| Server IP : 180.180.241.3 / Your IP : 216.73.216.35 Web Server : Microsoft-IIS/7.5 System : Windows NT NETWORK-NHRC 6.1 build 7601 (Windows Server 2008 R2 Standard Edition Service Pack 1) i586 User : IUSR ( 0) PHP Version : 5.3.28 Disable Function : NONE MySQL : ON | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : C:/Program Files/Malwarebytes/Anti-Malware/farflt/ |
Upload File : |
;;;
;;; Malwarebytes Anti-Ransomware driver
;;;
;;;
;;; Copyright (c) 2016, Malwarebytes
;;;
[Version]
Signature = "$Windows NT$"
Class = "ActivityMonitor" ;This is determined by the work this filter driver does
ClassGuid = {b86dff51-a31e-4bac-b3cf-e8cfe75c9fc2}
Provider = %Malwarebytes%
DriverVer=09/05/2017,3.0.0.289
CatalogFile=farflt.cat
[DestinationDirs]
DefaultDestDir = 12
Arw.DriverFiles = 12 ;%windir%\system32\drivers
;;
;; Default install sections
;;
[DefaultInstall]
OptionDesc = %ArwServiceDesc%
CopyFiles = Arw.DriverFiles
[DefaultInstall.Services]
AddService = %ArwServiceName%,,Arw.Service
;;
;; Default uninstall sections
;;
[DefaultUninstall]
DelFiles = Arw.DriverFiles
DelReg = Arw.DelRegistry
[DefaultUninstall.Services]
DelService = %ArwServiceName%,0x200 ;Ensure service is stopped before deleting
;
; Services Section
;
[Arw.Service]
DisplayName = %ArwServiceName%
Description = %ArwServiceDesc%
ServiceBinary = %12%\farflt.sys ;%windir%\system32\drivers\farflt.sys
Dependencies = %FltmgrServiceName% ;FltMgr
ServiceType = 1 ;SERVICE_KERNEL_DRIVER
StartType = 3 ;SERVICE_DEMAND_START
ErrorControl = 1 ;SERVICE_ERROR_NORMAL
LoadOrderGroup = "FSFilter Activity Monitor"
AddReg = Arw.AddRegistry
;
; Registry Modifications
;
[Arw.AddRegistry]
HKR,,%ArwDebugLevel%,0x00010001,0xFFFF
HKR,%RegInstancesSubkeyName%,%RegDefaultInstanceValueName%,0x00000000,%DefaultInstance%
HKR,%RegInstancesSubkeyName%"\"%Instance1.Name%,%RegAltitudeValueName%,0x00000000,%Instance1.Altitude%
HKR,%RegInstancesSubkeyName%"\"%Instance1.Name%,%RegFlagsValueName%,0x00010001,%Instance1.Flags%
[Arw.DelRegistry]
;
; Copy Files
;
[Arw.DriverFiles]
%ArwDriverName%.sys
[SourceDisksFiles]
farflt.sys = 1,,
[SourceDisksNames]
1 = %Disk1%
;;
;; String Section
;;
[Strings]
Malwarebytes = "Malwarebytes"
ArwServiceDesc = "Malwarebytes Anti-Ransomware"
ArwServiceName = "MBAMFarflt"
ArwDriverName = "farflt"
ArwDebugLevel = "DebugLevel"
FltmgrServiceName = "FltMgr"
RegInstancesSubkeyName = "Instances"
RegDefaultInstanceValueName = "DefaultInstance"
RegAltitudeValueName = "Altitude"
RegFlagsValueName = "Flags"
Disk1 = "ArwKernel Source Media"
;Instances specific information.
DefaultInstance = "MBAMFarflt"
Instance1.Name = "MBAMFarflt"
Instance1.Altitude = "268150"
Instance1.Flags = 0x0