Jump to content

Malwarebytes

Malwarebytes' Anti-Malware prompt


20 replies to this topic

#1
aram535

    New Member

  • Members
  • Pip
  • 5 posts
Hi,

I've been getting a notification since I upgraded to v4.1 (I think). A prompt that comes up that says

Malwarebyte's Anti-Malware
Malwarebyte's Anti-Malware IP Protection:
Infection detected: <ip address>

Ok, all good. thank you for stopping whatever it was.

A couple of issues:

1) The message doesn't go away, you have to click on the X to get rid of it which is very annoying.
2) There is no record of what was stopped, what was contained, and what triggers Malware to say it was <whatever>.

Am I missing an option here? I would like to have IP Protector be on, but not have to dismiss the message every time, and it happens a lot it seems. I'm assuming these are tracking cookies of some kind I've even gotten them going to known good sites (cnn, nytimes, weather.com, etc.)

Thanks.

Aram

#2
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,965 posts
  • Gender:Male
Greetings aram535 and welcome :unsure: .

Please review the information in the posts in this thread and it will most likely answer your questions for you. It explains what the message means, how the IP Protection works and also has options for controlling whether the IP Protection displays the messages or not as well as some other options.
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
aram535

    New Member

  • Members
  • Pip
  • 5 posts
Thank you, exactly what I needed. Two questions:

1. The log is simply a log of what was on the screen, no further information is provided as to what the "cause" of the block was.
2. The key: HKEY_LOCAL_MACHINE\Software\Malwarebytes' Anti-Malware doesn't seem to exist on my vista 64 machine. Is that the current location?

Thanks.

#4
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,965 posts
  • Gender:Male
You're welcome :unsure: .
  • The cause is that the IP's (websites) that were blocked have been determined to be malicious and therefore whenever your computer tries to access them, Malwarebytes' blocks it to prevent possible infection as those sites are typically known to either host malware or criminal activities such as phishing scams.
  • Yes, that's where it should be. I'm on Vista x64 as well and I have that key, I verified it shows up in both the 32 bit and 64 bit versions of regedit (one located in System32 and the other located in SysWoW64).

Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5
aram535

    New Member

  • Members
  • Pip
  • 5 posts
Ok I've created the Key and the DWORD value within. Let's see if the app will read it.

Thank you for your help.

#6
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,965 posts
  • Gender:Male
You're welcome, let me know if you have any trouble.
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7
aram535

    New Member

  • Members
  • Pip
  • 5 posts
Hi, it doesn't look like the key in the other article is being read:

[HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes' Anti-Malware]
"silentipmode"=dword:00000001

I restarted the machine and still when the IP block happens, it still display and it never goes off (until manually closed).

However, the second one you mentioned maybe working:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware]
"silentipmode"=dword:0000000

I'll 100% confirm later on today.

#8
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,965 posts
  • Gender:Male
Ok, I'll get one of the staff to take a look at this thread as well :rolleyes: .
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
aram535

    New Member

  • Members
  • Pip
  • 5 posts
I think adding to the WOW6432Node fixed it. So that's the proper path, for Vista 64 anyway.

#10
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,965 posts
  • Gender:Male
Yes, it seems so, although I'm running Vista 64 myself and have it in both locations. For some reason MBAM placed its entries in both locations. I'm investigating the cause but I suspect it could've been leftovers from a previous version before it was made fully 64 bit compatible.
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#11
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
You should probably run the full clean removal and verify reg keys are gone yourself Exile and then re-install the latest version again.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#12
yardbird

    Forum Deity

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,726 posts
  • Gender:Male
  • Location:Sedona. Arizona, USA
  • Interests:Where we keep the World Safe
Instructions for a clean removal and reinstall below:

please try a clean tool below, remove the program and re-install again

1. Uninstall Malwarebytes' Anti-Malware using Add/Remove programs in the control panel.
2. Restart your computer (very important).
3. Download and run this utility. http://www.malwareby.../mbam-clean.exe

4. It will ask to restart your computer (please allow it to).
5. After the computer restarts, install the latest version from here. http://www.malwareby...am-download.php

Note: You will need to reactivate the program using the license you were sent
Launch the program and set the Protection and Registration. Then go to the UPDATE tab if not done during installation and check for updates.
Restart the computer again and verify that MBAM is in the task tray and run a Quick Scan.

PLease post back with your results....regards...
Posted Image
No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
http://www.tentrexindustries.com/

#13
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,965 posts
  • Gender:Male
:) Thanks for the instructions yardbird :) .

I did it but the key was still there in the 64 bit registry so I removed it manually, reloaded MBAM and all is well, no new key was created there in the 64 bit registry :) .
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#14
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
In the 32 bit or the 64 bit? I got the impression that you were using a 64 bit O/S and wanted to know why there were entries left in the 32 bit registry. Or am I backwards?
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#15
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,965 posts
  • Gender:Male
They show up in both registries (there are actually 2 registries in 64 bit Windows, a 32 bit version and a 64 bit version), but in the 64 bit registry they should only show up under the wow6432node key.
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#16
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
Got you... Hmm, I need to investigate my x64 laptop a bit more... do you access the 2 registries differently?
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#17
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,965 posts
  • Gender:Male
Yep, one version of Regedit is located in C:\Windows\System32 while the other (32 bit version) is located in C:\Windows\SysWoW64.
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#18
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
By a little research, I found that "regedit" from the Run box opens the 64 bit version by default. Do you know the quick way to open the 32 bit registry? Is it:

Click Start, click Run, type drive letter where you installed Windows x64 Edition\Windows\syswow64\regedit.exe –m in the Open box, and then click OK. The –m switch lets you to run multiple instances of Registry Editor.

Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#19
exile360

    exile

  • Moderators
  • PipPipPipPipPipPip
  • 12,965 posts
  • Gender:Male
I haven't tried the -m switch but the path is correct. I've got them both pinned to my start menu myself, each labelled as either 32 bit or 64 bit.
Samuel E Lindsey
Product Manager

Posted Image

Follow us: Twitter, Become a fan: Facebook

#20
GT500

    Mostly Cantankerous

  • Trusted Advisors
  • PipPipPipPipPipPip
  • 5,528 posts
  • Gender:Male
  • Location:Fortville, IN

swagger said:

Got you... Hmm, I need to investigate my x64 laptop a bit more... do you access the 2 registries differently?

They are both in the same registry, and are both accessible through the 64-bit version of regedit (but only the 32-bit sections are accessible in the 32-bit version of regedit).

It's pretty easy to tell the difference in the 64-bit version of regedit (which is the default, BTW). For instance, when the two are separated in HKLM/Software, it looks like this:

64-bit:
HKEY_LOCAL_MACHINE\SOFTWARE

32-bit:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node

64-bit apps can, of course, see the 32-bit sections if they look in Wow6432Node, but 32-bit apps are shown the Wow6432Node as if it were the HKLM/Software key.

It works through WoW64, just like the System32 and SysWow32 directories do. 32-bit apps see the SysWow32 directory as if it were the System32 directory, and 64-bit apps will see both.

Quote

For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us