Jump to content

TheSpirit

Members
  • Posts

    6
  • Joined

  • Last visited

Reputation

0 Neutral

Contact Methods

  • Website URL
    http://
  • ICQ
    0

Profile Information

  • Location
    Denmark
  1. Hi Marcin. I suppose you are right. After all, it took me more than a month to realize that something was missing. Awfully quiet....
  2. I keep a copy of the Eicar test file on my system drive to verify that malware scanners detect and report this correctly. All the others do, but not MBAM. Is this too simple or irrelevant?
  3. Yes indeed, you are right, and it does appear in the list of drivers in Process Explorer, but only during the scan. Thank you.
  4. Thanks again exile, I did manage to find a mysterious handle in Process Explorer. Process Monitor is interesting, of course. I'll try that later. Millions of events, I'm sure.
  5. Thanks exile, but then I should be able to find it in Process Explorer as a driver in the System process like all other drivers, or listed on Autoruns' driver tab, right? This is a bit like tracking malware.
  6. New user running MBAM free on XP pro SP2+. Everything works just fine, and when I run a scan, this event pops up in the system event log: Event Type: InformationEvent Source: Service Control ManagerEvent Category: NoneEvent ID: 7035Date: 2008-12-07Time: 08:49:00User: **********\AdministratorComputer: **********Description:The MBAMSwissArmy service was successfully sent a start control.It looks fine to me, so I tried to trace this service using Windows and Sysinternals tools, but this seems to be impossible. So, where is it? Rootkit?
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.