mbam runtime errors (0 and 404)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sartre_4000, Sep 18, 2008.

  1. Sartre_4000

    Sartre_4000 Private E-2

    Hi guys,

    I came across this forum when I was trying to get rid of malware/viruses on my computer and after finding the info to be quite helpful i signed up. i've gone through the read/run me post and followed the steps, having gone through the list for windows XP cleaning procedure (though i havent installed the last 2 components yet...)

    the main things i noticed before running the programs was that:
    • the computer was running very slowly
    • had difficulties upgrading windows components (sits idle when trying to download the updates etc)

    i figured it may have been my settings on the comodo firewall, the installation of internet explorer 7.0, the network setup or from tweaking the start up programs etc.

    what inspired me to start the search was when i tried to use an online learning tool for uni (official site related to perason's education) which required that i used internet explorer rather than mozilla firefox. to access the online tests i needed to install components related specifically to the course, as well as flash player and adobe reader (which is mystifying b/c i already had adobe reader 8.0 and the site said i only needed 4.0)... anyway, problems resulted:
    • downloaded & installed adobe 9 from the official adobe site
    • also had to run an ActiveX... didn’t work out too well! see next point
    • firewall alerted me that it may contain malware but i ran with it b/c it was the official site and was part of my official uni course
    • said the install was unsuccessful/corrupt - getplus_helpersvc.exe – still currently located in C:\Program Files\NOS\bin  this is what was identified as malware

    i tried restarting the IE 7.0 browser but i had to re-enter the security settings, as if i had run it for the first time. after setting the (fairly strict) security policies (don't allow 3rd party cookies etc) i returned to the official site - www.coursecompass.com - to try again. not much time passed before i was notified, again from comodo as well as from wipatrol, that my keystrokes were being recorded.... anyway then the hunt for solutions officially began

    CC cleaner did its job and super antispyware, spybot SD and mbam seemed to have worked quite well, having detected and removed a few spyware entries and trojans. however... when i try to run mbam since the reboot i get runtime errors (0 and 440). i'm not sure if this is because there's still malware preventing me from running the program or whether it's a result of the registry being cleaned etc

    the computer seems to be running a lot quicker now and i also have KeyScrambler installed as an extra safety measure. nonetheless i want to make sure everything is working fine now. so i guess i'll firstly ask if there are any ideas as to why i'm getting the runtime errors before providing a log of the results found. sorry for the lengthy post by the way

    other details:
    using a hp compaq nx6320 laptop with windows xp, sp2
    also came with hp security/resident shield installed
    running the internet through a wireless connection and shouldnt be networked to my other 2 computers (one is win xp, other is a linux box with ubuntu 8.04)
    router is a dlink and i have assigned this computer a static ip address because i was getting errors from my laptop being assigned the same ip as my other windows box
    comodo firewall
    winpatrol (downloaded from the official site)
    KeyScrambler (downloaded from a link posted on this site)

    i'm pretty cautious about my downloads, so not sure where the problem arose, but have a feeling it has something to do with letting my little brother borrow the laptop. again, sorry for the length of the post, bt i figure more details is better than less. any help will be much appreciated! thanks in advance

    JC
     
  2. Sartre_4000

    Sartre_4000 Private E-2

    Current Hijack Log (WinPatrol)

    Looks pretty clean to me...

    SmitFraudFix v2.352

    Scan done at 22:46:09.40, Thu 18/09/2008
    Run from C:\Documents and Settings\JC\Desktop\Folders\Installs\Security\Smit Fraud\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in normal mode

    Edit by chaslang: Inline step 1 only of SmitFraudFix log removed.
     
    Last edited by a moderator: Sep 18, 2008
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you attach the 4 requested logs from the READ & RUN ME, we will look at them to see if you are having any malware problems. However what I expect is that you are having difficulties with the software you have installed and the websites your are accessing conflicting with the security features of the programs (like WinPatrol for example). If you block all cookies and have security settings too tight, you will have many problems with a variety of websites and I would expect you definitely would have problems with a training website where cookies, active-x, VB scripts, flash videos,...etc may be used.

    Having a computer run slowly and having problems with Window's Update.

    I'm not sure why you are getting runtime errors with MBAM but it may be due to WinPatrol or Comodo interferring with the installation or running of MBAM.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds