Hi,
I've been getting a notification since I upgraded to v4.1 (I think). A prompt that comes up that says
Malwarebyte's Anti-Malware
Malwarebyte's Anti-Malware IP Protection:
Infection detected: <ip address>
Ok, all good. thank you for stopping whatever it was.
A couple of issues:
1) The message doesn't go away, you have to click on the X to get rid of it which is very annoying.
2) There is no record of what was stopped, what was contained, and what triggers Malware to say it was <whatever>.
Am I missing an option here? I would like to have IP Protector be on, but not have to dismiss the message every time, and it happens a lot it seems. I'm assuming these are tracking cookies of some kind I've even gotten them going to known good sites (cnn, nytimes, weather.com, etc.)
Thanks.
Aram
#1
Posted 11 September 2009 - 09:26 PM
#2
Posted 11 September 2009 - 10:06 PM
Greetings aram535 and welcome
.
Please review the information in the posts in this thread and it will most likely answer your questions for you. It explains what the message means, how the IP Protection works and also has options for controlling whether the IP Protection displays the messages or not as well as some other options.
Please review the information in the posts in this thread and it will most likely answer your questions for you. It explains what the message means, how the IP Protection works and also has options for controlling whether the IP Protection displays the messages or not as well as some other options.
#3
Posted 11 September 2009 - 10:18 PM
Thank you, exactly what I needed. Two questions:
1. The log is simply a log of what was on the screen, no further information is provided as to what the "cause" of the block was.
2. The key: HKEY_LOCAL_MACHINE\Software\Malwarebytes' Anti-Malware doesn't seem to exist on my vista 64 machine. Is that the current location?
Thanks.
1. The log is simply a log of what was on the screen, no further information is provided as to what the "cause" of the block was.
2. The key: HKEY_LOCAL_MACHINE\Software\Malwarebytes' Anti-Malware doesn't seem to exist on my vista 64 machine. Is that the current location?
Thanks.
#4
Posted 11 September 2009 - 10:31 PM
You're welcome
.
- The cause is that the IP's (websites) that were blocked have been determined to be malicious and therefore whenever your computer tries to access them, Malwarebytes' blocks it to prevent possible infection as those sites are typically known to either host malware or criminal activities such as phishing scams.
- Yes, that's where it should be. I'm on Vista x64 as well and I have that key, I verified it shows up in both the 32 bit and 64 bit versions of regedit (one located in System32 and the other located in SysWoW64).
#5
Posted 11 September 2009 - 10:33 PM
Ok I've created the Key and the DWORD value within. Let's see if the app will read it.
Thank you for your help.
Thank you for your help.
#6
Posted 11 September 2009 - 10:34 PM
You're welcome, let me know if you have any trouble.
#7
Posted 12 September 2009 - 07:16 PM
Hi, it doesn't look like the key in the other article is being read:
[HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes' Anti-Malware]
"silentipmode"=dword:00000001
I restarted the machine and still when the IP block happens, it still display and it never goes off (until manually closed).
However, the second one you mentioned maybe working:
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware]
"silentipmode"=dword:0000000
I'll 100% confirm later on today.
[HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes' Anti-Malware]
"silentipmode"=dword:00000001
I restarted the machine and still when the IP block happens, it still display and it never goes off (until manually closed).
However, the second one you mentioned maybe working:
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware]
"silentipmode"=dword:0000000
I'll 100% confirm later on today.
#8
Posted 13 September 2009 - 04:05 AM
Ok, I'll get one of the staff to take a look at this thread as well
.
#9
Posted 15 September 2009 - 03:00 AM
I think adding to the WOW6432Node fixed it. So that's the proper path, for Vista 64 anyway.
#10
Posted 15 September 2009 - 03:33 PM
Yes, it seems so, although I'm running Vista 64 myself and have it in both locations. For some reason MBAM placed its entries in both locations. I'm investigating the cause but I suspect it could've been leftovers from a previous version before it was made fully 64 bit compatible.
#11
Posted 15 September 2009 - 05:23 PM
You should probably run the full clean removal and verify reg keys are gone yourself Exile and then re-install the latest version again.
#12
Posted 15 September 2009 - 05:48 PM
Instructions for a clean removal and reinstall below:
please try a clean tool below, remove the program and re-install again
1. Uninstall Malwarebytes' Anti-Malware using Add/Remove programs in the control panel.
2. Restart your computer (very important).
3. Download and run this utility. http://www.malwareby.../mbam-clean.exe
4. It will ask to restart your computer (please allow it to).
5. After the computer restarts, install the latest version from here. http://www.malwareby...am-download.php
Note: You will need to reactivate the program using the license you were sent
Launch the program and set the Protection and Registration. Then go to the UPDATE tab if not done during installation and check for updates.
Restart the computer again and verify that MBAM is in the task tray and run a Quick Scan.
PLease post back with your results....regards...
please try a clean tool below, remove the program and re-install again
1. Uninstall Malwarebytes' Anti-Malware using Add/Remove programs in the control panel.
2. Restart your computer (very important).
3. Download and run this utility. http://www.malwareby.../mbam-clean.exe
4. It will ask to restart your computer (please allow it to).
5. After the computer restarts, install the latest version from here. http://www.malwareby...am-download.php
Note: You will need to reactivate the program using the license you were sent
Launch the program and set the Protection and Registration. Then go to the UPDATE tab if not done during installation and check for updates.
Restart the computer again and verify that MBAM is in the task tray and run a Quick Scan.
PLease post back with your results....regards...

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
http://www.tentrexindustries.com/
#13
Posted 15 September 2009 - 06:04 PM
I did it but the key was still there in the 64 bit registry so I removed it manually, reloaded MBAM and all is well, no new key was created there in the 64 bit registry
#14
Posted 15 September 2009 - 06:08 PM
In the 32 bit or the 64 bit? I got the impression that you were using a 64 bit O/S and wanted to know why there were entries left in the 32 bit registry. Or am I backwards?
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#15
Posted 15 September 2009 - 06:17 PM
They show up in both registries (there are actually 2 registries in 64 bit Windows, a 32 bit version and a 64 bit version), but in the 64 bit registry they should only show up under the wow6432node key.
#16
Posted 15 September 2009 - 06:21 PM
Got you... Hmm, I need to investigate my x64 laptop a bit more... do you access the 2 registries differently?
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#17
Posted 15 September 2009 - 06:33 PM
Yep, one version of Regedit is located in C:\Windows\System32 while the other (32 bit version) is located in C:\Windows\SysWoW64.
#18
Posted 15 September 2009 - 06:46 PM
By a little research, I found that "regedit" from the Run box opens the 64 bit version by default. Do you know the quick way to open the 32 bit registry? Is it:
Click Start, click Run, type drive letter where you installed Windows x64 Edition\Windows\syswow64\regedit.exe –m in the Open box, and then click OK. The –m switch lets you to run multiple instances of Registry Editor.
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#19
Posted 15 September 2009 - 07:02 PM
I haven't tried the -m switch but the path is correct. I've got them both pinned to my start menu myself, each labelled as either 32 bit or 64 bit.
#20
Posted 15 September 2009 - 07:23 PM
swagger said:
Got you... Hmm, I need to investigate my x64 laptop a bit more... do you access the 2 registries differently?
They are both in the same registry, and are both accessible through the 64-bit version of regedit (but only the 32-bit sections are accessible in the 32-bit version of regedit).
It's pretty easy to tell the difference in the 64-bit version of regedit (which is the default, BTW). For instance, when the two are separated in HKLM/Software, it looks like this:
64-bit:
HKEY_LOCAL_MACHINE\SOFTWARE
32-bit:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node
64-bit apps can, of course, see the 32-bit sections if they look in Wow6432Node, but 32-bit apps are shown the Wow6432Node as if it were the HKLM/Software key.
It works through WoW64, just like the System32 and SysWow32 directories do. 32-bit apps see the SysWow32 directory as if it were the System32 directory, and 64-bit apps will see both.
Quote
For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account

Back to top










