Help - Search - Members - Calendar
Full Version: malwarebytes will not start
Malwarebytes Forum > Computer Help > Malware Removal - HijackThis Logs
dave k
If I try to click on malwarbytes.org site my browser shuts down. If I try to go to other suggeted sites for downloads [microsoft] the browser shuts down as soon as I click the link. Spybot and Trend Micro find very little but neither will update. I downloaded mbam software to a stick and loaded it onto my computer. This will not load and run. Since my home computer is useless for accessing your site my responses to your suggestions may be slow, but I will try them. Thanks
Maurice Naggar
Hello Dave and welcome to MalwareBytes forums.

You will need to continue to download tools using another pc, until this one is better and able to connect to internet.
Ideally download and burn to CD/DVD and transport to infected pc, and copy to the Desktop each tool.
Wish you had mentioned with flavor of Windows this is.
IF XP, then
Set Windows to show all files and all folders.
On your Desktop, double click My Computer, from the menu options, select tools, then Folder Options, and then select VIEW Tab and look at all of settings listed.

"CHECK" (turn on) Display the contents of system folders.

Under column, Hidden files and folders----choose ( *select* ) Show hidden files and folders.
Next, un-check Hide extensions for known file types.
Next un-check Hide protected operating system files.

IF Vista, then
Show all files:
  • Click the Start button, and then click Computer.
  • On the Organize menu, click Folder and Search Options.
  • Click the View tab.
  • Locate and uncheck Hide file extensions for known file types.
  • Locate and uncheck Hide protected operating system files (Recommended).
  • Locate and click Show hidden files and folders.
  • Click Apply > OK.

Next, Take out the trash (temporary files & temporary internet files)
Please download ATF Cleaner by Atribune, saving it to your desktop. It is used to cleanout temporary files & temp areas used by internet browsers.
Start ATF-Cleaner.exe to run the program.

Under Main choose: Select All

Click the Empty Selected button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose: Select All

Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser, do this also:
Click Opera at the top and choose: Select All

Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.
ATF-Cleaner should be run per the above in every user-login account {User Profile}
=


Now, locate your Malwarebytes AntiMalware mbam.exe and RENAME it to Bravo.exe
Start your Bravo.
Click the Settings Tab. Make sure all option lines have a checkmark.
Click the Update tab. Press the "Check for Updates" button.

When done, click the Scanner tab.
Do a Quick Scan.

Next, using My Computer {Windows Explorer}
look at the folder here
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
and RENAME HijackThis.exe to Sierra.exe

RE-Enable your AntiVirus and AntiSpyware applications.

Now, start Sierra (the renamed HijackThis) , and Do a Scan and Save the log.

Reply with a copy of the latest MBAM log
and the latest HijackThis log
and tell me, How is your system now ?

Be sure to Preview your reply. If all does not fit in one reply, use a 2nd or 3rd reply if needed.
Do NOT attach the reports, but copy and paste them in-line.
Use the ADDReply button to initiate the reply.

Do NOT use this pc to do any casual websurfing of any sort when it finally can connect !!
dave k
QUOTE (Maurice Naggar @ Apr 25 2009, 02:14 PM) *
Hello Dave and welcome to MalwareBytes forums.

You will need to continue to download tools using another pc, until this one is better and able to connect to internet.
Ideally download and burn to CD/DVD and transport to infected pc, and copy to the Desktop each tool.
Wish you had mentioned with flavor of Windows this is.
IF XP, then
Set Windows to show all files and all folders.
On your Desktop, double click My Computer, from the menu options, select tools, then Folder Options, and then select VIEW Tab and look at all of settings listed.

"CHECK" (turn on) Display the contents of system folders.

Under column, Hidden files and folders----choose ( *select* ) Show hidden files and folders.
Next, un-check Hide extensions for known file types.
Next un-check Hide protected operating system files.

IF Vista, then
Show all files:
  • Click the Start button, and then click Computer.
  • On the Organize menu, click Folder and Search Options.
  • Click the View tab.
  • Locate and uncheck Hide file extensions for known file types.
  • Locate and uncheck Hide protected operating system files (Recommended).
  • Locate and click Show hidden files and folders.
  • Click Apply > OK.

Next, Take out the trash (temporary files & temporary internet files)
Please download ATF Cleaner by Atribune, saving it to your desktop. It is used to cleanout temporary files & temp areas used by internet browsers.
Start ATF-Cleaner.exe to run the program.

Under Main choose: Select All

Click the Empty Selected button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose: Select All

Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser, do this also:
Click Opera at the top and choose: Select All

Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.
ATF-Cleaner should be run per the above in every user-login account {User Profile}
=


Now, locate your Malwarebytes AntiMalware mbam.exe and RENAME it to Bravo.exe
Start your Bravo.
Click the Settings Tab. Make sure all option lines have a checkmark.
Click the Update tab. Press the "Check for Updates" button.

When done, click the Scanner tab.
Do a Quick Scan.

Next, using My Computer {Windows Explorer}
look at the folder here
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
and RENAME HijackThis.exe to Sierra.exe

RE-Enable your AntiVirus and AntiSpyware applications.

Now, start Sierra (the renamed HijackThis) , and Do a Scan and Save the log.

Reply with a copy of the latest MBAM log
and the latest HijackThis log
and tell me, How is your system now ?

Be sure to Preview your reply. If all does not fit in one reply, use a 2nd or 3rd reply if needed.
Do NOT attach the reports, but copy and paste them in-line.
Use the ADDReply button to initiate the reply.

Do NOT use this pc to do any casual websurfing of any sort when it finally can connect !!
dave k
Hi Maurice,
Thanks. I'll try this.
Dave
Maurice Naggar
Dave,
When making a reply, press the ADDREPLY button to initiate the response and not the others.
and then review using the Preview Post to review, before pressing Add Reply

It is easier all around if you do not quote the prior post.
dave k
Hi Maurice,
I was able to get through 1 screen before the program shut down.
I have 2 computers that are recent builds. Both run XP, and I'm tying to use Firefox as a browser on both. On Saturday I was able get rid of the problem on 1 computer. I used the 'System Restore' tool in Windows. [I didn't see a response from anyone at your organization so thought I should keep plugging along.] I am now getting updates for Trend Micro, Spybot and mbam. The problem with this was I had to reload software, and freeware. I prefer a more elegant solution where I don't have to reload software and drivers.
I'm willing to work through any solution you have if you think it will work. I'll spare you the details of what I did unless your professional curiosity needs to know.
Thanks
Dave
Maurice Naggar
Dave,
Let's keep this thread about "this pc". I just want yout to try to run MBAM the way I suggest and the HijackTHis as outlined. Hold off on Spybtot (if you are doing this pc).

Now then, for any other pc with a suspect malware issue, open a separate thread after doing the required preliminaries, please.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.