Jump to content

Jekko

Staff
  • Posts

    365
  • Joined

  • Last visited

Posts posted by Jekko

  1. 3 hours ago, Acrobaze said:

    Hi @TempLost,

    I was in the same case as you and after launching the .bat file, chameleon is visible now and the protection button has become active again.
    But since I had renamed the desktop icon, I can not test the auto-protection easily anymore. Have you done it?

    @Acrobaze - That was my mistake!  Previously in MBAM 2.x we protected the desktop shortcut for malwarebytes.  Another way to test if self-protection is working is, while it's turned on, to create a new folder in the Malwarebytes Program Files directory.  C:\Program Files\Malwarebytes\Anti-Malware

    @TempLost - Thank you for your response!  I'll look into the 2 sets of logs you've sent, but if you have any clear instructions on program compatibility or conflict please don't hesitate to respond.  You originally opened this thread for Web Protection issues so we can continue the conversation here.

  2. Thanks for the logs @TempLost.  Unfortunately nothing clear has been found from procmon.  We did see there were accesses by aswidagenta.exe which is Avast Identity Protection software.  Could you try disabling Avast temporarily and running the batch script I gave you to see if self-protection can be enabled?

    Also, can I ask you to enable Event Log Data in MBAM's Application settings?  This will give more advanced logging to the MBAMSERVICE.log file.

    Please try those steps and attach your mbamservice.log file afterwards.

  3. Here is the process to get logs from ProcessMonitor:

    1. Run procmon.exe.
    2. Agree to the License Agreement.
    3. Process Monitor will open and being collecting events from your computer.
      procmon_running.png.967b0a733f78e7ab46da0878bc86b1d5.png
    4. Follow the other steps I've outlined earlier regarding SP_Replace.bat:
      1. Run SP_Replace.bat as Administrator.
      2. Wait for MBAM's UI to open.
      3. Turn on/off self-protection in MBAM's Protection Settings.
    5. Click on the save icon.
      procmon_save.png.89bca94a76c0705131798b1a2b1e496d.png
    6. Look at the path for Logfile.PML.
      procmon_path.png.1794ed5e408f08abfcc0071faf94d8b0.png
    7. Click OK.
    8. Zip and Attach Logfile.PML back here on the forums.

    If the file is too big, I can provide a box.com folder for you to upload to.  Please let me know if you have any questions.

  4. Thanks for the logs @TempLost.  Your cooperation has been great!  For some reason it looks like mbamchameleon.sys is being blocked when it should be created.  Could you try the following?

    1. Download ProcessMonitor.
    2. Run ProcessMonitor.
    3. Run SP_Replace.bat as Administrator.
    4. Wait for MBAM's UI to open.
    5. Turn on/off self-protection in MBAM's Protection Settings.
  5. 3 hours ago, TempLost said:

    No difference, I'm afraid - and no sign of MBAMChameleon.sys. I ran the .bat file as Administrator.

    @TempLost

    Do you still see self-protection enabled in the UI?

    Can you rename the shortcut for MBAM on desktop?  This would prove to us if chameleon is protecting MBAM's files correctly.

  6. Could you try the following?

    1. Open cmd.exe with admin credentials and run the command: net stop mbamservice
    2. Delete the file C:\ProgramData\Malwarebytes\MBAMService\config\SpConfigFile.json
    3. Open MBAM.

    Adversely, if you do not know how to do those steps, I am also attaching a file "SP_Replace.bat" which will do those steps listed.  You will need to run SP_Replace.bat as administrator for it to work correctly.

    After doing those steps, and MBAM is running again, please check if MBAMChameleon.sys has been replaced.

    SP_Replace.zip

  7. @TempLost,

    Thank you for the reply.  Please try turning off self-protection, then turn it on again.  This should replace mbamchameleon.sys.  Then attempt to turn on self-protection early start.  If that does not turn on still, that means something is blocking mbam from replacing mbamchameleon.sys.

  8. Please keep it enabled.  It will protect your Malwarebytes files from being modified or deleted.

    The Engineering team has identified which file is causing this issue.  "AOL Downloads\<subfolder>\comps\vwpt\Vwpt.exe"

    Until we can fix this, as @dcollins mentioned, please keep your exclusion for the AOL Downloads folder.

    Thank you so much for your help with us on this issue!

  9. @TOH,

    Try these steps for running Procdump.

    1. Download the following Procdump.zip file: Procdump.zip
    2. Place procdump.zip in C:\
    3. Extract procdump.zip.
    4. Check that the extracted files are in the directory "C:\Procdump"
    5. Right click "mbamservice_procdump.bat" and select Run as administrator.
      • If you did the steps correctly you will see the following:
        procdump_running.png
    6. Run a threat scan with MBAM 3.0.
    7. When MBAMSERVICE.exe crashes it should close that command window and generate a memory dump file in "C:\Procdump".

    Please follow these directions because "mbamservice_procdump.bat" needs to be run in the directory "C:\Procdump" for it to work correctly.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.