Jump to content


  • Posts

  • Joined

  • Last visited

Posts posted by Rsullinger

  1. Hey StroTech,

    This is happening because we are currently metering the updates for 1.10. We are slowly updating people to the latest version so all of your clients will eventually pull it and update to the latest version. So you are seeing 1 or 2 clients updating because of that. We do this with our updates to make sure that if there is an issue with the upgrade, we can stop it so it does not affect all machines. 

  2. Hey Heliae,


    That is odd, I would assume you would be seeing it more in your environment. Based on the logs, it does look like a memory error that some addons cause. I want to have you try a build on her machine to see if it fixes the issue. This build can be found here:


    If that does not fix it, then we may need to run a debug build. Let me know how that build does as we will be deploying that build out to everyone soon. 


  3. Hello Al,


    It looks like this is due to an issue that was fixed in one of our newer versions. I see that this is still on 1.8 of anti-exploit which is at least a version old. There is an option to turn on for the clients to update to the latest version automatically which should fix this. Since you are using the management console you can go into the policy> anti-exploit tab and enable the automatic updates option there. You can also test the latest beta build here which should fix it as well:




  4. Hello Stefanc,


    I will want to see some of the logs to see why this is happening. Can you follow the instructions here to collect the logs I will need:




    Also, to answer your question, if it is not popping up again, then we may have blocked the process it needed to run and it is not calling it again until our protection is disabled. We won't know if we will be able to exclude it until I get the logs though unfortunately. 

  5. Hey Marky200,


    Your version you are using is still valid. While you correct that there is a new test build (.37) on the forum, we have not pushed that out through automatic updates yet. One thing with 1.10 is that we opened up the premium shields to any free users now. So the subscription renewal would go toward the mb3 product. If you would like, I can have someone contact you about your subscription in a PM. 

  6. Hey Cliffs,

    The announcement should have some information on what was fixed in 1.10. A lot of it is opening up the premium features for free and our dynamic hooking (which is more for us at malwarebytes to help FP's). The rest have been bug fixes noted in the list. We will be posting the new updates out on the forums when it is available!

  7. Hello Hake,


    That is correct. Certain bit-defender applications cause a hooking conflict with anti-exploit installed side by side with it. So in that case, our dynamic config would disable that so they can work side by side. 

  8. Thank you for those! So it looks like there is a proxy set under the system account which we seem to be finding:


    ProxyEnable: [.DEFAULT] => Proxy is enabled.
    ProxyServer: [.DEFAULT] =>


    Is that something that may have been setup by the company on a network level? If not, once that is removed, then the clients will connect to the server like normal. 

  9. Hey King,


    Alright. We are detecting a proxy from something, you shouldn't be able to ping it but should be able to resolve it. It doesn't look like it is able to resolve it based on the logs. Do you mind running FRST on one of the machines. It will show me what is installed and if there is any proxy settings set on an account. Sometimes it may be on another account and we are detecting it from that. You can send me the FRST logs if you don't want to post it directly on the forums. To do this:


    1: Please download FRST from the link below and save it to your desktop:

    FRST 32-bit version: https://downloads.malwarebytes.com/file/FRST

    FRST 64-bit version: https://downloads.malwarebytes.com/file/FRST64

    2: Double-click the purple FRST icon to run the program. Click Yes when the disclaimer appears.

    3: Click the Scan button

    4: When the scan has finished, it will make 2 log files in the same directory the tool is run, FRST.txt and Addition.txt. Please attach both files in your reply.

  10. Hey King,

    This looks like a separate issue for this:


    System.Net.Http.HttpRequestException: An error occurred while sending the request. ---> System.Net.WebException: The remote server returned an error: (407) Proxy Authentication Required.


    Much like the 2008, it is trying to contact our sirius server but it is failing on proxy authentication. Do these computers have a proxy on them that must be met? if not, they may have something in the IE proxy settings that needs to be cleared. Some adware will do this for example. 

    If this is a proxy that the clients must use, during install of the product you can specify a proxy the client will use. That is mainly information for future use, for now, you would just need to go to the same directory as you collected the logs and run this instead:


    MBCloudEA.exe -proxy.server -proxy.port 906 -proxy.user Malware  -proxy.password Bytes


    Just replace the information there with the information of your actual proxy. After that, restart the service for Malwarebytes endpoint agent and it will connect to the server.

  11. Hey King,

    Is this server by chance on service pack 1 of 2008? It looks like it is not able to reach out and talk to our sirius.mwbsys.com address. The error it is giving that it does not have a common algorithm which normally points to a TLS/SSL issue. For 2008 at least, we have some instructions here on how to fix it if that is the case:




    Can you get the logs from one of the other endpoints as well so I can confirm that they are all having the same issue and not just 1 offs for each? 

  12. Hello,


    I want to have you collect me the diagnostic logs from the server so I can see why it is not collecting. You will have to run this command in command line:

    Note: you may need to load an admin command prompt to run the command.

    “C:\Program Files\Malwarebytes Endpoint Agent\MBCloudEA.exe –diag”

    You can do it by using:

    cd C:\Program Files\Malwarebytes Endpoint Agent\

    Then use:

    MBCloudEa.exe -diag




    This will save a file on the desktop called MBDiagnostics. Send me that file and I can see why your server is not connecting. 

  13. Hello Alex,


    They will indeed. The only thing you want to do to ensure that both of our products don't try to scan each other is put in mutual exclusions. So you would want to put BitDefenders file directories into our exclusion list and vice versa, you want to put these exclusions in theirs:



    You should not have to do anything else once you do that! 


Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.