Jump to content

Malwarebytes popup meaning& what2do?

Just re installed malwarebytes from the interwebs because my old malwarebytes just magicaly uninstalled itself or something when i tried to update it.

 

Soooo... my new malwarebytes keeps having this message pop up every 5 seconds. i dont know what it means or how to get rid of it. 

 

 

I have done scans with 

hitman pro

malwarebytes

glary utilities cleanup

avg

spybot s&d

 

And none have found any threats 

 

 

It i think it might be related to my vpn privateinternetaccess.com as i have seen rubyw.exe before related to the vpn with issues i had before

post-40649-0-06448500-1412097212.png

Link to comment
Share on other sites

Link to post
Share on other sites

Looks like you got a major virus there bud (there's a program on  your computer that is trying to send data to an external site every 5 minutes). Time to take the appropriate actions to fix it.

Link to comment
Share on other sites

Link to post
Share on other sites

have you scanned, malwarebytes actively tries to kill off crap which is trying to be a threat to your pc.

cpu: intel i5 4670k @ 4.5ghz Ram: G skill ares 2x4gb 2166mhz cl10 Gpu: GTX 680 liquid cooled cpu cooler: Raijintek ereboss Mobo: gigabyte z87x ud5h psu: cm gx650 bronze Case: Zalman Z9 plus


Listen if you care.

Cpu: intel i7 4770k @ 4.2ghz Ram: G skill  ripjaws 2x4gb Gpu: nvidia gtx 970 cpu cooler: akasa venom voodoo Mobo: G1.Sniper Z6 Psu: XFX proseries 650w Case: Zalman H1

Link to comment
Share on other sites

Link to post
Share on other sites

Go to the file they are showing and delete it ?

Or stop visiting the website that cause this to popup because it's obviously bad.

CPU: AMD Ryzen 3700x / GPU: Asus Radeon RX 6750XT OC 12GB / RAM: Corsair Vengeance LPX 2x8GB DDR4-3200
MOBO: MSI B450m Gaming Plus / NVME: Corsair MP510 240GB / Case: TT Core v21 / PSU: Seasonic 750W / OS: Win 10 Pro

Link to comment
Share on other sites

Link to post
Share on other sites

Yeah, do a scan....

Or if that doesn't show anything, go to that address. (I'm not respsonsible for any damages caused by this post)

Link to comment
Share on other sites

Link to post
Share on other sites

it pops up even though i just restarted my computer and have opened nothing. 

 

Ill try to see what the file thing is tho - I tried deleting the folder but i cant as its alredy in use it says. donno what to do

Go to the file they are showing and delete it ?

Or stop visiting the website that cause this to popup because it's obviously bad.

Link to comment
Share on other sites

Link to post
Share on other sites

it usually means that the program listed in that specific process is trying to access an ad from a web server that has been flagged as having malware on it. They can mostly be ignored, but It just goes to show how many ads out there are loaded with malware. But every now and then if it is a process you didn't install (not part of a legit program) then you could have a virus or malware and should do a full scan.

 

Examples are: the ads utorrent places while running, ads served to websites like cnet etc, some programs that display ads to pay for the content.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

it usually means that the program listed in that specific process is trying to access an ad from a web server that has been flagged as having malware on it. They can mostly be ignored, but It just goes to show how many ads out there are loaded with malware. But every now and then if it is a process you didn't install (not part of a legit program) then you could have a virus or malware and should do a full scan.

 

Examples are: the ads utorrent places while running, ads served to websites like cnet etc, some programs that display ads to pay for the content.

Im not running utorrent, not downloaded anything from cnet etc (i always use the programs own website for downloads)

And this message pops up even when i have nothing open, newly restarted pc.

 

I did a scan with malwarebytes and it came up with nothing

 

Also have done scans with spybot s&d + avg antivirus

Link to comment
Share on other sites

Link to post
Share on other sites

HitmanPro to the rescue

 

Registher in the settings window with your mail address (You won't get spam) and do a scan.

 

The IP is found in http://www.stopforumspam.com/ipcheck/37.221.165.196 which leads me to believe the file is part of malware.

 

If you still can not delete the file, go to task manager and stop the process rubyw.exe from running, then delete the folder.

Link to comment
Share on other sites

Link to post
Share on other sites

Im not running utorrent, not downloaded anything from cnet etc (i always use the programs own website for downloads)

And this message pops up even when i have nothing open, newly restarted pc.

 

I did a scan with malwarebytes and it came up with nothing

 

Also have done scans with spybot s&d + avg antivirus

 

they were just examples, it happens because the ads your browser or another program is trying to display are being served from a flagged IP address. 

 

What is rubyw.exe? Is it part of a proxy or VPN type solution?

 

did you download it? is it part of another program you have installed?

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

Just re installed malwarebytes from the interwebs because my old malwarebytes just magicaly uninstalled itself or something when i tried to update it.

 

Soooo... my new malwarebytes keeps having this message pop up every 5 seconds. i dont know what it means or how to get rid of it. 

 

also i donno how safe it is to show you guys this with some ip stuff on it so please tell me if i should remove it if its problematicsssssss

go into add or remove programs remove anything that looks sketchy or you didnt remember downloading if you dont know google it. after that remove all and any antivirus / anti spy / anti malware. then go and download super anti spyware. http://www.bleepingcomputer.com/download/superantispyware/dl/106/

then run it then try tdsskiller.

Bleepingcomputers.com is your friend in removing malware.

Project black out: cpu: athlon x4 750k @4.7ghz, Mobo: asrock fm2+ a55 vg3+, ram: 1x 8gb hyperx 1866mhz, video card: 1x saphire radeon r9 270x, Storage: 1tb hdd ssd in the future,  cooling: 2 noctua 120mm fans 1 on rad one front intake.

Link to comment
Share on other sites

Link to post
Share on other sites

Ill try to see what the file thing is tho - I tried deleting the folder but i cant as its alredy in use it says. donno what to do

Restart in safe mode (f8 at boot, right after the POST but before Windows boots) or use a Linux distro like Mint (put the DVD/USB key in, should automatically start in live mode) to access and delete the file from outside of windows.

CPU: AMD Ryzen 3700x / GPU: Asus Radeon RX 6750XT OC 12GB / RAM: Corsair Vengeance LPX 2x8GB DDR4-3200
MOBO: MSI B450m Gaming Plus / NVME: Corsair MP510 240GB / Case: TT Core v21 / PSU: Seasonic 750W / OS: Win 10 Pro

Link to comment
Share on other sites

Link to post
Share on other sites

they were just examples, it happens because the ads your browser or another program is trying to display are being served from a flagged IP address. 

 

What is rubyw.exe? Is it part of a proxy or VPN type solution?

 

did you download it? is it part of another program you have installed?

 

 

now that you mention it i have seen rubyw.exe before and i -think- that it was related to vpn privateinternetaccess.com im paid for. tek syndicate uses it.

 

Im not connected to the vpn though so i dont know whats going on

 

 

 

I have done scans with 

hitman pro

malwarebytes

glary utilities cleanup

avg

spybot s&d

 

And none have found any threats 

Link to comment
Share on other sites

Link to post
Share on other sites

now that you mention it i have seen rubyw.exe before and i -think- that it was related to vpn privateinternetaccess.com im paid for. tek syndicate uses it.

 

Im not connected to the vpn though so i dont know whats going on

 

 

 

I have done scans with 

hitman pro

malwarebytes

glary utilities cleanup

avg

spybot s&d

 

And none have found any threats 

 

I think you will find what is happening is that because it's a VPN, Even though it is not connected, it's probably still recreating itself as a new process and causing malwarebytes to think its a pup (potentially unwanted program).  It's fine, unless someone who knows more than me chimes in with better information, it's more than likely just a false positive.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

This is a problem with privateinternetaccess. It polls with random servers to check it's DNS settings. Nothing to be scared about, but I recommend using a OpenVPN client and use that to connect to PIA.

 

Check this topic: https://forums.malwarebytes.org/index.php?/topic/143933-mbam-pro-blocks-private-internet-access-pia-vpn-rubywexe/

// TODO: Update signature to include PC buid.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×