PDA

View Full Version : "Malwarebytes Anti-Malware" (new data: "") deleted in System Startup



marshach
2012-01-18, 13:49
I have SD-Resident active on my laptop. Every time I start my laptop SD-Resident pops up this warning:

value "Malwarebytes Anti-Malware" (new data: "") deleted in System Startup global entry!

I am not sure what this means. It appears to mean that something is trying to stop Malwaybytes from starting when Windows starts, so I keep denying the change.

Can someone please tell me what that warning means?

imageek
2012-01-18, 16:47
First of all, you shall never use more than two (maximum! - that includes your AV) real time scanners.

marshach
2012-01-19, 05:02
First of all, you shall never use more than two (maximum! - that includes your AV) real time scanners.

Thank you for the advice, God. :bow:

Now, can you answer my question.

Zenobia
2012-01-19, 05:06
Could you let me know if you have the free or Pro version of malwarebytes?

marshach
2012-01-19, 08:04
Could you let me know if you have the free or Pro version of malwarebytes?

I am using the Pro version (trial basis) of Malwarebytes.

Zenobia
2012-01-19, 11:05
If you have the Pro version,then it might be the real-time scanner being deleted from startup.
But,sometimes,Malwarebytes uses a runonce start-up entry so it can run at startup,if it needs to,I believe.

Could you follow this to export your startup list?:
http://www.safer-networking.org/en/howto/startup.html
Then copy and paste your startup list here.

marshach
2012-01-19, 20:28
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

Located: HK_LM:Run, Apoint
command: C:\Program Files\Apoint\Apoint.exe
file: C:\Program Files\Apoint\Apoint.exe
size: 176128
MD5: BDF765B33972A95AE8B5C5262D5E1325

Located: HK_LM:Run, ATIPTA
command: "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
file: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
size: 344064
MD5: 8DA7BF5728427A166F67F39AE4ABFD65

Located: HK_LM:Run, EaseUs Tray
command: "C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe"
file: C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe
size: 743560
MD5: 856666D442C0DE28EF67742C6EA8C752

Located: HK_LM:Run, EaseUs Watch
command: "C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe"
file: C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe
size: 70792
MD5: 24179325433A19F36002DDDD1F2FA156

Located: HK_LM:Run, KernelFaultCheck
command: %systemroot%\system32\dumprep 0 -k
file: C:\WINDOWS\system32\dumprep 0 -k
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_LM:Run, Malwarebytes' Anti-Malware
command: "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
file: C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
size: 460872
MD5: 385B9A26DBE3D97B483D977C037C4BEC

Located: HK_LM:Run, mcui_exe
command: "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
file: C:\Program Files\McAfee.com\Agent\mcagent.exe
size: 1195408
MD5: F906F057A4B6C7BCE2BC8ED5845FB95D

Located: HK_LM:Run, PRONoMgr.exe
command: C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
file: C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
size: 135168
MD5: 4A49F8BD0E05373DFEB41F0394BBFB91

Located: HK_LM:Run, Tweak UI
command: RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
file: C:\WINDOWS\system32\TWEAKUI.CPL
size: 106544
MD5: 60C0F454521212A09ED0961050128C63

Located: HK_LM:Run, WordWeb
command: "C:\Program Files\WordWeb\wweb32.exe" -startup
file: C:\Program Files\WordWeb\wweb32.exe
size: 65216
MD5: C42EDED9E707ABDD455BB27FBD72416F

Located: HK_LM:Run, ZCfgSvc.exe
command: C:\WINDOWS\system32\ZCfgSvc.exe
file: C:\WINDOWS\system32\ZCfgSvc.exe
size: 639040
MD5: 52B8BEE6EC6E24C1EC6EA9FB6648F3DD

Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-1214440339-839522115-1343024091-1004...
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2260480
MD5: 390679F7A217A5E73D756276C40AE887

Located: Startup (common), Macro Express 3.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\Macro Express3\MacExp.exe
file: C:\Program Files\Macro Express3\MacExp.exe
size: 3818496
MD5: FD94CF8CCBBB75BE80925B25F1237C0D

Located: Startup (common), MozyHome Status.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\MozyHome\mozystat.exe
file: C:\Program Files\MozyHome\mozystat.exe
size: 3709208
MD5: 9C4DBDC974CDC16E37815F140BD725AC

Located: Startup (user), Efficient Calendar Free.lnk
where: C:\Documents and Settings\Chuck\Start Menu\Programs\Startup...
command: C:\Program Files\Efficient Calendar Free\EfficientCalendarFree.exe
file: C:\Program Files\Efficient Calendar Free\EfficientCalendarFree.exe
size: 10265600
MD5: 81B57FF9D65467E6F7C07D24CB8CF16B

Located: Startup (user), MRU-Blaster Scheduler.lnk
where: C:\Documents and Settings\Chuck\Start Menu\Programs\Startup...
command: C:\Program Files\MRU-Blaster\scheduler.exe
file: C:\Program Files\MRU-Blaster\scheduler.exe
size: 118784
MD5: 9977337FB8AAB33DB6456478220D0FEE

Located: Startup (user), MRU-Blaster Silent Clean.lnk
where: C:\Documents and Settings\Chuck\Start Menu\Programs\Startup...
command: C:\Program Files\MRU-Blaster\mrublaster.exe
file: C:\Program Files\MRU-Blaster\mrublaster.exe
size: 1216512
MD5: 52EFEB28F52F709D70346DF170972904

Located: Startup (user), Shortcut to taskmgr.exe.lnk
where: C:\Documents and Settings\Chuck\Start Menu\Programs\Startup...
command: C:\WINDOWS\system32\taskmgr.exe
file: C:\WINDOWS\system32\taskmgr.exe
size: 135680
MD5: 2CD1C3506A85B38E2D17E61ADED175C4

Located: WinLogon, !SASWinLogon
command: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
file: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
size: 551296
MD5: 2AB3A3C80C935BC6C86F3880F8F34BCC

Located: WinLogon, AtiExtEvent
command: Ati2evxx.dll
file: Ati2evxx.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, dimsntfy
command: %SystemRoot%\System32\dimsntfy.dll
file: %SystemRoot%\System32\dimsntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, Sebring
command: C:\WINDOWS\system32\LgNotify.dll
file: C:\WINDOWS\system32\LgNotify.dll
size: 188482
MD5: 9A1C843AB0D1E4C92ADD0EDBBABA5B7F

Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Zenobia
2012-01-20, 02:00
Located: HK_LM:Run, Malwarebytes' Anti-Malware
command: "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
file: C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
size: 460872
MD5: 385B9A26DBE3D97B483D977C037C4BEC
The entry is listed as the real-time protection agent and tasktray:
http://www.bleepingcomputer.com/startups/Malwarebytes_Anti_Malware-24148.html

It says on the Malwarebytes website that the trial lasts for 14 days,and then reverts to the free version.Has it been 14 days yet?Maybe it's just reverting back. :)

marshach
2012-01-20, 03:16
No, it's only been a few days since I started the trial.

The last time the S&D Resident warning popped up I allowed the change. It has not reappeared since then, but Malwarebytes still starts up when Windows starts, so I do not know what the registry change was. Maybe the registry change was the switch from the free version of Malwarebytes to the Pro version trial. That may have been when the warning started appearing. I'm not sure. It probably was, though.

Zenobia
2012-01-20, 09:07
Did you Allow the change before or after you posted your startup list?

marshach
2012-01-22, 02:42
Did you Allow the change before or after you posted your startup list?

I allowed the change the day *after* posting the startup list.

Zenobia
2012-01-22, 07:28
Okay,good.
It's puzzling.I'm not sure what would cause the startup entry to be deleted,or why the real-time protection agent is still running at startup after the change was Allowed.
But since it is running,and there are no more prompts about the Malwarebytes startup entry being deleted,seems like everything is as it should be. :)