BleepingComputer.com: Why does this happen?

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Why does this happen?

#1 User is offline   huyvu90 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 12
  • Joined: 25-August 09

Posted 25 August 2009 - 01:36 AM

I have a folder in my PC which I'm 100% sure that it's a spyware. For some reasons malawarebyte doesn't detect it when I scan the folder while my PC booted from ubcd4win. Instead it only detects it when scan in normal XP mode. Why?

#2 User is offline   Blade 

  • Strong in the Bleepforce
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Site Admin
  • Posts: 10,232
  • Joined: 20-January 09
  • Gender:Male
  • Location:US

Posted 25 August 2009 - 07:18 AM

Scanning with MBAM in safe or normal mode will work but removal functions are not as powerful in safe mode. MBAM is designed to be at full power when malware is running so safe mode is not necessary when using it. In fact, it loses some effectiveness for detection & removal when used in safe mode because the program includes a special driver which does not work unless you boot XP normally. Additionally, scanning from a bootable disk or from safe mode prevents some types of malware from running so it may be missed during the detection process. For optimal removal, normal mode is recommended so it does not limit the abilities of MBAM.

~Blade
Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+

#3 User is offline   huyvu90 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 12
  • Joined: 25-August 09

Posted 25 August 2009 - 02:51 PM

View PostBlade Zephon, on Aug 25 2009, 07:18 AM, said:

Scanning with MBAM in safe or normal mode will work but removal functions are not as powerful in safe mode. MBAM is designed to be at full power when malware is running so safe mode is not necessary when using it. In fact, it loses some effectiveness for detection & removal when used in safe mode because the program includes a special driver which does not work unless you boot XP normally. Additionally, scanning from a bootable disk or from safe mode prevents some types of malware from running so it may be missed during the detection process. For optimal removal, normal mode is recommended so it does not limit the abilities of MBAM.

~Blade



How exactly does mbam driver help in detection?

#4 User is offline   DaChew 

  • Visiting Alien
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 10,317
  • Joined: 20-May 07
  • Gender:Male
  • Location:millenium falcon and rockytop

Posted 25 August 2009 - 09:36 PM

MBAM used in portable mode is only supported for corporate use if I am not mistaken.

MBAM is intended to take up where an AV leaves off, it's using a driver loaded in normal mode to catch rootkits and depends upon heuristics for much of it's usefulness. Scanning from a second enviroment pretty much eliminates heuristcs.

It's database is extremely small, an AV uses large databases and can detect more types of files.
Chewy

No. Try not. Do... or do not. There is no try.

#5 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,513
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 26 August 2009 - 09:17 AM

When compared to other security tools like Spybot S&D and Ad-Aware, the advantage of MBAM is that it uses a proprietary low level driver (similar to some ARK detectors) to locate hidden files and special techniques which enable it to detect a wide spectrum of threats including active rootkits.

Most anti-rootkit scanners will not work in safe mode because they utilize a driver which is required for the scanning process and that driver will not load in safe mode. Further, there are rootkit variants (haxdoor) that run in safe mode so the usual reason for running a scan in that mode does not apply.
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users