Jump to content

danburrito

Honorary Members
  • Posts

    59
  • Joined

  • Last visited

Posts posted by danburrito

  1. What happens when stop MBAE protection and specify a different download location, then enable protection again? Does the issue persist?

    You could try resetting the download folder.

     

    Type about:config in the address bar and confirm the warning message.

    In the search field, enter browser.download, you will find a few entries:

     

    browser.download.dir

    browser.download.downloadDir

    browser.download.folderList

    browser.download.lastDir

    browser.download.useDownloadDir

     

    If any of these have a status of user set, right click the entry and click 'reset' in the menu.

     

    Does it happen when downloading different file types? E.g. .exe, .pdf, .doc, .zip, etc.?

  2. I do not have a lot of junk plugins or extensions in FF so I doubt that is the problem. And again, this is with a FRESH FF 27.0 install, even with a clean test profile. After testing the clean profile I did restore bookmarks, etc from a Mozilla backup of my old profile that was made before removing FF. I will create another clean test profile and report results.

     

    Have you tried running Firefox in "SafeMode" yet? Also, it might help if you would list your extensions and plugins. It's not a clean profile anymore when you restore certain functions from an old backup.

  3. After doing a little expermenting with Process Lasso and Anti-Exploit's processes I found something that may be of concern. I wanted to see what would happen if A-E's processes were terminated and then restarted without doing a full reboot. First I right clicked on the icon and stopped the protection, then exited the program. This killed mbae.exe. Next I used Process Lasso to force terminate mbae-svc.exe. I then attempted to launch the program from the Desktop icon. Only mbae.exe would launch and the sys tray icon was not present. This makes it obvious that mbae-svc.exe must remain running during operation.  A full reboot corrects this of course. I was thinking this is less than ideal from a IT security standpoint. Are there CMD commands one could use to launch or terminate one or both processes? If not perhaps a consideration for a future build.

     

    ;)

    post-44148-0-30593100-1392825560_thumb.p

  4. Two suspected FPs in a created WinRAR SFX archive:

    Malwarebytes' Anti-Malware 1.46

    www.malwarebytes.org

    Database version: 4635

    Windows 6.1.7600

    Internet Explorer 8.0.7600.16385

    9/16/2010 9:11:07 PM

    mbam-log-2010-09-16 (21-11-07).txt

    Scan type: Quick scan

    Objects scanned: 3

    Time elapsed: 1 second(s)

    Memory Processes Infected: 0

    Memory Modules Infected: 0

    Registry Keys Infected: 0

    Registry Values Infected: 0

    Registry Data Items Infected: 0

    Folders Infected: 0

    Files Infected: 2

    Memory Processes Infected:

    (No malicious items detected)

    Memory Modules Infected:

    (No malicious items detected)

    Registry Keys Infected:

    (No malicious items detected)

    Registry Values Infected:

    (No malicious items detected)

    Registry Data Items Infected:

    (No malicious items detected)

    Folders Infected:

    (No malicious items detected)

    Files Infected:

    D:\_Disk A\Comodo Dragon v4.1.1.12_settings.exe (Backdoor.Bot) -> No action taken.

    D:\_Disk A\Opera v10.62_b3500_settings.exe (Backdoor.Bot) -> No action taken.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.