Jump to content

Malwarebytes

exile360

exile360

Member Since 14 Feb 2008
Offline Last Active Yesterday, 10:36 PM
*****

**Trojan.Downloader.ED**

15 April 2013 - 07:29 PM

As many of you are aware, we suffered a false positive earlier today which caused many of our users' systems to be rendered inoperable. The offending database was v2013.04.15.12, and was live for only 8 minutes.

We sincerely apologize for this false positive and an update was immediately pushed out to remove the offending definition that caused this.

------------------------------------------------------------------------------------------------------------------------------------------------

For Malwarebytes Anti-Malware Users:

Option A -- if your system can boot normally

Use the Malwarebytes Anti-Malware False Positive Fix Tool:
  • Make certain you are logged in as an administrator
  • Download the Malwarebytes Anti-Malware FP Fix Tool from here and save it to a convenient location such as your desktop
  • Extract all of the files to a folder and run RunThis.bat. NOTE: Windows Vista, Windows 7 and Windows 8 users must right-click on the file and choose Run as Administrator and click Yes or Continue to any User Account Control prompts
  • Restart your system and verify that it is now working properly
NOTE: There may be extra files in quarantine that will not be restored, though the system will be bootable. These are duplicate backup files and the files in question should already be restored.


Option B -- if your system cannot boot normally

Step 1: Boot into Safe Mode with Networking:

Windows XP:
  • Restart your computer.
  • When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with the Windows XP Advanced Options menu.
  • Select the option for Safe Mode with Networking using the arrow keys.
  • Then press Enter on your keyboard to boot into Safe Mode with Networking.
You should then be presented with the Windows XP Login screen. Log in to Windows and when it prompts you about Safe Mode and asks if you'd like to continue click Yes.


Windows Vista and Windows 7:
  • Restart your computer.
  • When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with the Windows Advanced Boot Options menu.
  • Select the option for Safe Mode with Networking using the arrow keys.
  • Then press Enter on your keyboard to boot into Safe Mode with Networking.
You should then be presented with the Windows Login screen. Log in to Windows.


Step 2: Use the Malwarebytes Anti-Malware False Positive Fix Tool:
  • Make certain you are logged in as an administrator
  • Download the Malwarebytes Anti-Malware FP Fix Tool from here and save it to a convenient location such as your desktop
  • Extract all of the files to a folder and run RunThis.bat. NOTE: Windows Vista, Windows 7 and Windows 8 users must right-click on the file and choose Run as Administrator and click Yes or Continue to any User Account Control prompts
  • Restart your system normally and verify that it is now working properly.
NOTE: There may be extra files in quarantine that will not be restored, though the system will be bootable. These are duplicate backup files and the files in question should already be restored.

------------------------------------------------------------------------------------------------------------------------------------------------

Malwarebytes Enterprise Edition Customers:
  • Within the console reinstall MBAM over the top (push install)
  • Use Windows tasks to execute the command (as admin): "C:\Program Files\Malwarebytes' Anti-Malware\mbamapi.exe" /quarantine -restore all
If the above failed, then you may also do the following

Use the Malwarebytes Anti-Malware False Positive Fix Tool:
  • Make certain you are logged in as an administrator
  • Download the Malwarebytes Anti-Malware FP Fix Tool from here and save it to a convenient location such as your desktop
  • Extract all of the files to a folder and run RunThis.bat. NOTE: Windows Vista, Windows 7 and Windows 8 users must right-click on the file and choose Run as Administrator and click Yes or Continue to any User Account Control prompts
  • Restart your system and verify that it is now working properly
------------------------------------------------------------------------------------------------------------------------------------------------

If you are still having a problem:

For those of you still having problems, please contact support via the following links and they will assist you directly in getting your systems functioning properly again:

Home User Support
Business Support

Please be sure to include the following information to expedite the repair process:
  • OS installed (i.e. XP, Vista, 7, 8 etc.)
  • Whether you have restarted your computer yet or not
  • Whether or not the system is bootable if you have attempted a restart of your system yet
  • Whether or not you have your Windows installation media (CD, DVD, recovery discs etc.)
We have also taken extensive measures to ensure that a false positive like this never happens again. Once more, I apologize that this occurred and hopefully we will be able to get everyone's systems in proper working order once more without too much trouble.

Thank you



Added 04/18/2013

Note for those that may require additional resources we have posted a new topic with various off site links to other possible resources of help. Computer Resources for Repair and Management

***False positive Trojan.Downloader.ED***

15 April 2013 - 07:24 PM

We sincerely apologize for this false positive. An update has already been pushed out to remove the offending definition that caused this.


If your system is bootable, then please do the following:

For Malwarebytes Anti-Malware Users:

NOTE: If Malwarebytes Anti-Malware will not run, then you should also install this file from Microsoft.

Step 1

Boot into Safe Mode with Networking:

Windows XP:

  • Restart your computer.
  • When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with the Windows XP Advanced Options menu.
  • Select the option for Safe Mode with Networking using the arrow keys.
  • Then press Enter on your keyboard to boot into Safe Mode with Networking.

You should then be presented with the Windows XP Login screen. Log in to Windows and when it prompts you about Safe Mode and asks if you'd like to continue click Yes.


Windows Vista and Windows 7:

  • Restart your computer.
  • When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with the Windows Advanced Boot Options menu.
  • Select the option for Safe Mode with Networking using the arrow keys.
  • Then press Enter on your keyboard to boot into Safe Mode with Networking.

You should then be presented with the Windows Login screen. Log in to Windows.


Step 2

  • Download the installer for Malwarebytes Anti-Malware from here and install it
  • Open Malwarebytes Anti-Malware and access the Quarantine tab
  • Click on the Restore All button and click Yes when prompted for confirmation
  • Restart your computer and allow it to start up normally


NOTE: There may be extra files in quarantine that will not be restored, though the system will be bootable. These are duplicate backup files and the files in question should already be restored.


Malwarebytes Enterprise Edition Customers:

  • Within the console reinstall MBAM over the top (push install)
  • Use Windows tasks to execute the command (as admin): "C:\Program Files\Malwarebytes' Anti-Malware\mbamapi.exe" /quarantine -restore all

If the above failed, then you may also do the following

Use the Malwarebytes Anti-Malware False Positive Fix Tool:

  • Make certain you are logged in as an administrator
  • Download the Malwarebytes Anti-Malware FP Fix Tool from here and save it to a convenient location such as your desktop
  • Extract all of the files to a folder and run RunThis.bat NOTE: Windows Vista, Windows 7 and Windows 8 users must right-click on the file and choose Run as Administrator and click Yes or Continue to any User Account Control prompts
  • Restart your system and verify that it is now working properly


For those of you still having problems, please contact support via the following links and they will assist you directly in getting your systems functioning properly again:

Home User Support
Business Support

Please be sure to include the following information to expedite the repair process:

  • OS installed (i.e. XP, Vista, 7, 8 etc.)
  • Whether you have restarted your computer yet or not
  • Whether or not the system is bootable if you have attempted a restart of your system yet
  • Whether or not you have your Windows installation media (CD, DVD, recovery discs etc.)

We have also taken extensive measures to ensure that a false positive like this never happens again. Once more, I apologize that this occurred and hopefully we will be able to get everyone's systems in proper working order once more without too much trouble.

***False positive Trojan.Downloader.ED***

15 April 2013 - 07:22 PM

As many of you are aware, we suffered a false positive earlier today which caused many of our users' systems to be rendered inoperable. The offending database was v2013.04.15.12, and was live for only 8 minutes.

We sincerely apologize for this false positive and an update was immediately pushed out to remove the offending definition that caused this.

------------------------------------------------------------------------------------------------------------------------------------------------

For Malwarebytes Anti-Malware Users:

Option A -- if your system can boot normally

Use the Malwarebytes Anti-Malware False Positive Fix Tool:
  • Make certain you are logged in as an administrator
  • Download the Malwarebytes Anti-Malware FP Fix Tool from here and save it to a convenient location such as your desktop
  • Extract all of the files to a folder and run RunThis.bat. NOTE: Windows Vista, Windows 7 and Windows 8 users must right-click on the file and choose Run as Administrator and click Yes or Continue to any User Account Control prompts
  • Restart your system and verify that it is now working properly
NOTE: There may be extra files in quarantine that will not be restored, though the system will be bootable. These are duplicate backup files and the files in question should already be restored.


Option B -- if your system cannot boot normally

Step 1: Boot into Safe Mode with Networking:

Windows XP:
  • Restart your computer.
  • When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with the Windows XP Advanced Options menu.
  • Select the option for Safe Mode with Networking using the arrow keys.
  • Then press Enter on your keyboard to boot into Safe Mode with Networking.
You should then be presented with the Windows XP Login screen. Log in to Windows and when it prompts you about Safe Mode and asks if you'd like to continue click Yes.


Windows Vista and Windows 7:
  • Restart your computer.
  • When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with the Windows Advanced Boot Options menu.
  • Select the option for Safe Mode with Networking using the arrow keys.
  • Then press Enter on your keyboard to boot into Safe Mode with Networking.
You should then be presented with the Windows Login screen. Log in to Windows.


Step 2: Use the Malwarebytes Anti-Malware False Positive Fix Tool:
  • Make certain you are logged in as an administrator
  • Download the Malwarebytes Anti-Malware FP Fix Tool from here and save it to a convenient location such as your desktop
  • Extract all of the files to a folder and run RunThis.bat. NOTE: Windows Vista, Windows 7 and Windows 8 users must right-click on the file and choose Run as Administrator and click Yes or Continue to any User Account Control prompts
  • Restart your system normally and verify that it is now working properly.
NOTE: There may be extra files in quarantine that will not be restored, though the system will be bootable. These are duplicate backup files and the files in question should already be restored.

------------------------------------------------------------------------------------------------------------------------------------------------

Malwarebytes Enterprise Edition Customers:
  • Within the console reinstall MBAM over the top (push install)
  • Use Windows tasks to execute the command (as admin): "C:\Program Files\Malwarebytes' Anti-Malware\mbamapi.exe" /quarantine -restore all
If the above failed, then you may also do the following

Use the Malwarebytes Anti-Malware False Positive Fix Tool:
  • Make certain you are logged in as an administrator
  • Download the Malwarebytes Anti-Malware FP Fix Tool from here and save it to a convenient location such as your desktop
  • Extract all of the files to a folder and run RunThis.bat. NOTE: Windows Vista, Windows 7 and Windows 8 users must right-click on the file and choose Run as Administrator and click Yes or Continue to any User Account Control prompts
  • Restart your system and verify that it is now working properly
------------------------------------------------------------------------------------------------------------------------------------------------

If you are still having a problem:

For those of you still having problems, please contact support via the following links and they will assist you directly in getting your systems functioning properly again:

Home User Support
Business Support

Please be sure to include the following information to expedite the repair process:
  • OS installed (i.e. XP, Vista, 7, 8 etc.)
  • Whether you have restarted your computer yet or not
  • Whether or not the system is bootable if you have attempted a restart of your system yet
  • Whether or not you have your Windows installation media (CD, DVD, recovery discs etc.)
We have also taken extensive measures to ensure that a false positive like this never happens again. Once more, I apologize that this occurred and hopefully we will be able to get everyone's systems in proper working order once more without too much trouble.

Thank you

A real life Transformer

02 December 2012 - 06:41 AM

One of the coolest things I've ever seen:

http://www.wimp.com/transformercar/

Follow Us