Malwarebytes question
Moderator: Wiz Feinberg
-
- Posts: 14336
- Joined: 4 Aug 1998 11:00 pm
- Location: Saugerties, NY
Malwarebytes question
I recently bought the full Premium version ( 3.1.2.1733 )
Here is an excerpt of a scan report:
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
My question is about Rootkits. In SETTINGS I definitely have Rootkit scan "ON" . The report confuses me. If I am misreading or misunderstanding the report, fine. I don't need to know what it means, as long as I can know that it is indeed scanning what I need it to scan.
Does this need my attention?
Here is an excerpt of a scan report:
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
My question is about Rootkits. In SETTINGS I definitely have Rootkit scan "ON" . The report confuses me. If I am misreading or misunderstanding the report, fine. I don't need to know what it means, as long as I can know that it is indeed scanning what I need it to scan.
Does this need my attention?
-
- Posts: 2663
- Joined: 4 Aug 1998 11:00 pm
- Location: Frostbite Falls, hard by Veronica Lake
Doesn't look right to me, Jon.
I show enabled next to rootkits.
I assume in settings/scan options/scan for rootkits, you have the toggle switch set to "on" and have closed the app and rebooted after confirming that setting.
If that's true, you might want to post at the Malwarebytes forum. I haven't checked there, but maybe it is a known issue.
I show enabled next to rootkits.
I assume in settings/scan options/scan for rootkits, you have the toggle switch set to "on" and have closed the app and rebooted after confirming that setting.
If that's true, you might want to post at the Malwarebytes forum. I haven't checked there, but maybe it is a known issue.
-
- Posts: 14336
- Joined: 4 Aug 1998 11:00 pm
- Location: Saugerties, NY
-
- Posts: 14336
- Joined: 4 Aug 1998 11:00 pm
- Location: Saugerties, NY
Great advice, Mitch.
It is a known thing, asked and answered in the forum. The selected settings (apparently) apply to manual scans. For automatic scheduled scans you have to click the scan in the schedule and make the selections in 'advanced settings'. My manual settings were good but the default in the scheduled scans is rootkits : disabled (for some reason).
Thanks for the help!
It is a known thing, asked and answered in the forum. The selected settings (apparently) apply to manual scans. For automatic scheduled scans you have to click the scan in the schedule and make the selections in 'advanced settings'. My manual settings were good but the default in the scheduled scans is rootkits : disabled (for some reason).
Thanks for the help!
-
- Posts: 2663
- Joined: 4 Aug 1998 11:00 pm
- Location: Frostbite Falls, hard by Veronica Lake
Thanks for digging into that.
I just checked settings/scan schedule/edit button/advanced and found that "scan for rootkits" was checked under "scheduled options".
I guess you are saying that that is NOT the default?
I frankly can't recall if I had previously visited that location and made that setting manually. If it isn't the default, I guess I must have as my scan report says rootkits enabled, unlike yours.
I just checked settings/scan schedule/edit button/advanced and found that "scan for rootkits" was checked under "scheduled options".
I guess you are saying that that is NOT the default?
I frankly can't recall if I had previously visited that location and made that setting manually. If it isn't the default, I guess I must have as my scan report says rootkits enabled, unlike yours.
-
- Posts: 14336
- Joined: 4 Aug 1998 11:00 pm
- Location: Saugerties, NY
Your summary is correct although all I can only say for certain that my auto scan was defaulted to 'disabled' and that this is the situation that I found in the MBAM forum. Maybe this pertains only to new installations or something (I upgraded from the free version a couple of weeks ago)? I do not know and did not investigate that.
-
- Posts: 22146
- Joined: 3 Dec 1999 1:01 am
- Location: Kansas City, MO
-
- Posts: 14336
- Joined: 4 Aug 1998 11:00 pm
- Location: Saugerties, NY
-
- Posts: 6107
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
I'm not Jack, but will chime in here anyway.Jon Light wrote:Jack--do you have some reasoning that would convince me to switch rootkit scanning off? I know/understand nothing and simply opt for 'more scanning is good' unless instructed otherwise.
Personally, I turn on scanning for rootkits. While they aren't an every day threat, they are out there in malware like the Petya virus. Petya scrambles the Master Boot Record (thus encrypting the entire disk) and uses a rootkit to reinstall if it is deleted. Petya is currently in the wild and uses some of the attack vectors used in Eternal Blue and WannaCry. While not particularly targeting normal computer users, we can become collateral damage. A rootkit detector goes a long way to stopping Petya and related malware.
Note that scanning for rootkits adds to the load on your computer during the scan and could interfere with its operation until the scanning has completed.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
- Posts: 14336
- Joined: 4 Aug 1998 11:00 pm
- Location: Saugerties, NY
-
- Posts: 6107
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Info on the Petya virus
Malwarebytes has an info page devoted to the new Petya/NotPetya virus.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog