Jump to content

wildman424

Malware Hunters
  • Posts

    1,679
  • Joined

Posts posted by wildman424

  1. @LiquidTension

    I still can't get your support tool to finish and produce mbst-grab-results.zip for you.I don't know what else to try to get your support tool to do its thing. Windows built in zip tool works fine. I use 7zip it works fine.  Where is it trying to create this file? Could I possibly have some folder/file permissions out of wack somewhere?

    Untitled.jpg.41eb4227d850705f0a18ab6ce2c547fd.jpg

     

  2. I have no ideal what was going on when the crash occurred. I may have been away from the computer when it happened. I didn't find the crash dump until I was about to delete all temp files with Ccleaner, it was in the results list or I would have missed it.  I did have a strange system crash last night that was difficult to recover from. No ideal what caused that, There isn't any crash dumps. I'm still looking through EventViewer.

    I haven't been able to get the support tool to zip the logs, It runs up to that point and then fails. I will try again to get those logs into you.

  3. I was getting ready to delete all my temp files, I found a mbam.exe crash dump.  Created this morning 4/14/2020 7:56am

    I'm going to upload for you. Question is should I password protect it and pm you the password, or just attach the 7zip archive as is?

     

    filename:   mbam.exe.10136.dmp

  4. Good news, I don't think it was Malwarebytes causing the issues I had this morning. I found some incorrect settings that I believe may have caused it. I will keep an eye on it over the next couple days and report back if it occurs again. I did notice that once I was online, it stayed online until I disabled the adapter using  "function key + F2". Then i had to fight with it to get online again. But I haven't been able to get it to happen again.

    I still can not get the support tool to zip the logs. FRST runs fine though.

  5. 3 hours ago, AdvancedSetup said:

    If you've rebooted the computer and Internet access is working in general you should be able to create the logs from the MBST tool

     

    I got stuck in a shutdown and restart loop there for a while, not sure what caused that! It didn't crash the system or anything, just randomly logged me out, shutdown and restarted. It did it 2 or 3 times when I was doing a reinstall.

    I'm trying again to get those logs for you right now.  I haven't been able to reproduce the issue again, and i have uninstalled and reinstalled and updated 3 or 4 times. Give it a min, see if I can get those logs and I'll shutdown and restart again, now that I have v4.1.0.56  component version 1.0.867 installed again.

    This component version 1.0.875 is the current beta correct?

  6. I spent about an hour this morning trying to connect to the internet. It didn't occur to me that Malwarebyes could be the problem.  Is there a known issue with MBAM causing DNS errors and loss of internet connectivity?

    Malwarebytes Version: 4.1.0.56

    Component Version:    1.0.875

    Update Package:           1.0.22398

    Will try a few different things and see if what I experienced is related to the issue being discussed here.

    In the mean time I wasn't able to get the support tool to provide the logs

    Capture.JPG.5fa218b5c84006e83e64d1a2a87864f9.JPG

     

     

     

  7. 41 minutes ago, BBK said:

    Update from MBAM? Update from Virus Protection? Microsoft?  I do know something changed between midnight last night and 2:38AM. If resolved could you please update? Thanks.

    My issue was with my firewall. I had to uninstall and do a clean reinstall of Malwarebytes because I had forgotten my password for the access policies I had set. Somewhere during the process of reinstalling the settings in my firewall had gotten screwed up. So right after the reinstall of MBAM it wouldn't update. That's what I was troubleshooting.

    The issue you're experiencing might be different or have a different cause. You mentioned that you have contacted support, so you might want to wait until they get back in contact with you, or start a new topic here: https://forums.malwarebytes.org/forum/41-malwarebytes-anti-malware-help/   so someone from the support team can work with you one on one about the issue.

    You can try to do a clean removal & clean reinstall, that sometimes fixes a lot of problems. Instructions on how to do that are here:

    https://forums.malwarebytes.org/topic/146017-mbam-clean-removal-process-2x/

     

  8. 23 minutes ago, BBK said:

    Pinged from command prompt

    
    data-cdn.mbamupdates.com

    No lost packets

    Its online and responding. What does a tcpview log reveal?

    I get the following:

    	mbam.exe    1060    TCP    wildthang1.hsd1.wv.comcast.net    1705    ec2-23-21-118-177.compute-1.amazonaws.com    https    CLOSE_WAIT                                        
    	mbam.exe    1060    TCP    wildthang1.hsd1.wv.comcast.net    2629    vip098.ssl.hwcdn.net    https    ESTABLISHED           
    	

    You may want to start your own topic so someone from the Malwarebytes Team can help you. If you append to my topic your post might accidentally get overlooked.

     

  9. Last Scan could be one of three listings:

    • Last Scan:Threat
    • Last Scan: Custom
    • Last Scan: Hyper
    "x" Days ago indicates when the Scan was done

     

    Malwarebytes Help File has always been in "All Program" under Malwarebytes Anti-Malware and expanding the folder.   NOTE: It has not been updated to reflect the 2.0 series

     

    What he was saying the way its worded  Last Scan: Threat 3 days ago may be confusing to a user not familar with the MBAM GUI. At a glance it sounds and looks as if a threat was detected during the last scan, when that is not the case. It is just the type of scan that was ran last. If it was reworded Last Scan: Threat Scan 3 days ago it might cut any potential confusion.

     

    The help file and its shortcut in "All Programs" is still there, although as you pointed out the help file has not been updated to reflect the 2.0 series yet. A shortcut to it using that button in the "About" screen makes sense to me, It can be coded to launch any shortcut or link. Having it launch the local helpfile (mbam.chm) gives the user another shortcut the helpfile. The helpfile might be able to answer the users question without having to request support. Adding a couple of links back to the support site next to it isn't hard to add.

  10. I'd like a 'Help' button (in the About screen) to be 1. Blue like all other links 2. Point to Support Page: http://www.malwarebytes.org/support/ Which ironically starts with the words Need help..

    Just opening the main site page is not helpful.

    Shouldn't this button actually open the help file ( mbam.chm ) that's included with the instalation instead of being a link?

    If there is going to be a link there, I suggest that it be a link to  http://www.malwarebytes.org/support/  or  The Help Desk Portal or maybe even both.

     

     

     

     

    On the bottom of my Dashboard I have: "Last Scan: Threat 3 days ago"

    I actually don't like the word 'threat', but since you are using it please state 'Threat Scan'. (as it is stated under Scan). This will change my 'Threat 3 days ago' (OMG!) to 'Threat Scan 3 days ago'.

     

    I was thinking the same thing. "Last Scan: Threat 3 days ago" should be "Last Scan: Threat Scan 3 days ago"  The wording might be a little confusing as it is.

     

     

     

    When I right click on the taskbar icon and select 'Check for Updates', I don't actually necessarily want the entire program to startup and then remain in front of me (especially if I'm viewing other things). Ideally I'd prefer an update box that just blinks away at end, or has an OK box. The entire program does not need to display.

    I'd rather see an update box simular to the old one in previous versions.

     

    Love the new GUI by the way. ;)

  11. I had a crash. This is on my laptop.

     

    Microsoft Windows 7 Ultimate    
    Version    6.1.7601 Service Pack 1 Build 7601    
    Manufacturer    Dell Inc.    
    System Model    Inspiron N5110    
    System Type    x64-based PC    
    Processor    Intel® Core i5-2410M CPU @ 2.30GHz, 2301 Mhz, 2 Core(s), 4 Logical Processor(s)

     

     

  12. Isn't MBAM supposed to detect this?

     

    I was told that the only reason to run MBAM along with an AV is to get protected against this kind of zero-day.

    With so many differant variants of malware out there in the wild and thousands of new ones being created and mutated everyday it is very difficult and even impossible to detect them all. While a single definition can detect thousands of multiple varients of malware there will always be several thousand, maybe even millions not yet discovered and known. We try to discover, analyze and detect as many as we can but unfortunately the bad guys are always finding new ways to keep their malware alive.

     

     

    Hi, rohunsaker

     

    I highly recommend you follow the instuctions left for you by daledoc1 and have a malware removal expert check it out. These ransomware infections can be very complex and usually copy multiple copies of themselves to various locations and use multiple start up points in the registry and other places to launch themselves.

  13. Yes, FileASSASSIN is very old and pre-dates x64 so it does not support shell menu integration on x64 Windows versions.

     

    That's what I thought Sam. I wasn't 100% sure. I been looking for a temp fix for this so I'll try adding the reg keys for the shell menu into the native x64 shell keys. Also noticed that if you try to register or unregister FileASSASSIN.dll using REGSVR32 to call DllRegisterServer or DllInstall it ends in an error, but FileASSASSINExt.dll will register just fine as long as you call DllRegisterServer ( It can't find the entry-point if you call DllInstall )   Could that prevent me from just adding the reg keys for the shell menu into the registry to get it to work?

     

     

     

     

    I know you guys  are really busy and currently have more important projects on the agenda, but is there a possibility to get FileAssassin an update in the near future?

     

     

    Thanks  :)

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.