Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

Put no trust in cryptic comments.


computers / alt.comp.os.windows-10 / Malwarebytes help?

SubjectAuthor
* Malwarebytes help?Stan Brown
+- Re: Malwarebytes help?Paul
+- Re: Malwarebytes help?YK
`* Re: Malwarebytes help? -- SOLVEDStan Brown
 `- Re: Malwarebytes help? -- SOLVEDYK

1
Malwarebytes help?

<MPG.3c83222f962689a98fec0@news.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=59898&group=alt.comp.os.windows-10#59898

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: the_stan...@fastmail.fm (Stan Brown)
Newsgroups: alt.comp.os.windows-10
Subject: Malwarebytes help?
Date: Fri, 25 Feb 2022 17:28:49 -0800
Organization: Oak Road Systems
Lines: 28
Message-ID: <MPG.3c83222f962689a98fec0@news.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 8yLsG9Oyz2+CMF4HigcH9wMciYcD0/lxlGuuEPVsV5sNZGRRb6
Cancel-Lock: sha1:xci+4k3UXvQTPnMs7aa2ytHcWQg=
User-Agent: MicroPlanet-Gravity/3.0.4
 by: Stan Brown - Sat, 26 Feb 2022 01:28 UTC

I have Malwarebytes Premium, not Malwarebytes Free. It's more than 48
hours since I submitted my ticket, but they haven't got back to me,
so I'm hoping maybe someone here knows the answer.

Malwarebytes complains about a PUM every time it runs. The "PUM" is a
Registry key I created, namely HKCU\SOFTWARE\MICROSOFT\WINDOWS
\CURRENTVERSION\POLICIES\ACTIVEDESKTOP|NOCHANGINGWALLPAPER. I want to
tell Malwarebytes to ignore it in scan, but I can't find a way to
tell it to ignore this one and still diagnose other PUMs.

The exclude list works great for files and folders, but doesn't let
me enter a Registry key. This article:

<https://support.malwarebytes.com/hc/en-us/articles/360038523134-
Malwarebytes-for-Windows-detected-a-Potentially-Unwanted-
Modification>

has a heading about halfway down, "Ignore a Potentially Unwanted
Modification", but the directions show changing settings to ignore
all PUMs.

Anyone know how to exclude one PUM from the scan without excluding
all PUMs?

--
Stan Brown, Tehachapi, California, USA https://BrownMath.com/
Shikata ga nai...

Re: Malwarebytes help?

<svc94q$1276$1@gioia.aioe.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=59901&group=alt.comp.os.windows-10#59901

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!aioe.org!S93I1Lkl9ZOMrnoZb2VKoA.user.46.165.242.75.POSTED!not-for-mail
From: nos...@needed.invalid (Paul)
Newsgroups: alt.comp.os.windows-10
Subject: Re: Malwarebytes help?
Date: Fri, 25 Feb 2022 23:08:59 -0500
Organization: Aioe.org NNTP Server
Message-ID: <svc94q$1276$1@gioia.aioe.org>
References: <MPG.3c83222f962689a98fec0@news.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="35046"; posting-host="S93I1Lkl9ZOMrnoZb2VKoA.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
X-Notice: Filtered by postfilter v. 0.9.2
Content-Language: en-US
 by: Paul - Sat, 26 Feb 2022 04:08 UTC

On 2/25/2022 8:28 PM, Stan Brown wrote:
> I have Malwarebytes Premium, not Malwarebytes Free. It's more than 48
> hours since I submitted my ticket, but they haven't got back to me,
> so I'm hoping maybe someone here knows the answer.
>
> Malwarebytes complains about a PUM every time it runs. The "PUM" is a
> Registry key I created, namely HKCU\SOFTWARE\MICROSOFT\WINDOWS
> \CURRENTVERSION\POLICIES\ACTIVEDESKTOP|NOCHANGINGWALLPAPER. I want to
> tell Malwarebytes to ignore it in scan, but I can't find a way to
> tell it to ignore this one and still diagnose other PUMs.
>
> The exclude list works great for files and folders, but doesn't let
> me enter a Registry key. This article:
>
> <https://support.malwarebytes.com/hc/en-us/articles/360038523134-
> Malwarebytes-for-Windows-detected-a-Potentially-Unwanted-
> Modification>
>
> has a heading about halfway down, "Ignore a Potentially Unwanted
> Modification", but the directions show changing settings to ignore
> all PUMs.
>
> Anyone know how to exclude one PUM from the scan without excluding
> all PUMs?

An example here, shows them carrying out a search,
flagging four registry settings, then you untick all
the tick boxes, and the button changes to "Next".

https://forums.malwarebytes.com/topic/261201-add-registry-key-to-the-exclusion-list-in-malwarebytes-v4/

https://forums.malwarebytes.com/topic/226680-cant-exclude-registry-entries/

Paul

Re: Malwarebytes help?

<svddts$182b$1@gioia.aioe.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=59916&group=alt.comp.os.windows-10#59916

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!aioe.org!7eNhu6rn7qgperVJs0vx7Q.user.46.165.242.75.POSTED!not-for-mail
From: youkidd...@yahoo.com (YK)
Newsgroups: alt.comp.os.windows-10
Subject: Re: Malwarebytes help?
Date: Sat, 26 Feb 2022 09:36:38 -0500
Organization: Aioe.org NNTP Server
Message-ID: <svddts$182b$1@gioia.aioe.org>
References: <MPG.3c83222f962689a98fec0@news.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="41035"; posting-host="7eNhu6rn7qgperVJs0vx7Q.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Thunderbird/78.10.2
Content-Language: en-US
X-Notice: Filtered by postfilter v. 0.9.2
 by: YK - Sat, 26 Feb 2022 14:36 UTC

On 2/25/2022 8:28 PM, Stan Brown wrote:
> I have Malwarebytes Premium, not Malwarebytes Free. It's more than 48
> hours since I submitted my ticket, but they haven't got back to me,
> so I'm hoping maybe someone here knows the answer.
>
> Malwarebytes complains about a PUM every time it runs. The "PUM" is a
> Registry key I created, namely HKCU\SOFTWARE\MICROSOFT\WINDOWS
> \CURRENTVERSION\POLICIES\ACTIVEDESKTOP|NOCHANGINGWALLPAPER. I want to
> tell Malwarebytes to ignore it in scan, but I can't find a way to
> tell it to ignore this one and still diagnose other PUMs.
>
> The exclude list works great for files and folders, but doesn't let
> me enter a Registry key. This article:
>
> <https://support.malwarebytes.com/hc/en-us/articles/360038523134-
> Malwarebytes-for-Windows-detected-a-Potentially-Unwanted-
> Modification>
>
> has a heading about halfway down, "Ignore a Potentially Unwanted
> Modification", but the directions show changing settings to ignore
> all PUMs.
>
> Anyone know how to exclude one PUM from the scan without excluding
> all PUMs?

When I run MWB it gives me the option to deselect each cleanup item.

Re: Malwarebytes help? -- SOLVED

<MPG.3c83f3df8a8af92798fec1@news.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=59920&group=alt.comp.os.windows-10#59920

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!3.eu.feeder.erje.net!feeder.erje.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: the_stan...@fastmail.fm (Stan Brown)
Newsgroups: alt.comp.os.windows-10
Subject: Re: Malwarebytes help? -- SOLVED
Date: Sat, 26 Feb 2022 08:23:33 -0800
Organization: Oak Road Systems
Lines: 29
Message-ID: <MPG.3c83f3df8a8af92798fec1@news.individual.net>
References: <MPG.3c83222f962689a98fec0@news.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 2u2bAnLUjAJ2XZLnRNUAaAd5k7MnTg3lfnoYb2iUqXQbcjPSKi
Cancel-Lock: sha1:tCyGq3jkAcP7A4z4FmlDOkgckjY=
User-Agent: MicroPlanet-Gravity/3.0.4
 by: Stan Brown - Sat, 26 Feb 2022 16:23 UTC

On Fri, 25 Feb 2022 17:28:49 -0800, Stan Brown wrote:
>
> I have Malwarebytes Premium, not Malwarebytes Free. It's more than 48
> hours since I submitted my ticket, but they haven't got back to me,
> so I'm hoping maybe someone here knows the answer.
>
> Anyone know how to exclude one PUM from the scan without excluding
> all PUMs?

Paul, John, YK -- Thank you all for responding.

The mistake I made is that I thought when I bring up scan results I
get the same chance to exclude items as when they pop up
automatically at the conclusion of a scan. I was wrong.

After reading all three of your articles and links, I ran a new scan
manually. The registry key popped up with the tick box not ticked, I
clicked Next, and then Always Ignore was an option. Now the registry
key shows up in the Allow List, along with the three Nirsoft programs
that Malwarebytes frowns on.

Thanks to all three of you!

(I did check Malwarebytes' forums and Googled, but I must have done a
bad job of picking search terms in each case.)

--
Stan Brown, Tehachapi, California, USA https://BrownMath.com/
Shikata ga nai...

Re: Malwarebytes help? -- SOLVED

<svguct$i6i$1@gioia.aioe.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=59963&group=alt.comp.os.windows-10#59963

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!aioe.org!Nef2hFr3Uz+g8mao/fpkOg.user.46.165.242.75.POSTED!not-for-mail
From: youkidd...@yahoo.com (YK)
Newsgroups: alt.comp.os.windows-10
Subject: Re: Malwarebytes help? -- SOLVED
Date: Sun, 27 Feb 2022 17:36:09 -0500
Organization: Aioe.org NNTP Server
Message-ID: <svguct$i6i$1@gioia.aioe.org>
References: <MPG.3c83222f962689a98fec0@news.individual.net> <MPG.3c83f3df8a8af92798fec1@news.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="18642"; posting-host="Nef2hFr3Uz+g8mao/fpkOg.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Thunderbird/78.10.2
X-Notice: Filtered by postfilter v. 0.9.2
Content-Language: en-US
 by: YK - Sun, 27 Feb 2022 22:36 UTC

On 2/26/2022 5:23 PM, Stan Brown wrote:
> Paul, John, YK -- Thank you all for responding.

Thank you for thanking us but even more for coming back with your results!

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor