Thursday, December 29, 2011

Troubleshoot Malwarebytes' Anti-Malware

Below are some common errors you may run into when attempting to use Malwarebytes' Anti-Malware.

Malwarebytes' setup program closes when you attempt to install it.

If you attempt to install Malwarebytes' and the setup program automatically closes then there is a good chance that you have an infection that is trying to stop the program from installing. To get around this, try renaming mbam-setup.exe to other names like:

mbam-setup.com
iexplore.exe
explorer.exe
userinit.exe
winlogon.exe
After each rename, try and run the program again. If that does not work, then you may to download and run Rkill to terminate the malware processes that are stopping you.

Malwarebytes' wont start

If you attempt to run Malwarebytes' and it does not start then there is a good chance that you have an infection that is trying to stop the program from running. To get around this, try renaming C:\program files\Malwarebytes' Anti-Malware\mbam.exe to other names like:

mbam.com
iexplore.exe
explorer.exe
userinit.exe
winlogon.exe
After each rename, try and run mbam.exe again. If that does not work, then you may to download and run Rkill to terminate the malware processes that are stopping you.

Error 732 when trying to update Malwarebytes' Anti-Malware

If you receive an Error 732 when trying to update MBAM it could be because you do not currently have an Internet connection or a malware has changed your connection settings so that you are using a proxy server. To make sure your connection has not been set to use a proxy server, please do the following steps:

Please start Internet Explorer, and when the program is open, click on the Tools menu and then select Internet Options as shown in the image below.

You should now be in the Internet Options screen as shown in the image below.

Now click on the Connections tab as designated by the blue arrow above.

You will now be at the Connections tab as shown by the image below.

Now click on the Lan Settings button as designated by the blue arrow above.

You will now be at the Local Area Network (LAN) settings screen as shown by the image below.

Under the Proxy Server section, please uncheck the checkbox labeled Use a proxy server for your LAN. Then press the OK button to close this screen. Then press the OK button to close the Internet Options screen. Now that you have disabled the proxy server you will be able to browse the web again with Internet Explorer.
Now try and update MBAM again.

Error 2 when installing MBAM

If you receive an Error 2 when installing MBAM then a core executable was deleted by a malware running on your computer. To fix this we will first need to download a randomized version of mbam.exe and save it to the C:\program files\Malwarebytes' Anti-Malware\ folder. We can then run that random named executable to start Malwarebytes' and scan your computer. To do this follow these steps:

If you receive a code 2 error while installing Malwarebytes's, please press the OK button to close these errors as we will resolve them in future steps. The code 2 error will look similar to the image below.

As this infection deletes a core executable of Malwarebytes' we will need to download a new copy of it and put it in the C:\program files\Malwarebytes' Anti-Malware\ folder. To download the file please click on the following link:

Malwarebytes' EXE Download
When your browser prompts you where to save it to, please save it to the C:\program files\Malwarebytes' Anti-Malware\ folder. When downloading the file, it will have a random filename. Please leave the filename the way it is as it is important that it is not changed. You may want to write down the name of the file as you will need to know the name in the next step.

Once the file has been downloaded, open the C:\program files\Malwarebytes' Anti-Malware\ folder and double-click on the file you downloaded in step 2.
Now that MBAM is running, please update the program and scan your computer like normal.

Using Rkill to terminate infection processes that may be stopping MBAM from running

If all of these steps do not work, then you can download, or copy from a clean computer, the Rkill program and run it on the infected computer. Rkill will then try and terminate the infections that may be stopping you from installing MalwareBytes'. Rkill, under various names, can be downloaded from the following links:

Rkill.com
Rkill.exe
iExplore.exe
rkill.scr
uSeRiNiT.exe
WiNlOgOn.exe

Once Rkill runs, it will create a log of what applications were terminated. You can then attempt to start the installation of MalwareBytes or start the program again.

No comments:

Post a Comment