SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > General > General Topics
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 04-15-13, 07:59 PM   #1
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 42,603
Downloads: 10
Uploads: 0


ALARM! Malwarebyte's Antimalware users: condition red!!!

If you use MBAM and have not already noticed, they just have had a serious and very major FP incident that equals a reactor meltdown. I am typing this froma backup laptop currently.

For the time being, immediately shut down MBAM and deactivate the update function until they get there homework done for sure. One update this night started a quarantining frenzy on vital windows system files, and even MBAM itself. They made many people very happy with that. Some companies may even sue them into nirvana over this. I shared the symptom of being locke dout of my system, account not recognised after reboot, and needing some backdoor tricks to get at least into the coinsole mode to return to a restore point - only one was left, luckily from 3 days ago - all others had been deleted. W7 has the nice feature to restore also deleted files, so that losses in my sys32 folder were replaced, it seems. Earlier windows versions do not do this - you then must hope that you can move the many dozens of system files in quarantine back into windows. I am in the process of saving data and files as backup. Maybe I can escape the need to reinstall, I'll see latr in the night.

Follow this thread for hints, updates, advice. Do not run MBAM until they confirm here that it is save. The falty database update is alredy removed, but since they are in hectic stress, I do not trust their results before some more dust has settled.

http://forums.malwarebytes.org/index...owtopic=125129
__________________
If you feel nuts, consult an expert.
Skybird is offline   Reply With Quote
Old 04-15-13, 08:01 PM   #2
Cybermat47
Willing Webfooted Beast
 
Cybermat47's Avatar
 
Join Date: Aug 2012
Location: Australia
Posts: 5,408
Downloads: 300
Uploads: 23


Default

Ok.

Malwarebytes anti-malware.... what's the deal with the name? Sounds somewhat strange to me...
__________________
Historical TWoS Gameplay Guide: http://www.subsim.com/radioroom/showthread.php?p=2572620
Historical FotRSU Gameplay Guide: https://www.subsim.com/radioroom/sho....php?p=2713394
Cybermat47 is offline   Reply With Quote
Old 04-15-13, 08:09 PM   #3
Oberon
Lucky Jack
 
Join Date: Jul 2002
Posts: 25,976
Downloads: 61
Uploads: 20


Default

Quote:
Originally Posted by Cybermat47 View Post
Ok.

Malwarebytes anti-malware.... what's the deal with the name? Sounds somewhat strange to me...
It's a (usually) pretty good anti-malware program, although I must confess I haven't run it in a while. I'll pass this info on though to those who do.
Oberon is offline   Reply With Quote
Old 04-15-13, 08:50 PM   #4
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 42,603
Downloads: 10
Uploads: 0


Default

false positives happoen sometimes, but this one was pretty serious and will cause them plenty of trouble, I'm sure.

It seems if you are running it and are fine right now, then you have missed the faulty update that was in the wild for just some minutes, apparently. I may have been lucky and managed to get tings running again, but I had to reinstall MBAM and by complete AF/Firewall suite as well. I am still paranoid on my system status right now, but for the time being things seem to work as intended. Latest update for MBAM - I run the Pro version - worked flawless again.

Cybermat, usually the software is pretty good indeed. It does all the work on my rig - almost all of the few intrusion alarms I get, come from either Opera of from MBAM, not from the the AV or Firewall.

For the time being, I run my accounts without passwords. It'S not nice to find yourself being locked out. Only repair CD by Acronis brought me in again and allowed to install the only restore point that was no massacred by tonight'S mess. Costed me four hours now.

Good night.
__________________
If you feel nuts, consult an expert.
Skybird is offline   Reply With Quote
Old 04-16-13, 05:20 AM   #5
Rhodes
Silent Hunter
 
Join Date: Aug 2005
Location: Figueira da Foz, Portugal
Posts: 4,515
Downloads: 110
Uploads: 0
Default

"My XP machine has survived, but the W7 machine is hosed.
I turned off updating on the XP machine"

Loved this comment!
Well I have the free version of that does not have the real time protection. I just will not run it until this is corrected. I use hitmanpro and like very much of it. It clean the nasty police ransomware that I got.
But it is strange that they did such a mess in the update program files, to have the Malwarebytes quarantine everything. Almost like a auto-immune disease.

Edit: been reading the forum, I think they already removed the bad update and post steps to correct it.
Rhodes is offline   Reply With Quote
Old 04-16-13, 06:00 AM   #6
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 42,603
Downloads: 10
Uploads: 0


Default

System seems to run fine again, MBAM running as usual, too.

I think its back to condition green.

But many company administrators will have a nice working day today. Many systems did not get off the hook so "easily" as I did.

Consequences for myself: database updates only once per day now, not once per hour (inbetween settings not possible, unfortunately). Icreases the chance to miss a mess like this.
__________________
If you feel nuts, consult an expert.
Skybird is offline   Reply With Quote
Old 04-16-13, 10:50 AM   #7
STEED
Lucky Jack
 
Join Date: Jan 2006
Location: Down Town UK
Posts: 27,695
Downloads: 89
Uploads: 48


Default

Stone the crows..uninstall uninstall uninstall.

Done

OK is the free edition which I had up to reading this thread safe again?
__________________
Dr Who rest in peace 1963-2017.

To borrow Davros saying...I NAME YOU CHIBNALL THE DESTROYER OF DR WHO YOU KILLED IT!
STEED is offline   Reply With Quote
Old 04-16-13, 11:12 AM   #8
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 42,603
Downloads: 10
Uploads: 0


Default

As far as I know, yes. Cause was just one database update that gave false positives for system files and files belonging to the scanner itself. I have the Pro version running all day now, no problems. The update was discovered after just some minutes, and immediately withdrawn.

It'S bad if one got struck by this, yes. But I would recommend not to leave them. The software does a tremendous job and nicely lines up beside antivirus and firewall. What it does, it does better than all other programs I tried over the years, and it leaves only a very small footprint on system ressources.

The pro version is a lifetime license, you do not pay per year, but only once in your life. It adds the constantly-on background scanner that monitors all online activities and filters threats out already while surfing, like an active antivirus software.

Just antivirus and firewall alone is not sufficient anymore these days.

I had to install a new full version over the ruin of the wrecked old one that was dysfunctional. From that I say downloading the full installer also is safe now.
__________________
If you feel nuts, consult an expert.
Skybird is offline   Reply With Quote
Old 04-16-13, 11:31 AM   #9
STEED
Lucky Jack
 
Join Date: Jan 2006
Location: Down Town UK
Posts: 27,695
Downloads: 89
Uploads: 48


Default

Thanks Sky.
__________________
Dr Who rest in peace 1963-2017.

To borrow Davros saying...I NAME YOU CHIBNALL THE DESTROYER OF DR WHO YOU KILLED IT!
STEED is offline   Reply With Quote
Old 04-16-13, 02:06 PM   #10
Jimbuna
Chief of the Boat
 
Jimbuna's Avatar
 
Join Date: Feb 2006
Location: 250 metres below the surface
Posts: 190,473
Downloads: 63
Uploads: 13


Default

Quote:
Originally Posted by STEED View Post
Stone the crows..uninstall uninstall uninstall.

Done

OK is the free edition which I had up to reading this thread safe again?
All is good.
__________________
Wise men speak because they have something to say; Fools because they have to say something.
Oh my God, not again!!

Jimbuna is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 06:39 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright © 1995- 2025 Subsim®
"Subsim" is a registered trademark, all rights reserved.