09 AM, said:

I did follow your instructions from your previous message. I submitted the 3 logs as requested on 17 Aug 08. I did start a new topic. Did I place the logs in the wrong forum? I do not know.

Should I re-submit them if so where?

Serge

I see your thread, you need to update MBAM, it's at version 1.25 now and post a new log from it for Tigger to see, and a new HJT log. Also as melboy has asked, are you referring to your email inbox as well as your quarantine folder?

#13
sergelepine

    New Member

  • Members
  • Pip
  • 21 posts
The answer required is for the E-mail in box.

My mistake the first question had been answered. I should have started a new topic.

Thanks

Serge


View Postmelboy, on Aug 20 2008, 11:58 AM, said:

Serge,

Was this question specifically about MBAM, or your E-mail inbox ?


#14
JeanInMontana

    Delete this account!!

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,867 posts
  • Interests:would love to see some honesty around this site.
OK what type of email do you use? Web Mail, OutLook? Every email will have a delete option on it.

#15
sergelepine

    New Member

  • Members
  • Pip
  • 21 posts
Forget the question. It was in In Box on this board. It is ok there nothing in it.

Serge


View PostJeanInMontana, on Aug 20 2008, 09:35 PM, said:

OK what type of email do you use? Web Mail, OutLook? Every email will have a delete option on it.


#16
Bill Castner

    New Member

  • Members
  • Pip
  • 1 posts

View PostRubbeR DuckY, on Aug 16 2008, 05:24 PM, said:

Even better, the copies in the quarantine are renamed, encrypted and password protected. Even if somebody attempted to run a file it would error.

The problem is that for an OPs notebook computer I have been working with, Quarantining this file renders the keyboard unusable (it acts as if the Special Function key was being held down). It would have helped if the files were not encrypted and password protected; or if a "back door" in the form of a Command Line alternative for restoring a file from Quarantine was provided. Then one could programmatically restore rather than depend only on a now inaccessible GUI.

I understand the concern -- I too have seen things run from anti-malware Quarantine folders even if renamed. (This issue underlies, for example, the Deckard Scan issue with TDSSSERV and the file advapi32.dll). But a "backdoor" for a Restore would be an idea worth consideration.

Best regards to all for a wonderful tool and a simply great job by all at Malwarebytes,
Bill Castner

#17
Jarro

    New Member

  • Members
  • Pip
  • 13 posts

View Postmelboy, on Aug 16 2008, 11:37 AM, said:

Serge,

Open MBAM, click on the quarantine tab. Do you see the file you had MBAM remove there?

You will see options Delete, delete all, restore, restore all. As Rubber Ducky said , copy's of files MBAM removes/deletes are sent to quarantine. Whilst in quarantine it (the copy of the original file) can do no harm to your pc. If at a later date you find MBAM has removed/deleted a legitimate file (a false positive), it can be restored from quarantine back to your pc, by clicking the restore button. If however, you know for certain that it is a malicious file then choosing delete, deletes it for good, and cannot then be restored.

Hope this helps. :D


View PostRubbeR DuckY, on Aug 16 2008, 09:24 PM, said:

Even better, the copies in the quarantine are renamed, encrypted and password protected. Even if somebody attempted to run a file it would error.

Wow this makes me feel safe.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us