Jump to content

Rsullinger

Staff
  • Posts

    533
  • Joined

  • Last visited

Posts posted by Rsullinger

  1. Hey Jaws98,

     

    What is causing it is hard to say, but our program is blocking it because java is attempting to run a cmd/script of some sort. We don't care what it is running, just that it is trying to make that type of call. Just from that piece of code it doesn't look malicious. Just to be safe, you may want to try re-installing the java software and get it on the latest to see if it still occurs. 

  2. Hey everyone, 

     

    I am going to reach out to you to collect some debug logs on this issue. The development team wants to see how this is triggering. You should see a PM from me with some instructions on how to do this. 

     

    Thank you,

     

    Ron 

  3. Hey Sandy,

     

    It will not affect them. The log we write to will overwrite itself after a certain amount of data (this prevents it from being a huge file). It will not affect the user and they will never see it. Just need to make sure that when the alert happens, we collect the logs as it will overwrite if to much time has passed. 

  4. The program will install in the x86 directory that is correct. If it is doing it on numerous machines, then I would like to take a look further into it. I want to see if something in particular is causing this during the upgrade. Can you please collecting the logs from this post and attachthem here:

     

    https://forums.malwarebytes.com/topic/191468-readme-first-posts-here-need-to-include-mbae-logs/

     

    Thank you,

     

    -Ron

  5. Hey StroTech,

     

    That looks like it may have just left behind the un-install entry from the upgrade. If you open up the program and it is showing the correct version there, then it is just something that got left behind for some reason. If you want to clean it up, you can do it manually or run our clean tool to remove everything and install the latest version. If you want to do that, here is the clean tool:

    https://forums.malwarebytes.org/applications/core/interface/file/attachment.php?id=199258

    This is where you can find the latest version of mbae that you have upgraded to:

    https://malwarebytes.box.com/s/ll8vdfmuc46dkqbk9iuaqp6iik0t0nq4

    Let me know if you have any issues! 

  6. Thank you for the logs!

     

    So I reviewed it and it may be due to a setting we have that causes cmd to not be ran if Java calls it. Sometimes infections use this vector so we have that setting to block it on by default. However, you can disable this setting if you know for sure this script is good. To do this, open up the mbae UI on the users machines (or go into the mbae tab in the policy if you are using mbmc) and go to the settings tab. Click on the advanced settings button and go to the java protection tab. Disable that first option for 'prevent web-based java command line' and test to see if it works. If you are pushing it from the console, it may take a bit to be pushed down to the client. 

     

  7. Hey MLAP,

     

    Exclusions are usually only done if there is an md5 of the file that can be excluded. I am not 100% sure why that block is occurring so I will need to see the full logs for the product. Do you mind collecting the logs from the instruction here:

     

    https://forums.malwarebytes.com/topic/191468-readme-first-posts-here-need-to-include-mbae-logs/

     

    You can send me the data in a PM if you do not wish to post it in the forum. 

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.