Jump to content

scoutt

Honorary Members
  • Posts

    124
  • Joined

  • Last visited

Posts posted by scoutt

  1. There is a command scanner, this switch is not part of the help /? switch in EACmd.exe

    create a file called scan.txt (scan.txt is just an example) inside scan.txt add the path to scan i.e. c:\ or c:\temp etc...

    \ProgramFiles\Malwarebytes Endpoint Agent\UserAgent\ .\eacmd.exe -ContextScan="C:\temp\scan.txt"

     

  2. I see from the update page that we have a new version being pushed.

    Quote

    Malwarebytes Anti-Exploit 1.13.2.257

    Protection:
     
    •    Protection against new exploit attack vectors
     
    Stability/issues fixed:
     
    •    Fixed a bug in Chrome and Edge browser shields
    •    Fixed customer issues with MS Office applications
    •    Fixed customer issues with Bank plugins 
    •    Improved Logging capabilities
    •    Internal Product Improvements

    But apparently the "Fixed customer issues with MS Office applications" is now causing lots of HP driver issues when printing from word.  

    Quote

    Exploit payload process blocked BLOCK   C:\Windows\System32\rundll32.exe C:\WINDOWS\system32\spool\DRIVERS\x64\3\hpmsn130.DLL,MonitorPrintJobStatus \pjob=19 \pnameNW Corner HP LaserJet color M551        User             Microsoft Office Word   C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE      Attacked application: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE; Parent process name: explorer.exe; Layer: Application Behavior Protection; API ID: 207; Address: ; Module: ; AddressType: ; StackTop: ; StackBottom: ; StackPointer: ; Extra:

    Anybody else seeing these? Just started yesterday when users started updating. Changing the driver to a Universal driver fixes some of them.

  3. Thanks Exile, I tried the above commands but there isn't a file called mbamapi.exe in the install of the Nebula client or Anti-Malware. I also tried all the exe's in both locations and nothing gives a list of switches. So I don't think its there (yet) either. I have a call with an engineer so I will ask the same question.

     

    Appreciate the help though

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.