Jump to content

How Do I Uninstall MB Anti-Rootkit BETA?


Recommended Posts

  • Staff

Hello, walc and welcome to the forums.

Malwarebytes Anti-Rootkit (MBAR) is a standalone product and does not install in the typical sense. When you are done using it, all you need to do is delete the executable you downloaded, as well as the \mbar folder created during the self-extraction routine when you first run the downloaded file. The mbar folder is typically created on your desktop.

Link to post
Share on other sites

  • 5 months later...

Hi

 

Have also this problem

 

Can,t uninnstall / delete mbar.

 

Can delete the desktop button, and some of the downloaded material.

 

But can,t delete a folder called mbar.

 

In this folder there are files like:

 

data, plugins, Languages, imagesformates, licence, logs, and many more files.

 

Can,t delete these With fileassins or lockhunter.

Link to post
Share on other sites

Have restartet several times.

 

Because I wanted to start up in safe mode - With using F8

 

That was impossible - couldn,t start in safe mode.

 

Using another pc than I have listed - cant change that in my profile.

 

 

Using MS Windows 7 64 bit SP1

 

Intel core i7 3930K CPU @ 3,20 GHz

 

16 GB RAM

 

NVIDIA GEFORCE GT 640

 

Samsung 840 SSD 128GB

 

2TB spinning disk

 

I think I have used this pc in safe mode earlier - it,s bought Januar 2013

Link to post
Share on other sites

Have also tried to give the folder and files another names without Luck.

 

Have tried to delete these files one by one without Luck.

 

Got the Message that only administrator can delete or make changes.

 

But do not know how to use the administrator

Link to post
Share on other sites

The log:

========================================

User Account type: Administrator

OS: Windows 7 Service Pack 1 Service Pack 1 64 bit Operating System

Current Build Number: 7601

Current Version Number: 6.1

Current CSDVersion: Service Pack 1

Malwarebytes Anti-Malware: 2.0.2.1012

Installed On: 2014/05/31

Malware Database: 2014.06.04.04

Rootkit Database: 2014.06.02.01

Remediation Database: 2013.10.16.01

IP Database: 0000.00.00.00

Domain Database: 0000.00.00.00

License: Premium

Malware Protection: 4 (The service is running.)

Malicious Website Protection: 1 (The service is not running.)

Chameleon: 4 (The service is running.)

Log Created: 2014/06/04 14:10:43

Compatibility Flag Settings:

=================================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\appCompatFlags\Layers

Malwarebytes Anti-Malware Shell Extension Block Check:

======================================================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked:

MBAM Startup Entries:

=====================

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Malwarebytes Anti-Malware Service and Driver Status:

=======================================================

--------------Driver File Info:--------------

C:\windows\system32\drivers\mbam.sys

File Size: 25816 BYTES FileVersion: 0.1.13.0 MD5: [f92b0e478c0faa6d6661e6e977247e60]

C:\windows\system32\drivers\mwac.sys

File Size: 63704 BYTES FileVersion: 1.0.1.0 MD5: [15e8abc06843672955ce26a009533bad]

C:\windows\system32\drivers\mbamswissarmy.sys

File Size: 122584 BYTES FileVersion: 0.1.7.0 MD5: [8a50d5304e6ae48664cf5838ec32f647]

C:\windows\system32\drivers\mbamchameleon.sys

File Size: 91352 BYTES FileVersion: 1.0.4.0 MD5: [9d9ed48f841ea37aa5310d54b9e5d3c7]

--------------MBAMProtector:--------------

Type: 2

State: 4 (The service is running.) (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)

WIN32_EXIT_CODE: 0

SERVICE_EXIT_CODE: 0

CHECKPOINT: 0

WAIT_HINT: 0

--------------MBAMService:--------------

Type: 16

State: 4 (The service is running.)

WIN32_EXIT_CODE: 0

SERVICE_EXIT_CODE: 0

CHECKPOINT: 0

WAIT_HINT: 0

--------------MBAMScheduler:--------------

Type: 16

State: 4 (The service is running.)

WIN32_EXIT_CODE: 0

SERVICE_EXIT_CODE: 0

CHECKPOINT: 0

WAIT_HINT: 0

--------------MBAMChameleon:--------------

Type: 2

State: 4 (The service is running.) (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)

WIN32_EXIT_CODE: 0

SERVICE_EXIT_CODE: 0

CHECKPOINT: 0

WAIT_HINT: 0

--------------MBAMWebAccessControl:--------------

Type: 1

State: 1 (The service is not running.) (State is stopped)

WIN32_EXIT_CODE: 0

SERVICE_EXIT_CODE: 0

CHECKPOINT: 0

WAIT_HINT: 0

Required Dependencies:

======================

--------------BFE:--------------

Type: 32

State: 4 (The service is running.)

WIN32_EXIT_CODE: 0

SERVICE_EXIT_CODE: 0

CHECKPOINT: 0

WAIT_HINT: 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE

DisplayName REG_SZ @%SystemRoot%\system32\bfe.dll,-1001

Group REG_SZ NetworkProvider

ImagePath REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork

Description REG_SZ @%SystemRoot%\system32\bfe.dll,-1002

ObjectName REG_SZ NT AUTHORITY\LocalService

ErrorControl REG_DWORD 1

Start REG_DWORD 2

Type REG_DWORD 32

DependOnService REG_MULTI_SZ RpcSs

ServiceSidType REG_DWORD 3

RequiredPrivileges REG_MULTI_SZ SeAuditPrivilege

FailureActions REG_BINARY Binary Data

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE\Parameters

ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\bfe.dll

ServiceDllUnloadOnStop REG_DWORD 1

ServiceMain REG_SZ BfeServiceMain

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE\Parameters\Policy

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE\Parameters\Policy\BootTime

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE\Parameters\Policy\BootTime\Filter

{dc95b53e-01cf-4058-821d-350b3d0d4676}REG_BINARY Binary Data

{2dd96961-5757-434f-b617-34e732517c0e}REG_BINARY Binary Data

{2db25e6c-f07a-44f4-b6c8-50a330d2790b}REG_BINARY Binary Data

{c42f1cd6-3a95-4ae2-a513-793c3ae610c7}REG_BINARY Binary Data

{0c41d586-9c19-4e01-9d66-b5b98a97576e}REG_BINARY Binary Data

{12c38916-82ac-4737-8f38-b6957ffebad6}REG_BINARY Binary Data

{c970a45d-57f9-4e32-a5bd-886a9662641e}REG_BINARY Binary Data

{0c3be01b-fe70-4cc4-89dc-c07996b67e6d}REG_BINARY Binary Data

{074f7f68-ee10-428a-89d1-ba78f6c327ca}REG_BINARY Binary Data

{c016105c-eb34-4519-a5fd-5f4e4ad4d18e}REG_BINARY Binary Data

{a47525e2-725b-4888-8af1-ba5a60c04f4d}REG_BINARY Binary Data

{0ccc96a3-8c5c-45e2-b80e-7e37b16cc1ad}REG_BINARY Binary Data

{935b7f48-0ede-44dd-9bc2-e00bb635cda3}REG_BINARY Binary Data

{941dad9d-7b1a-4354-997b-00cf1aa9b35c}REG_BINARY Binary Data

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE\Parameters\Policy\Persistent

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE\Parameters\Policy\Persistent\Callout

{22001ee0-8e87-4f75-ba58-248f5918a63a}REG_BINARY Binary Data

{79f2a265-b693-4cc9-b480-cbcd87bd4747}REG_BINARY Binary Data

{c4b50f21-503e-4d7a-abd4-ed0a823a2453}REG_BINARY Binary Data

{91e902db-2cef-4040-b8e2-02fe4fd49c25}REG_BINARY Binary Data

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE\Parameters\Policy\Persistent\Filter

{dc95b53e-01cf-4058-821d-350b3d0d4676}REG_BINARY Binary Data

{f444c576-6e60-4ea2-9faa-80d57ed12cd2}REG_BINARY Binary Data

{0c41d586-9c19-4e01-9d66-b5b98a97576e}REG_BINARY Binary Data

{12c38916-82ac-4737-8f38-b6957ffebad6}REG_BINARY Binary Data

{c970a45d-57f9-4e32-a5bd-886a9662641e}REG_BINARY Binary Data

{0c3be01b-fe70-4cc4-89dc-c07996b67e6d}REG_BINARY Binary Data

{4d9581d2-aef8-4993-84cd-b986ced80d42}REG_BINARY Binary Data

{be7cbdf4-b192-4aa5-94f8-1fb5c5ee07bc}REG_BINARY Binary Data

{716b48eb-0a35-4a76-92ab-1d987230d288}REG_BINARY Binary Data

{1165065e-4996-4338-abaf-4b8556b4d431}REG_BINARY Binary Data

{07a24961-a760-4e80-b263-6d275e1b09cb}REG_BINARY Binary Data

{5b0cb2e2-ab87-4974-9f1c-2f22a654eeb9}REG_BINARY Binary Data

{b6b2ca61-fb98-4422-adc2-e7cf56b3680c}REG_BINARY Binary Data

{0aa7fff8-919f-453c-928c-28a12122ba38}REG_BINARY Binary Data

{074f7f68-ee10-428a-89d1-ba78f6c327ca}REG_BINARY Binary Data

{c016105c-eb34-4519-a5fd-5f4e4ad4d18e}REG_BINARY Binary Data

{a47525e2-725b-4888-8af1-ba5a60c04f4d}REG_BINARY Binary Data

{0ccc96a3-8c5c-45e2-b80e-7e37b16cc1ad}REG_BINARY Binary Data

{91ffecf0-0a9e-4572-95f1-a7111af86967}REG_BINARY Binary Data

{64e55933-15a5-495d-a928-ccca43d44875}REG_BINARY Binary Data

{13bfd422-6f75-4408-8924-9400ec0cb19c}REG_BINARY Binary Data

{cbfb56db-3c85-4543-9bc2-76ea28cdd74e}REG_BINARY Binary Data

{2dd96961-5757-434f-b617-34e732517c0e}REG_BINARY Binary Data

{375fb39b-08c6-40f2-bdf2-08fa63f970a2}REG_BINARY Binary Data

{2db25e6c-f07a-44f4-b6c8-50a330d2790b}REG_BINARY Binary Data

{c42f1cd6-3a95-4ae2-a513-793c3ae610c7}REG_BINARY Binary Data

{b6fdab6b-dcc6-43e3-99ce-7aeca65063a4}REG_BINARY Binary Data

{3697a558-3ed3-49be-a4c1-c1a4448653b4}REG_BINARY Binary Data

{935b7f48-0ede-44dd-9bc2-e00bb635cda3}REG_BINARY Binary Data

{941dad9d-7b1a-4354-997b-00cf1aa9b35c}REG_BINARY Binary Data

{b02a4013-b6b5-4859-9168-1e3299e43b24}REG_BINARY Binary Data

{d870c96c-75ee-46a6-8a02-8e4401a73423}REG_BINARY Binary Data

{8b50e2ec-7cf0-4b71-b42e-5b0536f6cab8}REG_BINARY Binary Data

{4137b143-2770-43d4-91a2-55bb0a069830}REG_BINARY Binary Data

{3180114b-8338-4740-9a16-444134ad62f4}REG_BINARY Binary Data

{17043d46-fac2-4561-bca1-0c7a05e95f5f}REG_BINARY Binary Data

{567d3836-3f5b-4067-b9c4-952f677010a2}REG_BINARY Binary Data

{4e718c57-c397-4221-9fbb-14fd51701d6a}REG_BINARY Binary Data

{3a90a266-1519-4d23-911b-e84cd0f02ab8}REG_BINARY Binary Data

{56b4fdc4-bb4e-4c42-a9d8-f627ee15ac21}REG_BINARY Binary Data

{1ba41ed8-151d-4577-9272-317856bc637c}REG_BINARY Binary Data

{9248d57e-f843-4159-807d-3813173e2096}REG_BINARY Binary Data

{4658cd86-525d-44ed-98a5-791a7b8655f1}REG_BINARY Binary Data

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE\Parameters\Policy\Persistent\Provider

{decc16ca-3f33-4346-be1e-8fb4ae0f3d62}REG_BINARY Binary Data

{4b153735-1049-4480-aab4-d1b9bdc03710}REG_BINARY Binary Data

{1bebc969-61a5-4732-a177-847a0817862a}REG_BINARY Binary Data

{aa6a7d87-7f8f-4d2a-be53-fda555cd5fe3}REG_BINARY Binary Data

{839cd73f-1907-49ea-9aa5-0e6be9048087}REG_BINARY Binary Data

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE\Parameters\Policy\Persistent\SubLayer

{b3cdd441-af90-41ba-a745-7c6008ff2300}REG_BINARY Binary Data

{b3cdd441-af90-41ba-a745-7c6008ff2301}REG_BINARY Binary Data

{b3cdd441-af90-41ba-a745-7c6008ff2302}REG_BINARY Binary Data

{9ba30013-c84e-47e5-ac6e-1e1aed72fa69}REG_BINARY Binary Data

{8c36b346-4e0c-4049-8b55-5295ac35567c}REG_BINARY Binary Data

--------------fltmgr:--------------

Type: 2

State: 4 (The service is running.) (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)

WIN32_EXIT_CODE: 0

SERVICE_EXIT_CODE: 0

CHECKPOINT: 0

WAIT_HINT: 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\FltMgr

AttachWhenLoaded REG_DWORD 1

DisplayName REG_SZ @%SystemRoot%\system32\drivers\fltmgr.sys,-10001

Group REG_SZ FSFilter Infrastructure

ImagePath REG_EXPAND_SZ system32\drivers\fltmgr.sys

Description REG_SZ @%SystemRoot%\system32\drivers\fltmgr.sys,-10000

ErrorControl REG_DWORD 3

Start REG_DWORD 0

Tag REG_DWORD 1

Type REG_DWORD 2

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\FltMgr\Enum

0 REG_SZ Root\LEGACY_FLTMGR\0000

Count REG_DWORD 1

NextInstance REG_DWORD 1

C:\windows\system32\drivers\fltmgr.sys

File Size: 289664 BYTES FileVersion: 6.1.7601.17514 MD5: [da6b67270fd9db3697b20fce94950741]

C:\windows\SysWOW64\comctl32.ocx

File Size: 609824 BYTES FileVersion: 6.0.81.5 MD5: [e2bed335446b7321ff38a138b3962e8a]

C:\windows\SysWOW64\mscomctl.ocx

File Size: 1070232 BYTES FileVersion: 6.1.98.39 MD5: [766f501b61c22723536af696a74133d4]

C:\windows\SysWOW64\olepro32.dll

File Size: 90112 BYTES FileVersion: 6.1.7601.17514 MD5: [703ffd301ab900b047337c5d40fd6f96]

MBAM Registry Settings and License Info:

========================================

--------------Settings:--------------

Advanced:

AutomaticQuarantine: true

AutostartProtection: true

EarlyStartSelfProtection: true

LimitedMode: false

SelfProtection: true

StartSilentMode: false

StartupDelay: 0

ApplicationState:

First-Run-After-Installation: false

General:

DaysUntilNotifyExpiration: 5

Language: no

RightClickAccess: true

SilentErrors: false

Logging:

ExportLog: true

Notification:

ProtectionTray:

DisplayMilliseconds: 7000

ScanHistory:

Duration_Complete: 36000

Duration_Driver: 4000

Duration_Filesystem: 0

Duration_Heuristics: 134000

Duration_Loading: 0

Duration_MasterBootRecord: 0

Duration_Memory: 40000

Duration_PreScan: 6000

Duration_Registry: 6000

Duration_Sector: 0

Duration_SectorMemory: 0

Duration_Startup: 4000

ItemCount_Complete: 245383

ItemCount_Driver: 304

ItemCount_Filesystem: 39431

ItemCount_Heuristics: 9181

ItemCount_Loading: 0

ItemCount_MasterBootRecord: 2

ItemCount_Memory: 2797

ItemCount_PreScan: 0

ItemCount_Registry: 574

ItemCount_Sector: 0

ItemCount_SectorMemory: 223

ItemCount_Startup: 1140

LastScanDateEpoch: 1401852238979

LastScanType: 1 (Threat Scan)

Update:

LastUpdate: 2014-06-04T08:05:15

NotifyInstallReady: true

NotifyOutdatedDatabase: 1

ProxyPassword:

ProxyPort: 0

ProxyServer:

ProxyUsername:

UseProxy: false

UseProxyAuthentication: false

--------------Account:--------------

Account Status: Premium

Expiration Time: 2034/04/14 17:46:21

Activation Time: 2014/04/14 17:46:21

Trial Used: false

--------------Access Policies:--------------

Scheduler Queue:

================

tasks:

7e1324bf-e63f-4217-b23f-111fd4c4ec0f:

parameters:

CheckForUpdatesBeforeScanStart: true

ProcessLaunchedFromScheduler: true

ScanConfig:

ExitWhenNoMalwareDetected: false

FileSystemOption: true

RebootSystemWhenMalwareDetected: false

RemoveMalwareAutomaticallyWhenScanEnds: false

ScanArchives: true

ScanHeuristic: true

ScanMemoryObjects: true

ScanPUM: 2

ScanPUP: 1

ScanRegistry: true

ScanRootkits: false

ScanStartup: true

ScanTargets:

ScanType: 1 (Threat Scan)

Silent: true

StartTaskFromSystemAccount: false

TaskType: 0

triggers:

cce32113-b009-4bc0-9a03-9343c1e82574:

dateinterval: 1:0:0

lastscheduled: Wed, 04 Jun 2014 05:23:55.999525 +0200

lasttriggered: Wed, 04 Jun 2014 05:23:55.999525 +0200

nextscheduled: Thu, 05 Jun 2014 05:27:39.999525 +0200

recovery: 00:00:00

start: Tue, 15 Apr 2014 03:00:00 +0000

timeinterval: 00:00:00

type: 4

uuid: cce32113-b009-4bc0-9a03-9343c1e82574

type: scan

uuid: 7e1324bf-e63f-4217-b23f-111fd4c4ec0f

a6c9d3b9-fcc6-4673-bc1e-e84182a3250c:

parameters:

NotifyWhenUpdateCompletes: true

ProcessLaunchedFromScheduler: true

TaskType: 3

triggers:

71b51471-69ba-4286-9e9f-d83554108fb5:

dateinterval: 0:0:0

lastscheduled: Wed, 04 Jun 2014 13:27:38.490341 +0200

lasttriggered: Wed, 04 Jun 2014 13:27:38.490341 +0200

nextscheduled: Wed, 04 Jun 2014 14:28:13.490341 +0200

recovery: 00:00:00

start: Mon, 14 Apr 2014 17:48:45.749930 +0200

timeinterval: 01:00:00

type: 3

uuid: 71b51471-69ba-4286-9e9f-d83554108fb5

type: update

uuid: a6c9d3b9-fcc6-4673-bc1e-e84182a3250c

Pending File Rename Operations:

================================

If any Malwarebytes Anti-Malware items are listed below, the user must reboot to complete a Malwarebytes Anti-Malware upgrade installation.

MBAMProtector Registry Values:

==============================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector

Type REG_DWORD 2

Start REG_DWORD 3

ErrorControl REG_DWORD 1

ImagePath REG_EXPAND_SZ \??\C:\windows\system32\drivers\mbam.sys

Group REG_SZ FSFilter Anti-Virus

DependOnService REG_MULTI_SZ FltMgr

WOW64 REG_DWORD 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector\Instances

DefaultInstance REG_SZ MBAMProtector Instance

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector\Instances\MBAMProtector Instance

Altitude REG_SZ 328800

Flags REG_DWORD 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector\Parameters

PassThruFile REG_SZ mbampt.exe

ProductPath REG_SZ C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector\Enum

0 REG_SZ Root\LEGACY_MBAMPROTECTOR\0000

Count REG_DWORD 1

NextInstance REG_DWORD 1

MBAMService Registry Values:

============================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMService

Type REG_DWORD 16

Start REG_DWORD 2

ErrorControl REG_DWORD 1

ImagePath REG_EXPAND_SZ "C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware\mbamservice.exe"

DependOnService REG_MULTI_SZ MBAMProtector

WOW64 REG_DWORD 1

ObjectName REG_SZ LocalSystem

Description REG_SZ Malwarebytes Anti-Malware service

DelayedAutostart REG_DWORD 0

MBAMScheduler Registry Values:

==============================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMScheduler

Type REG_DWORD 16

Start REG_DWORD 2

ErrorControl REG_DWORD 1

ImagePath REG_EXPAND_SZ "C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware\mbamscheduler.exe"

WOW64 REG_DWORD 1

ObjectName REG_SZ LocalSystem

Description REG_SZ Malwarebytes Anti-Malware scheduler

Terminal Services Status for (null) entries in PM logs and GetUserToken errors:

===============================================================================

--------------TERMService:--------------

Type: 32

State: 1 (The service is not running.) (State is stopped)

WIN32_EXIT_CODE: 1077

SERVICE_EXIT_CODE: 0

CHECKPOINT: 0

WAIT_HINT: 0

TermService Start is set to: 3 (Manual Startup)

Proxy Status: No proxy is Set

LAN Settings:

=============

only 'Automatically detect settings' is selected

SystemPartition:

================

HKEY_LOCAL_MACHINE\SYSTEM\Setup\

SystemPartition REG_SZ \Device\HarddiskVolume1

Balloon Tips Status:

====================

Enabled

Time Format Settings:

=====================

Should be:

h:mm:ss tt

AM

PM

:

Currently:

REG_SZ HH:mm:ss

REG_SZ

REG_SZ

REG_SZ

Language and Regional Settings:

===============================

ACP: Language is English (United States)

MACCP: Language is English (United States)

OEMCP: 850 Please refer to this link for details: Here

Startup Folders for Error_Expanding_Variables Check:

====================================================

All Users Startup Folder Exists.

Current User's Startup Folder Exists.

Context Menu Entries:

=====================

HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers\MBAMShlExt

(Default): REG_SZ {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\MBAMShlExt

(Default): REG_SZ {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

HKEY_CLASSES_ROOT\MBAMExt.MBAMShlExt

(Default): REG_SZ MBAMShlExt Class

HKEY_CLASSES_ROOT\MBAMExt.MBAMShlExt\CLSID

(Default): REG_SZ {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

HKEY_CLASSES_ROOT\MBAMExt.MBAMShlExt\CurVer

(Default): REG_SZ MBAMExt.MBAMShlExt.1

HKEY_CLASSES_ROOT\MBAMExt.MBAMShlExt.1

(Default): REG_SZ MBAMShlExt Class

HKEY_CLASSES_ROOT\MBAMExt.MBAMShlExt.1\CLSID

(Default): REG_SZ {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

HKEY_CLASSES_ROOT\Interface\{015FAC74-0374-494A-A02D-316D562C0FCE}

(Default): REG_SZ IMBAMShlExt

HKEY_CLASSES_ROOT\Interface\{015FAC74-0374-494A-A02D-316D562C0FCE}\ProxyStubClsid32

(Default): REG_SZ {00020424-0000-0000-C000-000000000046}

HKEY_CLASSES_ROOT\Interface\{015FAC74-0374-494A-A02D-316D562C0FCE}\TypeLib

(Default): REG_SZ {AFF1A83B-6C83-4342-8E68-1648DE06CB65}

Version REG_SZ 1.0

HKEY_CLASSES_ROOT\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}

(Default): REG_SZ MBAMShlExt Class

HKEY_CLASSES_ROOT\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}\InprocServer32

(Default): REG_SZ C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware\mbamext.dll

ThreadingModel REG_SZ Apartment

HKEY_CLASSES_ROOT\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}\ProgID

(Default): REG_SZ MBAMExt.MBAMShlExt.1

HKEY_CLASSES_ROOT\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}\TypeLib

(Default): REG_SZ {AFF1A83B-6C83-4342-8E68-1648DE06CB65}

HKEY_CLASSES_ROOT\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}\VersionIndependentProgID

(Default): REG_SZ MBAMExt.MBAMShlExt

HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}

HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0

(Default): REG_SZ MBAMExt 1.0 Type Library

HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\0

HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\0\win32

(Default): REG_SZ C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware\mbamext.dll

HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\FLAGS

(Default): REG_SZ 0

HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\HELPDIR

(Default): REG_SZ C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware

HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}

HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0

(Default): REG_SZ MBAMExt 1.0 Type Library

HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\0

HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\0\win32

(Default): REG_SZ C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware\mbamext.dll

HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\FLAGS

(Default): REG_SZ 0

HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\HELPDIR

(Default): REG_SZ C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware

List of MBAM Related Directories:

=================================

C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware\

7z.dll File Size: 920888 BYTES FileVersion: 9.20.0.0 MD5: [9f522b2708cab181c0f137abbcd1de2e]

atl100.dll File Size: 159032 BYTES FileVersion: 10.0.40219.325 MD5: [e013127ee031f1418b72fde79b1c2366]

changes.txt File Size: 2261 BYTES FileVersion: N/A MD5: [af70267bdf9a37a96f1a79a5c3720ae6]

is-JQIC3.tmp File Size: 184632 BYTES FileVersion: 3.0.4.0 MD5: [945bb364b09f3a8e998dbff02a0a5a58]

license.rtf File Size: 39478 BYTES FileVersion: N/A MD5: [8627b31943a534aad30d154c2b2c1aaf]

master.conf File Size: 1258 BYTES FileVersion: N/A MD5: [9702ca5e82d3756c6d8af34a2ababaea]

mbam.dll File Size: 579896 BYTES FileVersion: 1.0.7.0 MD5: [d32c2a98859cb22d57a665f15f351e7d]

mbam.exe File Size: 6970168 BYTES FileVersion: 1.0.0.532 MD5: [4fbc630768570e6ac35c3de8f6ec79f5]

mbamcore.dll File Size: 1680696 BYTES FileVersion: 1.0.11.0 MD5: [f722fa26739eafcbd8d5f3829b632cd7]

mbamdor.exe File Size: 54072 BYTES FileVersion: 1.0.1.0 MD5: [4da2f2da54a92850f56c0db712058188]

mbamext.dll File Size: 111416 BYTES FileVersion: 2.1.4.0 MD5: [36dabd15de764c22cabc71d355ea7e37]

mbampt.exe File Size: 39736 BYTES FileVersion: 1.0.0.0 MD5: [9acd7583584c93ee542c273df8e91dc1]

mbamscheduler.exe File Size: 1809720 BYTES FileVersion: 3.0.2.0 MD5: [d84aea3f3329d622dfc1297dddf6163b]

mbamservice.exe File Size: 860472 BYTES FileVersion: 3.0.2.0 MD5: [4f45ed469906494f9bf754e476390dbd]

mbamsrv.dll File Size: 4437816 BYTES FileVersion: 1.1.0.0 MD5: [9b48e38c35f08fa831b387a0b27c40aa]

msvcp100.dll File Size: 421688 BYTES FileVersion: 10.0.40219.325 MD5: [e4b829081e639e42985853bae754a53d]

msvcr100.dll File Size: 774456 BYTES FileVersion: 10.0.40219.325 MD5: [80fcedbe920e9cbe30d9d3665bd6efed]

QtCore4.dll File Size: 2732856 BYTES FileVersion: 4.8.4.0 MD5: [30490eed6a1e20e8259c0b9c58f488fe]

QtGui4.dll File Size: 8575288 BYTES FileVersion: 4.8.4.0 MD5: [15e21aa7d0c0c994cd565eeb96d13c20]

QtNetwork4.dll File Size: 909112 BYTES FileVersion: 4.8.4.0 MD5: [d7588d42e29080c32a003bee465160d8]

unins000.dat File Size: 47144 BYTES FileVersion: N/A MD5: [77fac57af90c2dab01ef1fbb632cb535]

unins000.exe File Size: 718353 BYTES FileVersion: 51.52.0.0 MD5: [3cf64e6d6ba9ddbcbc825d906baee592]

C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware\\Chameleon

C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware\\Chameleon\Windows

chameleon.chm File Size: 235882 BYTES FileVersion: N/A MD5: [c4190b71f037714aa77aba294434ba5b]

firefox.com File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

firefox.exe File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

firefox.pif File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

firefox.scr File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

iexplore.exe File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

mbam-chameleon.com File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

mbam-chameleon.exe File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

mbam-chameleon.pif File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

mbam-chameleon.scr File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

mbam-killer.exe File Size: 1181496 BYTES FileVersion: N/A MD5: [c6927fd8f7e9105b64db5d5a08b53731]

rundll32.exe File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

svchost.exe File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

windows.exe File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

winlogon.exe File Size: 750392 BYTES FileVersion: 3.0.4.0 MD5: [09882e8edd1144e6ef1af6d1f98305ee]

C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware\\imageformats

qgif4.dll File Size: 32568 BYTES FileVersion: 4.8.4.0 MD5: [e59f533c26c8375cd120b4791482217e]

C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware\\Languages

lang_bg.qm File Size: 144048 BYTES FileVersion: N/A MD5: [9ccb79999432d56b9843a3e2b2c90325]

lang_bs.qm File Size: 145523 BYTES FileVersion: N/A MD5: [6ab7a6274d4f9f7553c944f5c66201ba]

lang_ca.qm File Size: 132254 BYTES FileVersion: N/A MD5: [68a83ec63b6e7bc5dbdd412bcc49c6ce]

lang_cs.qm File Size: 141243 BYTES FileVersion: N/A MD5: [6b8acee7f461fa69b83d2c45c3725427]

lang_da.qm File Size: 130101 BYTES FileVersion: N/A MD5: [8539796784746218b229419e99ab308d]

lang_de.qm File Size: 149462 BYTES FileVersion: N/A MD5: [fcd3bc376ad219396e8c7d3c87cd8864]

lang_el.qm File Size: 149912 BYTES FileVersion: N/A MD5: [74f13f95f63fe96c08e571598df052d6]

lang_en.qm File Size: 115961 BYTES FileVersion: N/A MD5: [8c9da1c0ce06b89f8d323bf948bfba4e]

lang_es.qm File Size: 130487 BYTES FileVersion: N/A MD5: [33e1c6d40b841cc2e783ec8d8102e66f]

lang_et.qm File Size: 138126 BYTES FileVersion: N/A MD5: [aa215b5f37a72a69854c9163ac543b51]

lang_fi.qm File Size: 144256 BYTES FileVersion: N/A MD5: [18912c339939c3a6629004ec900f4fe4]

lang_fr.qm File Size: 149253 BYTES FileVersion: N/A MD5: [ec2bf2f431c4273f151b8c8a7b84c387]

lang_he.qm File Size: 116101 BYTES FileVersion: N/A MD5: [9e692744e77051c6ce14df32f9b71920]

lang_hr.qm File Size: 139841 BYTES FileVersion: N/A MD5: [3e3737fe86eb595c5f6817eebf731aa7]

lang_hu.qm File Size: 145621 BYTES FileVersion: N/A MD5: [52d3d7fcf8c8db071ef0573a1357c2fd]

lang_id.qm File Size: 143102 BYTES FileVersion: N/A MD5: [80473d2c73d2f54f2b23c9316f2d0ceb]

lang_it.qm File Size: 146851 BYTES FileVersion: N/A MD5: [7e7aea7d0b433d7e912ed9f0887684a7]

lang_ja.qm File Size: 121282 BYTES FileVersion: N/A MD5: [19ac79b7a5e05d665e417c2dd75afc94]

lang_ko.qm File Size: 118033 BYTES FileVersion: N/A MD5: [de213178c14490bf452ea45278d3442d]

lang_nl.qm File Size: 146325 BYTES FileVersion: N/A MD5: [5aec6f6bdc5e6c28744e6ef374709eeb]

lang_no.qm File Size: 142918 BYTES FileVersion: N/A MD5: [4388c08217618af2e24173af6f5d3f97]

lang_pl.qm File Size: 145434 BYTES FileVersion: N/A MD5: [699700c889447d1f9b607c04f07fff67]

lang_pt_BR.qm File Size: 131739 BYTES FileVersion: N/A MD5: [a3430222223d59da8ec6ea1edae5ee2f]

lang_pt_PT.qm File Size: 149128 BYTES FileVersion: N/A MD5: [afdf1907af4c95f9af510d5fc1bb9067]

lang_ro.qm File Size: 121166 BYTES FileVersion: N/A MD5: [1672a2b3a9807a1497fe43824c0026c0]

lang_ru.qm File Size: 122186 BYTES FileVersion: N/A MD5: [d4dd1eea2b0f52aba2fca4d159c387f7]

lang_sk.qm File Size: 119827 BYTES FileVersion: N/A MD5: [8b200d162e8028843e41aa1a927cfd84]

lang_sl.qm File Size: 143191 BYTES FileVersion: N/A MD5: [1760a6aa6990b2f0c4c71ec04b25ac9c]

lang_sr.qm File Size: 143261 BYTES FileVersion: N/A MD5: [377d15c0da0249f4a7a58978b6307d81]

lang_sv.qm File Size: 142525 BYTES FileVersion: N/A MD5: [2587ead21967296fefdd0ee0684fe8b4]

lang_tr.qm File Size: 142194 BYTES FileVersion: N/A MD5: [880fcbe97ec6f13ec094f7371b5b295f]

lang_vi.qm File Size: 126874 BYTES FileVersion: N/A MD5: [c61281786b5bfec68afc742a19f6abd9]

lang_zh_tr.qm File Size: 110870 BYTES FileVersion: N/A MD5: [f223d83580b1ee35edea13293cb2c80d]

C:\Users\ulf johansen\Downloads\Malwarebytes\Malwarebytes Anti-Malware\\Plugins

fixdamage.exe File Size: 821560 BYTES FileVersion: 1.1.0.1010 MD5: [3a4dcd021d9f3a5305a22e5e309da305]

C:\Users\ulf johansen\AppData\Roaming\Malwarebytes\Malwarebytes Anti-Malware

C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware

actions.ref File Size: 314 BYTES FileVersion: N/A MD5: [b26a36c0696e299fdfebe180c09c2737]

domains.ref File Size: 38 BYTES FileVersion: N/A MD5: [8c30b536b67543eb68e68b9640d4d498]

exclusions.dat File Size: 108 BYTES FileVersion: N/A MD5: [187852c483b0c0bad7ec6815eaab0384]

ips.ref File Size: 33 BYTES FileVersion: N/A MD5: [8a1c580788ea8de3f32862c2c1cf373c]

mbam-setup.exe File Size: 17292760 BYTES FileVersion: 2.0.2.1012 MD5: [e90bf9e1562f40140161573b79cd5720]

rules.ref File Size: 8375024 BYTES FileVersion: N/A MD5: [032cb7cf9b91ed6fc038033777ce0c27]

swissarmy.ref File Size: 21316 BYTES FileVersion: N/A MD5: [a6d0ca7a44b74627656ca4d3e892e853]

C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Configuration

build.conf File Size: 4522 BYTES FileVersion: N/A MD5: [844c24edf9988eb9948316e27f23c0c3]

database.conf File Size: 4 BYTES FileVersion: N/A MD5: [2261e7eca4cd0615a97263c0ad5045c2]

gatekeeper.conf File Size: 4 BYTES FileVersion: N/A MD5: [2261e7eca4cd0615a97263c0ad5045c2]

license.conf File Size: 559 BYTES FileVersion: N/A MD5: [2f7b244c0799f24e2a72db7bc9400a0a]

manifest.conf File Size: 2133 BYTES FileVersion: N/A MD5: [92dbc85565e07684687e866e846c42bd]

marketing.conf File Size: 1434 BYTES FileVersion: N/A MD5: [19533c40d9c9778b2ab423dbcf063d80]

net.conf File Size: 6132 BYTES FileVersion: N/A MD5: [08dc4ae8db4d359ef2bdb42d30df0d36]

notifications.conf File Size: 4 BYTES FileVersion: N/A MD5: [2261e7eca4cd0615a97263c0ad5045c2]

scheduler.conf File Size: 2076 BYTES FileVersion: N/A MD5: [46795652eea78d5d0ae4551ab4b37218]

settings.conf File Size: 2104 BYTES FileVersion: N/A MD5: [246f168b17974a0273ad63023ac6069c]

statistics.conf File Size: 597 BYTES FileVersion: N/A MD5: [d571e08ca3d1de18a8abc1a990265f75]

C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs

mbam-log-2014-06-04 (05-23-56).xml File Size: 2508 BYTES FileVersion: N/A MD5: [c117b6dd609b68a1bdd18c37b5f7fe7d]

protection-log-2014-06-03.xml File Size: 20472 BYTES FileVersion: N/A MD5: [b15602efd0d763dec9a3a8f1c7322ce4]

protection-log-2014-06-04.xml File Size: 4423 BYTES FileVersion: N/A MD5: [861858420bd26ffd06eb8973e644e184]

C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Quarantine

Malware Exclusions:

===================

Category: Folder, Exclusion: C:\Users\ulf johansen\Downloads\bitorrent

Web Exclusions:

================

Quarantined Items:

===================

===============================================================

END OF FILE

Link to post
Share on other sites

  • Staff

First...disable self-protection in MBAM. You can re-eneable it later.

 

In the \mbar folder on your desktop, open a command prompt by holding the shift button and right clicking, then select Open Command Window Here

 

In the command prompt, type the following command then press Enter

 

mbar.exe /r

 

Let me know the results.

Link to post
Share on other sites

  • Staff

Hello.

I'm telling you how we can try to disable the protection that is preventing you from deleting the mbar folder.

First, disable self-protection in Malwarebytes Anti-Malware.

 

Next...

We need to run MBAR in a special way. This requires that you open a command prompt that is pointing to the \mbar directory. The easiest way to do that is this:

 

In the mbar folder on your desktop, open a command prompt by holding the shift button and right clicking, then select' Open Command Window Here'

 

In the command prompt, type the following command then press Enter

 

mbar.exe /r

 

Let me know the results.

Link to post
Share on other sites

On my desktop I only have a mbar icon for starup the program.

I can,t open a command as you wrote.

If mbam is the problem - I have to delete / uninstall mbam.

And then mbar could been deleted.

Mybe reinstall mbam and never install mbar again.

Link to post
Share on other sites

  • Staff

On my desktop I only have a mbar icon for starup the program.

I can,t open a command as you wrote.

If mbam is the problem - I have to delete / uninstall mbam.

And then mbar could been deleted.

Mybe reinstall mbam and never install mbar again.

 

You wrote earlier:

 

 

But can,t delete a folder called mbar.

 

In this folder there are files like:

 

data, plugins, Languages, imagesformates, licence, logs, and many more files.

 

My instructions were designed for those facts.

The MBAR download is a self-extracting executable, which creates that mbar folder.

 

At any rate it seems like you've resolved the issue.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.