Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Compromised Tomcat 9, Malewarebytes notification keeps popping up.


  • Please log in to reply
19 replies to this topic

#16 Alban1806

Alban1806
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:30 AM

Posted 21 April 2024 - 10:20 PM

Sorry Oh My!, this hasn't been a good time for me. I've been super busy. I'll go ahead and exclude both of those on Malewarebytes and update you if anything else occurs.



BC AdBot (Login to Remove)

 


#17 Alban1806

Alban1806
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:30 AM

Posted 21 April 2024 - 10:25 PM

It appears that I'm still getting Tomcat9 malewarebytes messages even though I put it on the allow list. I attached a file for what I have on my allow list.


Edited by Alban1806, 21 April 2024 - 10:27 PM.


#18 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 22 April 2024 - 08:02 AM

It is completely understandable, I know lives are busy. If you could just touch base every few days that will let me know you are still engaged. I'm just trying to manage my topics.

Let me take a look at the most recent detections. Please do this.

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::
Zip: C:\ProgramData\Malwarebytes\MBAMService\MwacDetections
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
  • The tool will create a zipped folder in the same location from where FRST was run with today's date, example: 06.11.2016_13.24.50.zip. Upload the file to GoFile or the file hosting site of your choice and send me a Personal Message with the download link
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Fixlog
  • Uploaded file

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#19 Alban1806

Alban1806
  • Topic Starter

  •  Avatar image
  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:30 AM

Posted 22 April 2024 - 10:14 PM

Fix result of Farbar Recovery Scan Tool (x64) Version: 19.04.2024 01
Ran by Alan Bangura (22-04-2024 23:12:06) Run:4
Running from C:\Users\Alan Bangura\Downloads
Loaded Profiles: Alan Bangura & SQLTELEMETRY$SQLEXPRESS & MSSQL$SQLEXPRESS
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
Zip: C:\ProgramData\Malwarebytes\MBAMService\MwacDetections
End::
*****************
 
================== Zip: ===================
C:\ProgramData\Malwarebytes\MBAMService\MwacDetections -> copied successfully to C:\Users\Alan Bangura\Desktop\22.04.2024_23.12.06.zip
=========== Zip: End ===========
 
==== End of Fixlog 23:13:37 ====


#20 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted Yesterday, 03:10 PM

Thank you for the report.

The most recent notifications are related to Malwarebytes blocking incoming TCP requests. They are not initiated from your computer or indicative of malware on your system. Malwarebytes is doing its job in blocking repeated attempts to access your system.

If you would like, you can suspend notifications related to Tomcat 9.
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users