Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 16th, 2009, 12:08 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Malware Defender Issue

I've run into one problem, not unique to a particular version of MD. I just ran a windows Update, and now MD tells me I need to download the kernel symbols. But when I try to do so, the download fails.

Any ideas.

Pete
  #2  
Old April 16th, 2009, 12:24 PM
tony62's Avatar
tony62 tony62 is offline
Frequent Poster
 
Join Date: Aug 2005
Location: UK
Posts: 214
Default Re: Malware Defender Issue

Hi Peter,
are you using Windows XP? I also received several windows updates yesterday and MD downloaded the kernel symbols with no problems.
Have you tried deleting the contents of: C:\Program Files\Malware Defender\symbols?
  #3  
Old April 16th, 2009, 01:06 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Malware Defender Issue

Quote:
Originally Posted by tony62
Hi Peter,
are you using Windows XP? I also received several windows updates yesterday and MD downloaded the kernel symbols with no problems.
Have you tried deleting the contents of: C:\Program Files\Malware Defender\symbols?

Hi Tony

Yes XP . I will try deleting those contents and see what happens.

Thanks,
  #4  
Old April 16th, 2009, 01:43 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Malware Defender Issue

Figured it out. There was no symbols folder, so I tried manually creating one, and couldn't. Protection issues. So I disabled MD, and shutdown OA, and bingo kernel symbols downloaded fine.

Pete
  #5  
Old April 16th, 2009, 02:02 PM
bellgamin's Avatar
bellgamin bellgamin is offline
Very Frequent Poster
 
Join Date: Aug 2002
Location: Hawaii
Posts: 5,202
Default Re: Malware Defender Issue

Quote:
Originally Posted by Peter2150
Figured it out. There was no symbols folder, so I tried manually creating one, and couldn't. Protection issues. So I disabled MD, and shutdown OA, and bingo kernel symbols downloaded fine.

Pete
Hmmm... the defender got screwed by the protector? Ah well, such is life. Some folks get the elevator -- others get the shaft.
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender
  #6  
Old April 16th, 2009, 03:24 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Malware Defender Issue

It's weird, the symbols directory seems to have gotten deleted during the system update. Then the folder was protected so the new symbol folder couldn't be opened.
  #7  
Old April 16th, 2009, 09:54 PM
xiaolin xiaolin is offline
Frequent Poster
 
Join Date: Aug 2008
Posts: 248
Default Re: Malware Defender Issue

Quote:
Originally Posted by Peter2150
It's weird, the symbols directory seems to have gotten deleted during the system update. Then the folder was protected so the new symbol folder couldn't be opened.
Thanks for the information. I will look into it.

MD will delete the old symbols before downloading new symbols.
  #8  
Old April 16th, 2009, 10:43 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Malware Defender Issue

Quote:
Originally Posted by xiaolin
Thanks for the information. I will look into it.

MD will delete the old symbols before downloading new symbols.

Thanks xiaolin. Should new symbols be necessary with a Windows update?

Pete
  #9  
Old April 17th, 2009, 12:13 AM
Espresso's Avatar
Espresso Espresso is offline
Frequent Poster
 
Join Date: Aug 2006
Posts: 974
Default Re: Malware Defender Issue

I had the same problem, but when I checked with a packet sniffer, I saw that MD was getting a http 404 error when it tried to download the symbols.
  #10  
Old April 17th, 2009, 07:26 AM
xiaolin xiaolin is offline
Frequent Poster
 
Join Date: Aug 2008
Posts: 248
Default Re: Malware Defender Issue

Quote:
Originally Posted by Peter2150
Thanks xiaolin. Should new symbols be necessary with a Windows update?

Pete
If the Windows kernel file is updated, MD will download new symbols for the new file.
  #11  
Old April 17th, 2009, 07:27 AM
xiaolin xiaolin is offline
Frequent Poster
 
Join Date: Aug 2008
Posts: 248
Default Re: Malware Defender Issue

Quote:
Originally Posted by Espresso
I had the same problem, but when I checked with a packet sniffer, I saw that MD was getting a http 404 error when it tried to download the symbols.
Could you try to download the symbols again after restart?
  #12  
Old April 17th, 2009, 08:26 AM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Malware Defender Issue

Quote:
Originally Posted by xiaolin
If the Windows kernel file is updated, MD will download new symbols for the new file.

Makes sense. I run Online Armor, along with MD, and it's clear one of them was protecting the program area. Shutting down OA, and disabling all protections in MD solved my problem.

Pete
  #13  
Old April 30th, 2009, 11:19 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: Malware Defender Issue

It's not unexpected, but I do get "Failed to get kernel symbols." when prompted to download new symbols after upgrading my Vista machines to SP2 RTM (TechNet release)...

HTTP:Request, GET /download/symbols/index2.txt

HTTP:Response, HTTP/1.1, Status Code = 404, URL: /download/symbols/index2.txt

18 0.312001 {HTTP:7, TCP:6, IPv4:3} 192.168.1.116 msdl.microsoft.akadns.net HTTP HTTP:Request, GET /download/symbols/ntkrpamp.pdb/109FACEC7E244C8FAC6D191457B5C7022/ntkrpamp.pdb

HTTP:Response, HTTP/1.1, Status Code = 404, URL: /download/symbols/ntkrpamp.pdb/109FACEC7E244C8FAC6D191457B5C7022/ntkrpamp.pdb
__________________
Nick
  #14  
Old May 1st, 2009, 04:33 AM
xiaolin xiaolin is offline
Frequent Poster
 
Join Date: Aug 2008
Posts: 248
Default Re: Malware Defender Issue

Quote:
Originally Posted by nick s
It's not unexpected, but I do get "Failed to get kernel symbols." when prompted to download new symbols after upgrading my Vista machines to SP2 RTM (TechNet release)...

HTTP:Request, GET /download/symbols/index2.txt

HTTP:Response, HTTP/1.1, Status Code = 404, URL: /download/symbols/index2.txt

18 0.312001 {HTTP:7, TCP:6, IPv4:3} 192.168.1.116 msdl.microsoft.akadns.net HTTP HTTP:Request, GET /download/symbols/ntkrpamp.pdb/109FACEC7E244C8FAC6D191457B5C7022/ntkrpamp.pdb

HTTP:Response, HTTP/1.1, Status Code = 404, URL: /download/symbols/ntkrpamp.pdb/109FACEC7E244C8FAC6D191457B5C7022/ntkrpamp.pdb
The kernel symbols for Vista SP2 may be not provided by MS now.

The HIPS functions will work fine without kernel symbols.

Thanks,
Xiaolin
  #15  
Old May 1st, 2009, 05:22 AM
demoneye's Avatar
demoneye demoneye is offline
Very Frequent Poster
 
Join Date: Dec 2007
Location: ISRHell
Posts: 1,220
Default Re: Malware Defender Issue

same problem like peter in here , its somehow faild to download

also i found another thing , correct me if i wrong , when i del a rule i made to any software and try to lunch it , it lunch without MD alerts

using XP sp3 + MD 2.1.1

cheers
__________________
Drive snapshot
WINDOWS 8 FIREWALL
Sandboxie (64-bit)
Secuirty software no.1~> YOUR SKILLS
Prevention is better than the cure
using win 8 Pro X64

Last edited by demoneye : May 1st, 2009 at 05:41 AM.
  #16  
Old May 1st, 2009, 08:45 PM
xiaolin xiaolin is offline
Frequent Poster
 
Join Date: Aug 2008
Posts: 248
Default Re: Malware Defender Issue

Quote:
Originally Posted by demoneye
same problem like peter in here , its somehow faild to download

also i found another thing , correct me if i wrong , when i del a rule i made to any software and try to lunch it , it lunch without MD alerts

using XP sp3 + MD 2.1.1

cheers
Launching software is controld by child application rule. You need to delete the app from the child application rules of explorer.exe.

thanks
  #17  
Old May 2nd, 2009, 02:57 PM
demoneye's Avatar
demoneye demoneye is offline
Very Frequent Poster
 
Join Date: Dec 2007
Location: ISRHell
Posts: 1,220
Default Re: Malware Defender Issue

Quote:
Originally Posted by xiaolin
Launching software is controld by child application rule. You need to delete the app from the child application rules of explorer.exe.

thanks
yes i know , i did it but no help , i used "find rules" ,enter software name , and Del all related rules(so no missed rules) , software still lunch without any MD warning, btw it goes for all software i checked

any explanation to that?is it a bug ppl somehow missed ?
__________________
Drive snapshot
WINDOWS 8 FIREWALL
Sandboxie (64-bit)
Secuirty software no.1~> YOUR SKILLS
Prevention is better than the cure
using win 8 Pro X64

Last edited by demoneye : May 2nd, 2009 at 03:50 PM.
  #18  
Old May 2nd, 2009, 09:12 PM
xiaolin xiaolin is offline
Frequent Poster
 
Join Date: Aug 2008
Posts: 248
Default Re: Malware Defender Issue

Quote:
Originally Posted by demoneye
yes i know , i did it but no help , i used "find rules" ,enter software name , and Del all related rules(so no missed rules) , software still lunch without any MD warning, btw it goes for all software i checked

any explanation to that?is it a bug ppl somehow missed ?
The only possible reason is that you are select one of the first two options in Options dialog -> Rules.
  #19  
Old May 15th, 2009, 12:31 AM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: Malware Defender Issue

Quote:
Originally Posted by xiaolin
The kernel symbols for Vista SP2 may be not provided by MS now.

The HIPS functions will work fine without kernel symbols.

Thanks,
Xiaolin
Kernel symbols for Vista SP2 are now available .
__________________
Nick
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:42 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums