Jump to content

Local Game Server Blocked?!


Recommended Posts

Yesterday I installed malware bytes because I heard it was a good program. But just a few minutes ago, I received a message on my desktop saying "A malicious IP has been blocked" and under that, it said "Program: hl2.exe". What the heck?! And now I can't host a local server for me and my buddy. I've already put the program on the ignore list and it still is blocked. I also put it on the ignore list for Mcaffee. I have no idea why it doesn't work. The game is Garry's mod if that changes anything. I don't know what to do. I have also tried turning off all of my firewall. It working just fine yesterday.

Link to post
Share on other sites

  • Root Admin

Hello and :welcome:

 

Please open MBAM and go to the Logs tab.  Then locate the Protection logs from the past couple of days and post them back here please along with the following.

 

Please create an mbam-check log:

  • Download mbam-check.exe from here and save it to your desktop
  • Double-click on mbam-check.exe to run it, it should then open a log file
  • Please do not copy and paste the entire contents of the log into your next post, instead please attach the log CheckResults.txt file which should now be located on your desktop to your next post


 

 

 

Please run the following scanner and send back the logs.

Download DDS from one of the locations below and save to your Desktop
dds.scr
dds.com


Temporarily disable any script blocker if your Anti-Virus/Anti-Malware has it.
How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Once downloaded you can disconnect from the Internet and disable your Ant-Virus temporarily if needed.
Then double click dds.scr or dds.com to run the tool.
Click the Run button if prompted with an Open File - Security Warning dialog box.
A black DOS console should open and run for a moment. 


    When done, DDS will open two (2) logs:
  1. DDS.txt
  2. Attach.txt


  • Save both reports to your desktop
  • Please include the following logs in your next reply as an attachment: DDS.txt and Attach.txt
    You can ignore the note about zipping the Attach.txt file


 

 

Thanks

Link to post
Share on other sites

mbam-check result log version: 2.0.0.1000

Malwarebytes Version: REG_SZ  1.75.0.1300

Date Log Created: 07/24/13
Time Log Created: 19:39:32

User Account type: Administrator

64 bit Operating System

Product Name: REG_SZ  Windows 7 Home Premium

Current Build Number: 7601

Current Version Number: 6.1

Current CSDVersion: Service Pack 1

Proxy Status: No proxy is Set

Proxy Override:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\
 ProxyOverride REG_SZ  *.local

LAN Settings:
=============

only 'Automatically detect settings' is selected

SystemPartition:
================

HKEY_LOCAL_MACHINE\SYSTEM\Setup\
 SystemPartition REG_SZ  \Device\HarddiskVolume1

Balloon Tips Status:
====================

Enabled

Time Format Settings:
=====================

Should be:
  h:mm:ss tt
  AM
  PM
  :

Currently:
REG_SZ  h:mm:ss tt
REG_SZ  AM
REG_SZ  PM
REG_SZ  :

Language and Regional Settings:
===============================

ACP:  Language is English (United States)
MACCP:  Language is English (United States)
OEMCP:  Language is English (United States)

Startup Folders for Error_Expanding_Variables Check:
====================================================

All Users Startup Folder Exists.
Current User's Startup Folder Exists.

Terminal Services Status for (null) entries in PM logs and GetUserToken errors:
===============================================================================

TERMService:
==============
Type    : 32
State    : 1 (The service is not running.) (State is stopped)
WIN32_EXIT_CODE  : 1077
SERVICE_EXIT_CODE : 0
CHECKPOINT  : 0
WAIT_HINT  : 0

TermService Start is set to: 3 (Manual Startup)

Compatibility Flag Settings (Any MBAM file listings should be removed):
=======================================================================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\appCompatFlags\Layers
 C:\Program Files (x86)\Steam\steamapps\common\Age Of Empires 3\bin\age3.exeREG_SZ  WINXPSP3 RUNASADMIN
 C:\Program Files (x86)\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exeREG_SZ  WINXPSP3 RUNASADMIN
 C:\Program Files (x86)\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exeREG_SZ  WINXPSP3 RUNASADMIN
 C:\Program Files (x86)\Steam\steam.exeREG_SZ  ELEVATECREATEPROCESS
 C:\Program Files (x86)\Xfire2\Xfire.exeREG_SZ  ElevateCreateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\appCompatFlags\Layers
 C:\Program Files (x86)\Steam\steamapps\common\Age Of Empires 3\bin\age3.exeREG_SZ  WINXPSP3 RUNASADMIN
 C:\Program Files (x86)\Steam\steamapps\common\Age Of Empires 3\bin\age3x.exeREG_SZ  WINXPSP3 RUNASADMIN
 C:\Program Files (x86)\Steam\steamapps\common\Age Of Empires 3\bin\age3y.exeREG_SZ  WINXPSP3 RUNASADMIN

Malwarebytes Anti-Malware Shell Extension Block Check:
======================================================

 

MBAM Startup Entries:
=====================
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Service and Driver Status:
==========================

MBAMProtector:
==============
Type    : 2
State    : 4 (The service is running.) (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE  : 0
SERVICE_EXIT_CODE : 0
CHECKPOINT  : 0
WAIT_HINT  : 0

MBAMService:
==============
Type    : 16
State    : 4 (The service is running.)
WIN32_EXIT_CODE  : 0
SERVICE_EXIT_CODE : 0
CHECKPOINT  : 0
WAIT_HINT  : 0

MBAMScheduler:
==============
Type    : 16
State    : 4 (The service is running.)
WIN32_EXIT_CODE  : 0
SERVICE_EXIT_CODE : 0
CHECKPOINT  : 0
WAIT_HINT  : 0

  <--CAN NOT OPEN SC_HANDLE, SERVICE IS NOT RUNNING FOR: MBAMChameleon

MBAMProtector Registry Values:
==============================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector
 Type                          REG_DWORD  2
 Start                         REG_DWORD  3
 ErrorControl                  REG_DWORD  1
 ImagePath                     REG_EXPAND_SZ \??\C:\Windows\system32\drivers\mbam.sys
 Group                         REG_SZ  FSFilter Anti-Virus
 DependOnService               REG_MULTI_SZ FltMgr

 WOW64                         REG_DWORD  1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector\Instances
 DefaultInstance               REG_SZ  MBAMProtector Instance
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector\Instances\MBAMProtector Instance
 Altitude                      REG_SZ  328800
 Flags                         REG_DWORD  0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMProtector\Enum
 0                             REG_SZ  Root\LEGACY_MBAMPROTECTOR\0000
 Count                         REG_DWORD  1
 NextInstance                  REG_DWORD  1
MBAMService Registry Values:
============================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMService
 Type                          REG_DWORD  16
 Start                         REG_DWORD  2
 ErrorControl                  REG_DWORD  1
 ImagePath                     REG_EXPAND_SZ "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"
 DependOnService               REG_MULTI_SZ MBAMProtector

 WOW64                         REG_DWORD  1
 ObjectName                    REG_SZ  LocalSystem
 Description                   REG_SZ  Malwarebytes Anti-Malware service
 DelayedAutostart              REG_DWORD  0
MBAMScheduler Registry Values:
==============================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MBAMScheduler
 Type                          REG_DWORD  16
 Start                         REG_DWORD  2
 ErrorControl                  REG_DWORD  1
 ImagePath                     REG_EXPAND_SZ "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe"
 WOW64                         REG_DWORD  1
 ObjectName                    REG_SZ  LocalSystem
 Description                   REG_SZ  Malwarebytes Anti-Malware scheduler

MBAM DLL's and Runtime Files:
=============================

HKEY_CLASSES_ROOT\vbAcceleratorSGrid6.vbalGrid
 (Default):                    REG_SZ  vbAccelerator Grid Control
HKEY_CLASSES_ROOT\vbAcceleratorSGrid6.vbalGrid\Clsid
 (Default):                    REG_SZ  {C5DA1F2B-B2BF-4DFC-BC9A-439133543A67}

HKEY_CLASSES_ROOT\SSubTimer6.GSubclass
 (Default):                    REG_SZ  SSubTimer6.GSubclass
HKEY_CLASSES_ROOT\SSubTimer6.GSubclass\Clsid
 (Default):                    REG_SZ  {71A27032-C7D8-11D2-BEF8-525400DFB47A}

HKEY_CLASSES_ROOT\SSubTimer6.CTimer
 (Default):                    REG_SZ  SSubTimer6.CTimer
HKEY_CLASSES_ROOT\SSubTimer6.CTimer\Clsid
 (Default):                    REG_SZ  {71A27034-C7D8-11D2-BEF8-525400DFB47A}

HKEY_CLASSES_ROOT\SSubTimer6.ISubclass
 (Default):                    REG_SZ  SSubTimer6.ISubclass
HKEY_CLASSES_ROOT\SSubTimer6.ISubclass\Clsid
 (Default):                    REG_SZ  {71A2702F-C7D8-11D2-BEF8-525400DFB47A}

 

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A2702F-C7D8-11D2-BEF8-525400DFB47A}
 (Default):                    REG_SZ  SSubTimer6.ISubclass
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A2702F-C7D8-11D2-BEF8-525400DFB47A}\Implemented Categories
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A2702F-C7D8-11D2-BEF8-525400DFB47A}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A2702F-C7D8-11D2-BEF8-525400DFB47A}\ProgID
 (Default):                    REG_SZ  SSubTimer6.ISubclass
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A2702F-C7D8-11D2-BEF8-525400DFB47A}\Programmable
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A2702F-C7D8-11D2-BEF8-525400DFB47A}\TypeLib
 (Default):                    REG_SZ  {71A2702D-C7D8-11D2-BEF8-525400DFB47A}
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A2702F-C7D8-11D2-BEF8-525400DFB47A}\VERSION
 (Default):                    REG_SZ  1.0

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27032-C7D8-11D2-BEF8-525400DFB47A}
 (Default):                    REG_SZ  SSubTimer6.GSubclass
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27032-C7D8-11D2-BEF8-525400DFB47A}\Implemented Categories
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27032-C7D8-11D2-BEF8-525400DFB47A}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27032-C7D8-11D2-BEF8-525400DFB47A}\InprocServer32
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware\ssubtmr6.dll
 ThreadingModel                REG_SZ  Apartment
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27032-C7D8-11D2-BEF8-525400DFB47A}\ProgID
 (Default):                    REG_SZ  SSubTimer6.GSubclass
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27032-C7D8-11D2-BEF8-525400DFB47A}\Programmable
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27032-C7D8-11D2-BEF8-525400DFB47A}\TypeLib
 (Default):                    REG_SZ  {71A2702D-C7D8-11D2-BEF8-525400DFB47A}
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27032-C7D8-11D2-BEF8-525400DFB47A}\VERSION
 (Default):                    REG_SZ  1.0

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27034-C7D8-11D2-BEF8-525400DFB47A}
 (Default):                    REG_SZ  SSubTimer6.CTimer
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27034-C7D8-11D2-BEF8-525400DFB47A}\Implemented Categories
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27034-C7D8-11D2-BEF8-525400DFB47A}\Implemented Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27034-C7D8-11D2-BEF8-525400DFB47A}\InprocServer32
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware\ssubtmr6.dll
 ThreadingModel                REG_SZ  Apartment
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27034-C7D8-11D2-BEF8-525400DFB47A}\ProgID
 (Default):                    REG_SZ  SSubTimer6.CTimer
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27034-C7D8-11D2-BEF8-525400DFB47A}\Programmable
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27034-C7D8-11D2-BEF8-525400DFB47A}\TypeLib
 (Default):                    REG_SZ  {71A2702D-C7D8-11D2-BEF8-525400DFB47A}
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71A27034-C7D8-11D2-BEF8-525400DFB47A}\VERSION
 (Default):                    REG_SZ  1.0

HKEY_CLASSES_ROOT\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}
HKEY_CLASSES_ROOT\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}\1.1
 (Default):                    REG_SZ  vbAccelerator VB6 SGrid Control 2.0
HKEY_CLASSES_ROOT\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}\1.1\0
HKEY_CLASSES_ROOT\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}\1.1\0\win32
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware\vbalsgrid6.ocx
HKEY_CLASSES_ROOT\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}\1.1\FLAGS
 (Default):                    REG_SZ  2
HKEY_CLASSES_ROOT\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}\1.1\HELPDIR
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}\1.1
 (Default):                    REG_SZ  vbAccelerator VB6 SGrid Control 2.0
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}\1.1\0
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}\1.1\0\win32
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware\vbalsgrid6.ocx
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}\1.1\FLAGS
 (Default):                    REG_SZ  2
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{DE8CE233-DD83-481D-844C-C07B96589D3A}\1.1\HELPDIR
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware
HKEY_CLASSES_ROOT\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}
HKEY_CLASSES_ROOT\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}\1.0
 (Default):                    REG_SZ  vbAccelerator VB6 Subclassing and Timer Assistant (with configurable message response, multi-control support + timer bug fix)
HKEY_CLASSES_ROOT\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}\1.0\0
HKEY_CLASSES_ROOT\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}\1.0\0\win32
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware\ssubtmr6.dll
HKEY_CLASSES_ROOT\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}\1.0\FLAGS
 (Default):                    REG_SZ  0
HKEY_CLASSES_ROOT\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}\1.0\HELPDIR
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}\1.0
 (Default):                    REG_SZ  vbAccelerator VB6 Subclassing and Timer Assistant (with configurable message response, multi-control support + timer bug fix)
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}\1.0\0
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}\1.0\0\win32
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware\ssubtmr6.dll
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}\1.0\FLAGS
 (Default):                    REG_SZ  0
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{71A2702D-C7D8-11D2-BEF8-525400DFB47A}\1.0\HELPDIR
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware
HKEY_CLASSES_ROOT\Interface\{71A2702E-C7D8-11D2-BEF8-525400DFB47A}
 (Default):                    REG_SZ  _ISubclass
HKEY_CLASSES_ROOT\Interface\{71A2702E-C7D8-11D2-BEF8-525400DFB47A}\ProxyStubClsid32
 (Default):                    REG_SZ  {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{71A2702E-C7D8-11D2-BEF8-525400DFB47A}\TypeLib
 (Default):                    REG_SZ  {71A2702D-C7D8-11D2-BEF8-525400DFB47A}
 Version                       REG_SZ  1.0
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{71A2702E-C7D8-11D2-BEF8-525400DFB47A}
 (Default):                    REG_SZ  ISubclass
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{71A2702E-C7D8-11D2-BEF8-525400DFB47A}\ProxyStubClsid
 (Default):                    REG_SZ  {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{71A2702E-C7D8-11D2-BEF8-525400DFB47A}\ProxyStubClsid32
 (Default):                    REG_SZ  {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{71A2702E-C7D8-11D2-BEF8-525400DFB47A}\TypeLib
 (Default):                    REG_SZ  {71A2702D-C7D8-11D2-BEF8-525400DFB47A}
 Version                       REG_SZ  1.0
HKEY_CLASSES_ROOT\Interface\{71A27036-C7D8-11D2-BEF8-525400DFB47A}
 (Default):                    REG_SZ  __CTimer
HKEY_CLASSES_ROOT\Interface\{71A27036-C7D8-11D2-BEF8-525400DFB47A}\ProxyStubClsid32
 (Default):                    REG_SZ  {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{71A27036-C7D8-11D2-BEF8-525400DFB47A}\TypeLib
 (Default):                    REG_SZ  {71A2702D-C7D8-11D2-BEF8-525400DFB47A}
 Version                       REG_SZ  1.0
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{71A27036-C7D8-11D2-BEF8-525400DFB47A}
 (Default):                    REG_SZ  CTimer
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{71A27036-C7D8-11D2-BEF8-525400DFB47A}\ProxyStubClsid
 (Default):                    REG_SZ  {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{71A27036-C7D8-11D2-BEF8-525400DFB47A}\ProxyStubClsid32
 (Default):                    REG_SZ  {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{71A27036-C7D8-11D2-BEF8-525400DFB47A}\TypeLib
 (Default):                    REG_SZ  {71A2702D-C7D8-11D2-BEF8-525400DFB47A}
 Version                       REG_SZ  1.0
HKEY_CLASSES_ROOT\Interface\{1EDFD7DF-030D-4144-952E-9D7D86691CDB}
 (Default):                    REG_SZ  __vbalGrid
HKEY_CLASSES_ROOT\Interface\{1EDFD7DF-030D-4144-952E-9D7D86691CDB}\ProxyStubClsid32
 (Default):                    REG_SZ  {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{1EDFD7DF-030D-4144-952E-9D7D86691CDB}\TypeLib
 (Default):                    REG_SZ  {DE8CE233-DD83-481D-844C-C07B96589D3A}
 Version                       REG_SZ  1.1
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{1EDFD7DF-030D-4144-952E-9D7D86691CDB}
 (Default):                    REG_SZ  vbalGrid
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{1EDFD7DF-030D-4144-952E-9D7D86691CDB}\ProxyStubClsid
 (Default):                    REG_SZ  {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{1EDFD7DF-030D-4144-952E-9D7D86691CDB}\ProxyStubClsid32
 (Default):                    REG_SZ  {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Wow6432Node\Interface\{1EDFD7DF-030D-4144-952E-9D7D86691CDB}\TypeLib
 (Default):                    REG_SZ  {DE8CE233-DD83-481D-844C-C07B96589D3A}
 Version                       REG_SZ  1.1
MBAM Registry Settings and License Info:
========================================

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware
 advancedheuristics            REG_DWORD  1
 downloadprogram               REG_DWORD  1
 hidereg                       REG_DWORD  0
 detectp2p                     REG_DWORD  0
 detectpum                     REG_DWORD  1
 detectpup                     REG_DWORD  2
 updatewarn                    REG_DWORD  1
 updatewarndays                REG_DWORD  7
 useproxy                      REG_DWORD  0
 useauthentication             REG_DWORD  0
 contextmenu                   REG_DWORD  1
 reportthreats                 REG_DWORD  1
 startwithwindows              REG_DWORD  1
 startfsdisabled               REG_DWORD  0
 startipdisabled               REG_DWORD  0
 silentipmode                  REG_DWORD  1 <--MBAM SILENT IP MODE IS ENABLED
 autoquarantine                REG_DWORD  1
 notifyinstallprogram          REG_DWORD  1
 trialpromptshown              REG_DWORD  1
 autoquarantinenotify          REG_DWORD  1
 alwaysscanarchives            REG_DWORD  1
 InstallPath                   REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware
 dbdate                        REG_SZ  Wed, 24 Jul 2013 22:41:13 GMT
 dbversion                     REG_SZ  v2013.07.24.10
 programversion                REG_SZ  1.75.0.1300
 programbuild                  REG_SZ  consumer
 trialended                    REG_DWORD  0
 SchedulerQueue                REG_MULTI_SZ 6148, 30312293, 3882030272, 1, 23 | 30312574, 3187902289

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware (Trial)
 TrialId                        There is data here but it is hidden.
 StartDate                     REG_SZ  Wed, 24 Jul 2013 00:41:25 UTC
 EndDate                       REG_SZ  Wed, 07 Aug 2013 00:41:25 UTC
HKEY_CURRENT_USER\SOFTWARE\Malwarebytes' Anti-Malware
 alwaysscanfiles               REG_DWORD  1
 alwaysscanheuristics          REG_DWORD  1
 alwaysscanmemory              REG_DWORD  1
 alwaysscanregistry            REG_DWORD  1
 alwaysscanstartups            REG_DWORD  1
 autosavelog                   REG_DWORD  1
 openlog                       REG_DWORD  1
 defaultscan                   REG_DWORD  0
 terminateie                   REG_DWORD  0
 Language                      REG_SZ  English.lng
 selectedrives                 REG_SZ  C:\|D:\|Q:\|
HKEY_USERS\S-1-5-18\SOFTWARE\Malwarebytes' Anti-Malware
 alwaysscanfiles               REG_DWORD  1
 alwaysscanheuristics          REG_DWORD  1
 alwaysscanmemory              REG_DWORD  1
 alwaysscanregistry            REG_DWORD  1
 alwaysscanstartups            REG_DWORD  1
 autosavelog                   REG_DWORD  1
 openlog                       REG_DWORD  1
 defaultscan                   REG_DWORD  0
 terminateie                   REG_DWORD  0
HKEY_USERS\.DEFAULT\SOFTWARE\Malwarebytes' Anti-Malware
 alwaysscanfiles               REG_DWORD  1
 alwaysscanheuristics          REG_DWORD  1
 alwaysscanmemory              REG_DWORD  1
 alwaysscanregistry            REG_DWORD  1
 alwaysscanstartups            REG_DWORD  1
 autosavelog                   REG_DWORD  1
 openlog                       REG_DWORD  1
 defaultscan                   REG_DWORD  0
 terminateie                   REG_DWORD  0

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Malwarebytes' Anti-Malware_is1
 Inno Setup: Setup Version     REG_SZ  5.5.3-dev (a)
 Inno Setup: App Path          REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware
 InstallLocation               REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware\
 Inno Setup: Icon Group        REG_SZ  Malwarebytes' Anti-Malware
 Inno Setup: User              REG_SZ  Sam
 Inno Setup: Selected Tasks    REG_SZ  desktopicon
 Inno Setup: Deselected Tasks  REG_SZ  quicklaunchicon
 Inno Setup: Language          REG_SZ  English
 DisplayName                   REG_SZ  Malwarebytes Anti-Malware version 1.75.0.1300
 DisplayIcon                   REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
 UninstallString               REG_SZ  "C:\Program Files (x86)\Malwarebytes' Anti-Malware\unins000.exe"
 QuietUninstallString          REG_SZ  "C:\Program Files (x86)\Malwarebytes' Anti-Malware\unins000.exe" /SILENT
 DisplayVersion                REG_SZ  1.75.0.1300
 Publisher                     REG_SZ  Malwarebytes Corporation
 URLInfoAbout                  REG_SZ  http://www.malwarebytes.org
 NoModify                      REG_DWORD  1
 NoRepair                      REG_DWORD  1
 InstallDate                   REG_SZ  20130724
 MajorVersion                  REG_DWORD  1
 MinorVersion                  REG_DWORD  75
 EstimatedSize                 REG_DWORD  19743
Pending File Rename Operations:
================================
If any Malwarebytes Anti-Malware items are listed below, the user must reboot to complete a Malwarebytes Anti-Malware upgrade installation.

Scheduler Queue:
================

Scheduled Item: Update  Schedule Options: | Daily | Random 
Start Time: 2013-07-23 05:31  Repeating Every: 1  Recover if missed by: 23

 

Context Menu Entries:
=====================

HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers\MBAMShlExt
 (Default):                    REG_SZ  {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\MBAMShlExt
 (Default):                    REG_SZ  {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

HKEY_CLASSES_ROOT\MBAMExt.MBAMShlExt
 (Default):                    REG_SZ  MBAMShlExt Class
HKEY_CLASSES_ROOT\MBAMExt.MBAMShlExt\CLSID
 (Default):                    REG_SZ  {57CE581A-0CB6-4266-9CA0-19364C90A0B3}
HKEY_CLASSES_ROOT\MBAMExt.MBAMShlExt\CurVer
 (Default):                    REG_SZ  MBAMExt.MBAMShlExt.1
HKEY_CLASSES_ROOT\MBAMExt.MBAMShlExt.1
 (Default):                    REG_SZ  MBAMShlExt Class
HKEY_CLASSES_ROOT\MBAMExt.MBAMShlExt.1\CLSID
 (Default):                    REG_SZ  {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

HKEY_CLASSES_ROOT\Interface\{015FAC74-0374-494A-A02D-316D562C0FCE}
 (Default):                    REG_SZ  IMBAMShlExt
HKEY_CLASSES_ROOT\Interface\{015FAC74-0374-494A-A02D-316D562C0FCE}\ProxyStubClsid32
 (Default):                    REG_SZ  {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{015FAC74-0374-494A-A02D-316D562C0FCE}\TypeLib
 (Default):                    REG_SZ  {AFF1A83B-6C83-4342-8E68-1648DE06CB65}
 Version                       REG_SZ  1.0
HKEY_CLASSES_ROOT\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}
 (Default):                    REG_SZ  MBAMShlExt Class
HKEY_CLASSES_ROOT\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}\InprocServer32
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll
 ThreadingModel                REG_SZ  Apartment
HKEY_CLASSES_ROOT\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}\ProgID
 (Default):                    REG_SZ  MBAMExt.MBAMShlExt.1
HKEY_CLASSES_ROOT\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}\TypeLib
 (Default):                    REG_SZ  {AFF1A83B-6C83-4342-8E68-1648DE06CB65}
HKEY_CLASSES_ROOT\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}\VersionIndependentProgID
 (Default):                    REG_SZ  MBAMExt.MBAMShlExt

HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}
HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0
 (Default):                    REG_SZ  MBAMExt 1.0 Type Library
HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\0
HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\0\win64
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll
HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\FLAGS
 (Default):                    REG_SZ  0
HKEY_CLASSES_ROOT\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\HELPDIR
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0
 (Default):                    REG_SZ  MBAMExt 1.0 Type Library
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\0
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\0\win64
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\FLAGS
 (Default):                    REG_SZ  0
HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}\1.0\HELPDIR
 (Default):                    REG_SZ  C:\Program Files (x86)\Malwarebytes' Anti-Malware

MBAM Drivers:
=============

C:\Windows\system32\drivers\mbam.sys File Size: 25928     BYTES FileVersion: 1.60.2.0

Required Dependencies:
======================

BFE:
==============
Type    : 32
State    : 4 (The service is running.)
WIN32_EXIT_CODE  : 0
SERVICE_EXIT_CODE : 0
CHECKPOINT  : 0
WAIT_HINT  : 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE
 DisplayName                   REG_SZ  @%SystemRoot%\system32\bfe.dll,-1001
 Group                         REG_SZ  NetworkProvider
 ImagePath                     REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
 Description                   REG_SZ  @%SystemRoot%\system32\bfe.dll,-1002
 ObjectName                    REG_SZ  NT AUTHORITY\LocalService
 ErrorControl                  REG_DWORD  1
 Start                         REG_DWORD  2
 Type                          REG_DWORD  32
 DependOnService               REG_MULTI_SZ RpcSs

 ServiceSidType                REG_DWORD  3
 RequiredPrivileges            REG_MULTI_SZ SeAuditPrivilege

 FailureActions                REG_BINARY Binary Data

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BFE\Parameters
 ServiceDll                    REG_EXPAND_SZ %SystemRoot%\System32\bfe.dll
 ServiceDllUnloadOnStop        REG_DWORD  1
 ServiceMain                   REG_SZ  BfeServiceMain

fltmgr:
==============
Type    : 2
State    : 4 (The service is running.) (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE  : 0
SERVICE_EXIT_CODE : 0
CHECKPOINT  : 0
WAIT_HINT  : 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\FltMgr
 AttachWhenLoaded              REG_DWORD  1
 DisplayName                   REG_SZ  @%SystemRoot%\system32\drivers\fltmgr.sys,-10001
 Group                         REG_SZ  FSFilter Infrastructure
 ImagePath                     REG_EXPAND_SZ system32\drivers\fltmgr.sys
 Description                   REG_SZ  @%SystemRoot%\system32\drivers\fltmgr.sys,-10000
 ErrorControl                  REG_DWORD  3
 Start                         REG_DWORD  0
 Tag                           REG_DWORD  1
 Type                          REG_DWORD  2
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\FltMgr\Enum
 0                             REG_SZ  Root\LEGACY_FLTMGR\0000
 Count                         REG_DWORD  1
 NextInstance                  REG_DWORD  1
C:\Windows\system32\drivers\fltmgr.sys File Size: 289664    BYTES FileVersion: 6.1.7601.17514
C:\Windows\SysWOW64\comctl32.ocx File Size: 608448    BYTES FileVersion: 6.0.81.5
C:\Windows\SysWOW64\mscomctl.ocx File Size: 1066176   BYTES FileVersion: 6.0.88.62
C:\Windows\SysWOW64\olepro32.dll File Size: 90112     BYTES FileVersion: 6.1.7601.17514

List of MBAM Related Directories:
=================================

C:\Program Files (x86)\Malwarebytes' Anti-Malware
7z.dll                         File Size:    914432 BYTES FileVersion: 9.20.0.0
changes.txt                    File Size:       200 BYTES
license.rtf                    File Size:     17916 BYTES
mbam.chm                       File Size:    474148 BYTES
mbam.dll                       File Size:    527944 BYTES FileVersion: 1.70.0.0
mbam.exe                       File Size:    887432 BYTES FileVersion: 1.75.0.1
mbamcore.dll                   File Size:   1127496 BYTES FileVersion: 1.70.0.0
mbamext.dll                    File Size:     95304 BYTES FileVersion: 1.70.0.0
mbamgui.exe                    File Size:    532040 BYTES FileVersion: 1.70.0.0
mbamnet.dll                    File Size:   2191944 BYTES FileVersion: 1.70.0.0
mbampt.exe                     File Size:     40008 BYTES FileVersion: 1.70.0.0
mbamscheduler.exe              File Size:    418376 BYTES FileVersion: 1.70.0.0
mbamservice.exe                File Size:    701512 BYTES FileVersion: 1.70.0.0
ssubtmr6.dll                   File Size:     46416 BYTES FileVersion: 1.1.0.3
unins000.dat                   File Size:     15331 BYTES
unins000.exe                   File Size:    712264 BYTES FileVersion: 51.52.0.0
unins000.msg                   File Size:     11277 BYTES
vbalsgrid6.ocx                 File Size:    496976 BYTES FileVersion: 2.0.0.40

C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon
chameleon.chm                  File Size:    186068 BYTES
firefox.com                    File Size:    218184 BYTES
firefox.exe                    File Size:    218184 BYTES
firefox.pif                    File Size:    218184 BYTES
firefox.scr                    File Size:    218184 BYTES
iexplore.exe                   File Size:    218184 BYTES
mbam-chameleon.com             File Size:    218184 BYTES
mbam-chameleon.exe             File Size:    218184 BYTES
mbam-chameleon.pif             File Size:    218184 BYTES
mbam-chameleon.scr             File Size:    218184 BYTES
mbam-killer.exe                File Size:    896072 BYTES
rundll32.exe                   File Size:    218184 BYTES
svchost.exe                    File Size:    218184 BYTES
winlogon.exe                   File Size:    218184 BYTES

C:\Program Files (x86)\Malwarebytes' Anti-Malware\Languages
arabic.lng                     File Size:     21894 BYTES
belarusian.lng                 File Size:     26884 BYTES
bosnian.lng                    File Size:     27108 BYTES
bulgarian.lng                  File Size:     27574 BYTES
catalan.lng                    File Size:     28252 BYTES
chineseSI.lng                  File Size:     11024 BYTES
chineseTR.lng                  File Size:     11952 BYTES
croatian.lng                   File Size:     26670 BYTES
czech.lng                      File Size:     24874 BYTES
danish.lng                     File Size:     26582 BYTES
dutch.lng                      File Size:     28342 BYTES
english.lng                    File Size:     24542 BYTES
estonian.lng                   File Size:     25146 BYTES
finnish.lng                    File Size:     25950 BYTES
french.lng                     File Size:     29830 BYTES
german.lng                     File Size:     29894 BYTES
greek.lng                      File Size:     29300 BYTES
hebrew.lng                     File Size:     19362 BYTES
hungarian.lng                  File Size:     28666 BYTES
indonesian.lng                 File Size:     26854 BYTES
italian.lng                    File Size:     28194 BYTES
japanese.lng                   File Size:     16266 BYTES
korean.lng                     File Size:     14188 BYTES
latvian.lng                    File Size:     27100 BYTES
lithuanian.lng                 File Size:     27838 BYTES
norwegian.lng                  File Size:     25116 BYTES
polish.lng                     File Size:     26644 BYTES
portugueseBR.lng               File Size:     28654 BYTES
portuguesePT.lng               File Size:     29062 BYTES
romanian.lng                   File Size:     28290 BYTES
russian.lng                    File Size:     27302 BYTES
serbian.lng                    File Size:     26804 BYTES
slovak.lng                     File Size:     25644 BYTES
slovenian.lng                  File Size:     24852 BYTES
spanish.lng                    File Size:     30060 BYTES
swedish.lng                    File Size:     25992 BYTES
thai.lng                       File Size:     26092 BYTES
turkish.lng                    File Size:     25876 BYTES
vietnamese.lng                 File Size:     29528 BYTES

C:\Users\Sam\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware

C:\Users\Sam\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs

C:\Users\Sam\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine

C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware
exclusions.dat                 File Size:       130 BYTES
rules.ref                      File Size:   6838521 BYTES

C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Configuration
build.conf                     File Size:       140 BYTES
config.conf                    File Size:      4076 BYTES
custom.conf                    File Size:        20 BYTES
database.conf                  File Size:       432 BYTES
html.conf                      File Size:      2904 BYTES
local.conf                     File Size:       674 BYTES
manifest.conf                  File Size:      1752 BYTES
messaging.conf                 File Size:      1430 BYTES
news.conf                      File Size:       272 BYTES

C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Logs
protection-log-2013-07-24.txt  File Size:      1924 BYTES

C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine

===============================================================
END OF FILE

Link to post
Share on other sites

  • Root Admin

I need to see the Protection log files please so I can verify if it really is our program that is blocking or causing an issue.

 

If you want to 100% rule out our program then simply temporarily uninstall MBAM and see if that fixes it or not, otherwise I need logs to see what's going on.

 

Thanks

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.