Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows VistaWindows XPWindows MeWindows 98Windows 95Virtual PCInternet ExplorerOutlook ExpressWindows MediaSecurity
Related Topics
MS Server ProductsMS OfficePC HardwareMore Topics ...

Windows Forum / Windows Vista / Security / July 2007

Tip: Looking for answers? Try searching our database.

Malicious Software Removal Tool

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Zygy - 14 Jul 2007 08:06 GMT
Should I download Malicious Software Removal Tool or is it not necessary
with Vista Security Protection?
Malke - 14 Jul 2007 14:04 GMT
> Should I download Malicious Software Removal Tool or is it not necessary
> with Vista Security Protection?

There is no "Vista Security Protection" product. Even though Vista was
designed to be a more secure operating system than XP, you still need an
antivirus, firewall (the built-in Vista Firewall is fine for most
people), and a non-viral malware scanner (the built-in Windows Defender
is fine for most people).

The Malicious Software Removal Tool is a limited program that searches
for some specific forms of malware. It will not hurt you to run it.

Malicious Software Removal Tool explanation -
http://www.microsoft.com/security/malwareremove/default.mspx

Malke
Signature

Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

dean-dean - 14 Jul 2007 14:16 GMT
Windows Update offers the scan once a month.  (Look at your Update history,
when you open Windows Update).   But yes, you can also download the Tool and
run it whenever you like.

http://www.microsoft.com/downloads/details.aspx?FamilyID=ad724ae0-e72d-4f54-9ab3
-75b8eb148356&displaylang=en


> Should I download Malicious Software Removal Tool or is it not necessary
> with Vista Security Protection?
Zygy - 15 Jul 2007 09:00 GMT
Hi, Many thanks for the replies.I do already have all the other protections,
but as experts do you also run the Malicious Software Removal Tool?
> Should I download Malicious Software Removal Tool or is it not necessary
> with Vista Security Protection?
Malke - 15 Jul 2007 14:37 GMT
> Hi, Many thanks for the replies.I do already have all the other
> protections, but as experts do you also run the Malicious Software
> Removal Tool?
>> Should I download Malicious Software Removal Tool or is it not
>> necessary with Vista Security Protection?

I usually let it run on my Windows machines when it appears in the
monthly updates. It has never hurt anything. It has never found anything
either, but I run a tight ship on those computers. ;-)

Malke
Signature

Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

dean-dean - 15 Jul 2007 16:49 GMT
The Malicious Software Removal Tool is updated through Windows Update once a
month.  Windows Update runs the Tool "silently", without user input, unless
it finds a problem.   If you want to see an interface, and a list of the
malicious software it checks for (which are hyperlinked for more info), make
a shortcut to C:\Windows\System32\mrt.exe (right-click on mrt.exe > Send To
> Desktop (create shortcut).  With the interface, you can also choose a
type of scan (Quick, Full, or Customized).  You'll see the progress of the
scan, and a report afterwards.  As the Tool states, it's not a replacement
for an Anti-Virus product, but merely checks, on demand, for some of the
malicious-software biggies.  In response to your initial question,
downloading it isn't really necessary if Windows Update is up-to-date.

> Hi, Many thanks for the replies.I do already have all the other
> protections, but as experts do you also run the Malicious Software Removal
> Tool?
>> Should I download Malicious Software Removal Tool or is it not necessary
>> with Vista Security Protection?
Zygy - 16 Jul 2007 13:19 GMT
Many thanks for the very comprehensive reply. However I cannot find the
Malicious Software Removal Tool, to apply your suggestion on a shortcut,
although I downloaded and run it. I looked in Start, Search, but I cannot
see anything resembling it. Can you suggest where I should look?
> The Malicious Software Removal Tool is updated through Windows Update once
> a
[quoted text clipped - 18 lines]
>>> Should I download Malicious Software Removal Tool or is it not necessary
>>> with Vista Security Protection?
dean-dean - 16 Jul 2007 14:56 GMT
Hi Zygy.  There is no shortcut made to the program, by default.  Using
Windows Explorer, navigate to C:\Windows\System32, and look for the file
named mrt.exe.  Then right-click on that file and choose Send To >Desktop
(create shortcut).  This will put a shortcut on your Desktop, which you can
rename Malicious Software Removal Tool.  From there you can move it to
wherever you like.  For example, if you want it in your start Menu,
right-click the Start button and choose Open.  Then open the Programs
folder.  Drag the icon into the folder you want.  This will put the shortcut
in your Start Menu.

> Many thanks for the very comprehensive reply. However I cannot find the
> Malicious Software Removal Tool, to apply your suggestion on a shortcut,
[quoted text clipped - 24 lines]
>>>> necessary
>>>> with Vista Security Protection?
Zygy - 17 Jul 2007 08:21 GMT
Hi Dean, many thanks for the explanation. However I failed to find the file
to which you refer in Explore and what is even more interesting is that a
Search for C:\Windows\System32 will produce every mention in our exchanges
of Malicious Software Removal Tool, but not the file. To resolve this I
downloaded the file and saved it on the Desktop, which gives me the same
facilities. If you have any ideas why I cannot find the file by going on a
right click to Start/Explore I would be interested to hear.
> Hi Zygy.  There is no shortcut made to the program, by default.  Using
> Windows Explorer, navigate to C:\Windows\System32, and look for the file
[quoted text clipped - 34 lines]
>>>>> necessary
>>>>> with Vista Security Protection?
dean-dean - 17 Jul 2007 14:22 GMT
Hi Zygy.  Well, maybe the easiest way to get to that file with Explorer is
to double-click (Open) the Computer icon (on your Desktop, or in the Start
Menu, on the right side), then double-click (Open) your (C:) Drive, then
Open the Windows folder, then Open the System32 folder.  In the System32
folder, sort the files by name, and then scroll down to the file mrt.exe.
Make a shortcut as I explained in my previous post.  You can also get to
that folder by pressing the Windows key + the R key on your keyboard.  This
will pop up Run.  Run is also found under Start Menu > Programs >
Accessories.  In the Open box of Run, type (or Copy and Paste):

C:\Windows\System32

Click on OK. This will open the System32 folder.  Or you could type:

C:\Windows\System32\mrt.exe

Click on OK. This will open the Malicious Software Removal Tool.

> Hi Dean, many thanks for the explanation. However I failed to find the
> file to which you refer in Explore and what is even more interesting is
[quoted text clipped - 42 lines]
>>>>>> necessary
>>>>>> with Vista Security Protection?
Zygy - 18 Jul 2007 12:58 GMT
Hi Dean, You are a mine of information for someone like me, a self-taught
user. Many thanks for being so helpful!
> Hi Zygy.  Well, maybe the easiest way to get to that file with Explorer is
> to double-click (Open) the Computer icon (on your Desktop, or in the Start
[quoted text clipped - 63 lines]
>>>>>>> necessary
>>>>>>> with Vista Security Protection?
mommacrystal - 27 Jul 2007 22:00 GMT
> Should I download Malicious Software Removal Tool or is it not necessary
> with Vista Security Protection?
>
> I have the removal tool, everything is setup, works great, just one problem, I have malicious software on my computer it won't remove, I cannot find it, have searched extensively throughout my computer, it is no where to be found. Searched the given address for it and cannot get to it, please any suggestions would be appreciated.
dean-dean - 27 Jul 2007 22:29 GMT
What is the name of the Malicious software, and where, specifically, is it
located?

>> Should I download Malicious Software Removal Tool or is it not necessary
>> with Vista Security Protection?
[quoted text clipped - 4 lines]
>> no where to be found. Searched the given address for it and cannot get to
>> it, please any suggestions would be appreciated.
mommacrystal - 29 Jul 2007 23:38 GMT
Detection name: Dialer_Coulomb
C:\Users\Crystal\AppData\Local\Temp\$03DC67E1.t$m
When I get ot the Temp folder and open it, the file is not there, I now have
five of these with different numbers, smae address just different #'s. Any
help would be appreciated, have ran Avast, Trend, Windows Defender, AVG, I
found that AVG Spyware was now compatibel with Vista. It wasn't a few months
ago so I am now scanning with that, hopefully it will kick it out for me. I
really don't knwo that much about spyware so any info would be apreciated
much, thanks!

Here is the full message I am getting:

Notification



Real-time Spyware Protection
Real-time Spyware Protection has detected spyware and performed the action
specified.  

.
Action taken: Removal of a malicious program has failed. You must delete the
dangerous file yourself using Windows Explorer.
.
Incident name:
C:\Users\Crystal\AppData\Local\Temp\$03DC67E1.t$m
Detection name: Dialer_Coulomb
User name: Crystal
Note: If Search for and clean Trojans is turned on and executed after
scanning, click Next to view the final action taken.

> What is the name of the Malicious software, and where, specifically, is it
> located?
[quoted text clipped - 7 lines]
> >> no where to be found. Searched the given address for it and cannot get to
> >> it, please any suggestions would be appreciated.
dean-dean - 30 Jul 2007 00:32 GMT
Try this:

First, in Control Panel > Folder Options, on the View tab, do three things.
Choose to "Show hidden files and folders", and UN-check "Hide protected
operating system files (Recommended)".  If you have "Hide extensions for
known file types" checked,  UN-check that (Apply, OK).

Press the Windows key + R on your keyboard.  Copy and Paste this into the
Run box:

C:\Users\Crystal\AppData\Local\Temp

Click OK.  Do you see the file $03DC67E1.t$m ?  Or other files with $ in
their names?  The files might be "dimmed", which is Explorer's way of
showing you the files are hidden.  Delete all the contents of the Temp
folder, if you can.  Then right-click a blank spot inside the folder, and
choose Refresh.  Do files come back?  If so, repeat your scans and try
deleting files in this folder in Safe Mode (without Networking).

> Detection name: Dialer_Coulomb
> C:\Users\Crystal\AppData\Local\Temp\$03DC67E1.t$m
[quoted text clipped - 44 lines]
>> >> to
>> >> it, please any suggestions would be appreciated.
mommacrystal - 30 Jul 2007 01:18 GMT
I tried it but it didnt' work, you think it's a possibility that maybe it's
glitch? I don't think it is but it is an option I guess, tahks so much for
trying, I'm still trying, Blessed be.

> Try this:
>
[quoted text clipped - 63 lines]
> >> >> to
> >> >> it, please any suggestions would be appreciated.
mommacrystal - 31 Jul 2007 04:18 GMT
I replied yesterday but for some odd reason it didnt' post, sorry, thanks for
the advice but it didn't do it, the files aren't int eh designated folder
that it says there in. Coould it be a glitch?

> Try this:
>
[quoted text clipped - 63 lines]
> >> >> to
> >> >> it, please any suggestions would be appreciated.
dean-dean - 31 Jul 2007 05:52 GMT
Yes, it could be a glitch, or a false positve.  That's what I'm thinking.
When you run TrendMicro, make sure your definition files are up to date.
Run the scan again, with the C:\Users\Crystal\AppData\Local\Temp folder
open.  See if anything shows up, while the scan is running.  Keep the Temp
folder as empty as possible, so that you can see what's going on during the
scan.

>I replied yesterday but for some odd reason it didnt' post, sorry, thanks
>for
[quoted text clipped - 79 lines]
>> >> >> to
>> >> >> it, please any suggestions would be appreciated.
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.