Jump to content

Malicious Memory Protection


sheend111

Recommended Posts

Hi  Ima new member but iv'e been using malwarebytes for about 2 year

To I got this popup 

Malwarebytes
www.malwarebytes.com

-Log Details-
Protection Event Date: 11/3/17
Protection Event Time: 11:32 PM
Log File: 0b398b2a-c093-11e7-b307-bcaec5c285d5.json
Administrator: Yes

-Software Information-
Version: 3.3.0.2173
Components Version: 1.0.233
Update Package Version: 1.0.3165
License: Premium

-System Information-
OS: Windows 10 (Build 10586.218)
CPU: x64
File System: NTFS
User: System

-Exploit Details-
File: 0
(No malicious items detected)

Exploit: 1
Malware.Exploit.Agent.Generic, , Blocked, [0], [392684],0.0.0

-Exploit Data-
Affected Application: Jriver
Protection Layer: Malicious Memory Protection
Protection Technique: Exploit code executing from Heap memory blocked
File Name: 
URL:  

 

Now I carn't run the program  Help would be most welcome      Thanks      sheend111

 

Link to post
Share on other sites

  • 3 weeks later...
  • Staff

Hi sheend111,

Thanks for reporting. Can you please get some logs, so we can help you out. Please follow the below instructions.

1. Exploit logs:
Please download the files from this link:
https://malwarebytes.app.box.com/s/kzoo8u6jq7n82e0uji909y7pnuozx77z

Press the Windows + R keys, type "services.msc" and hit Enter.

Find the service named "Malwarebytes service" and use the right-click menu to stop the service.

Extract the contents of the ZIP to a sub-folder in your Desktop.
Copy the files mbae.dll and mbae64.dll and paste them to the C:\Program Files\Malwarebytes\Anti-Malware\ folder.
Copy the files mbae.sys and mbae64.sys and paste them to the C:\Windows\System32\drivers\ folder.

After you replace the files, start the "Malwarebytes service" service again or reboot the computer. 

Reproduce the problem and collect and send back to us these two files:
C:\ProgramData\Malwarebytes\MBAMService\logs\mbae-default.log
C:\ProgramData\Malwarebytes\MBAMService\logs\MBAMSERVICE.log

The directory is hidden by default so you might have to click on "View -> Hidden items" in Explorer to see it.   
There is also a post here from Microsoft on how to do this for the more recent OS: https://support.microsoft.com/en-us/help/14201/windows-show-hidden-files

2. FRST

Please download FRST from the link below and save it to your desktop:
    
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

    
Double-click the purple FRST icon to run the program. Click Yes when the disclaimer appears.
Click the Scan button. When the scan has finished, it will make 2 log files in the same directory the tool is run, FRST.txt and Addition.txt. Please attach both files to your reply.

I know this is a lot to do at once, so if you have any questions about the process, please let me know!

Thanks.

Link to post
Share on other sites

  • 2 weeks later...

Hi Again    It seems that I jumped the gun    The expliot is sill here and it's driving me mad  I think I've followed the above instructions so here it comes  Thanks for your help I have athought that maybe it's the number of files that I have to add to the libiry Its Lots both music tv and movies    about 10 tb  although I have tried installing the in parts My regular computer is down  It has a i7 and a1060 graphic card and 32 gb of mem   hope to be able to get it fixed before xmas  this com has a i3 and only 4 gb of ram  Thanks Again DAVID

FRST.txt

Addition.txt

mbae-default.log

MBAMSERVICE.LOG

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.