Solved Rootkit.Fileless.MTGen - tried to run Farbar - W10 prevents

Grimmbro

New Member
Thread author
Nov 11, 2017
5
Followed your instructions and downloaded Farbar - when I click it to run , a large Windows message appears warning me that Windows stopped an unrecognized app from running. So what now ?
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,


Download
51a5f31352b88-icon_MBAR.png
Malwarebytes Anti-Rootkit to your desktop.
  • Double-click the icon to start the tool.
  • It will ask you where to extract it, then it will start.
    • If it didn't start, locate mbar folder on your Desktop and double click on mbar.cmd

      14kz52w.png

  • Warning! Malwarebytes Anti-Rootkit needs to be run from an account with administrator rights.
  • Click in the introduction screen "next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
  • When the scan is finished and no malware has been found select "Exit".
  • If malware was detected, make sure to check all the items and click "Cleanup". Reboot your computer.
  • Open the MBAR folder and paste the content of the following files in your next reply:
    • "mbar-log-{date} (xx-xx-xx).txt"
    • "system-log.txt"
 

Grimmbro

New Member
Thread author
Nov 11, 2017
5
Hello,


Download
51a5f31352b88-icon_MBAR.png
Malwarebytes Anti-Rootkit to your desktop.
  • Double-click the icon to start the tool.
  • It will ask you where to extract it, then it will start.
    • If it didn't start, locate mbar folder on your Desktop and double click on mbar.cmd

      14kz52w.png
  • Warning! Malwarebytes Anti-Rootkit needs to be run from an account with administrator rights.
  • Click in the introduction screen "next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
  • When the scan is finished and no malware has been found select "Exit".
  • If malware was detected, make sure to check all the items and click "Cleanup". Reboot your computer.
  • Open the MBAR folder and paste the content of the following files in your next reply:
    • "mbar-log-{date} (xx-xx-xx).txt"
    • "system-log.txt"
 

Grimmbro

New Member
Thread author
Nov 11, 2017
5
Thank you. I downloaded the Anti-Rootkit file and once again a Windows Security screen popped up warning me of this file and the only option it had was a button that says DON'T RUN. However, when I looked closer, in small print it had an option which I believe said learn more. When I clicked that, the button changed to 2 buttons - one that says Run Anyway and the other Don't Run. I clicked the Run Anyway and was able to complete the scan. There were 2 files found and cleaned up. I rebooted and here are the files you requested in your instructions. I also noticed that an icon is now gone from the small tray icons on the right lower corner of my screen. This is the icon which was for the Fujitsu ScanSnap Manager which is an application that allowed me to scan using the ScanSnap scanner. I will check to see if restoring that application may trigger the malware again. Not sure if one is related to the other but this is something that I immediately noticed after the reboot .Will update with the results.
 

Attachments

  • mbar-log-2017-11-12 (15-10-41).txt
    3 KB · Views: 6
  • system-log.txt
    121.4 KB · Views: 2
  • Like
Reactions: lowdetection

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top