Malwarebytes Anti-Rootkit BETA

Discussion in 'other anti-malware software' started by Cudni, Nov 10, 2012.

  1. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,874
    Location:
    Outer space
    Thanks, do you have any info when it will be available?
     
  2. arifg

    arifg Developer

    Joined:
    Nov 13, 2012
    Posts:
    14
    Location:
    USA
    To the end of this week I guess...
     
  3. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,751
    Location:
    Germany
  4. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,304
    With latest beta...

    ScreenShot_mbar2_scan_02.jpg

    ScreenShot_mbar2_scan_05.jpg
     
  5. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,874
    Location:
    Outer space
    It's fixed in the new beta :)
     
  6. jadinolf

    jadinolf Registered Member

    Joined:
    Sep 2, 2006
    Posts:
    1,047
    Location:
    Southern California
    hayc59 tipped me off that you folks had a thread here. Thanks G.

    My only report is that I've been using it since the beginning.

    No problems and it has found nothing.
     
  7. mrtonyg

    mrtonyg Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    35
    Location:
    USA
    I received the identical warning to the guy on post #26 and proceeded to delete the registry key.

    The key is installed by Adobe Acrobat 9.0 Professional (at least in my case) and it broke the install.

    I am running the latest version of MBAR 1.01.0.1011.
     
  8. AdvancedSetup

    AdvancedSetup Security Expert

    Joined:
    May 8, 2008
    Posts:
    141
    Location:
    USA
    Thank you for the feedback.

    Though Microsoft has said for a long time now that this feature should not be used there are still software vendors that do use it but you find much more abuse by malware than legit vendors.

    Even in XP, Microsoft says this is bad practice and may not be supported in future versions of Windows.

    AppInit_DLLs in Windows 7 and Windows Server 2008 R2


    Hopefully we'll come up an update on this issue in a future build before release.

    Just a reminder that it is still beta software and anyone using it should be taking proper precautions to ensure the safety of their machine before using it.

    Thank you
     
  9. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Group Policy Hardening: disable turning off System restore = false positive

    Please check on value, enabled should be reported, not disabled, thanks
     
  10. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,751
    Location:
    Germany
  11. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
  12. Durad

    Durad Registered Member

    Joined:
    Aug 13, 2005
    Posts:
    594
    Location:
    Canada
    Can you tell us everything what "fixdamage.exe" will fix?
    Thanks
     
  13. gerardwil

    gerardwil Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    4,748
    Location:
    EU
    Within the MBAR folder there is the ReadMe.rtf file with explanations.

    Bleeping Computer has a Tutorial as well: how to use malwarebytes anti-rootkit
     

    Attached Files:

  14. Rules

    Rules Registered Member

    Joined:
    Mar 3, 2009
    Posts:
    704
    Location:
    EU
  15. iammike

    iammike Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    342
    Location:
    SE Asia
    Last edited: Jan 29, 2013
  16. Rules

    Rules Registered Member

    Joined:
    Mar 3, 2009
    Posts:
    704
    Location:
    EU
  17. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,751
    Location:
    Germany
  18. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,221
    Location:
    USA
  19. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,751
    Location:
    Germany
  20. gerardwil

    gerardwil Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    4,748
    Location:
    EU

    Attached Files:

  21. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,304
    Just finished scanning...

    ScreenShot_MBAR6_scan_02.jpg ScreenShot_MBAR6_scan_03.jpg

    ScreenShot_MBAR6_scan_05.jpg ScreenShot_MBAR6_scan_06.jpg
     
  22. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
  23. CyberMan969

    CyberMan969 Registered Member

    Joined:
    Apr 21, 2011
    Posts:
    589
    I also got the AppInit_DLLs warning with the latest version. The scan completes fine without removing this registry entry, and results come back clean anyway. When I search in regedit for this entry it cannot be found, still the MBAM Anti-rootkit tells me that it's there.

    I suspect this may be because of Rollback RX but I'm not sure. I just ran the scan again and opted to delete the entry, I will now reboot to see if something stops working. Any opinions would be welcome!

    PS: I just rebooted and everything seems to be fine. All my programs function as normal. I don't know why that entry was there in the first place. My computer has never been infected, I'm actually quite paranoid about my security setup...
     
    Last edited: Mar 7, 2013
  24. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,755
    Location:
    Texas
    http://www.techrepublic.com/blog/security/rootkit-coders-beware-malwarebytes-is-in-hot-pursuit/9207
     
  25. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.