View Full Version : Malware Defender Version 1.2.3 (December 18, 2008)
demoneye
December 18th, 2008, 04:41 PM
Version 1.2.3 (December 18, 2008 )
* Fixed a bug that may cause chkdsk error when startup.
* Fixed a bug when creating rules for named pipe in learning mode.
* Added support for resizing the registry rule dialog box.
* Changed the default setting of "Allow signed applications to be run by system applications" to unchecked.
* Other Minor improvements.
jmonge
December 20th, 2008, 01:43 AM
is this beta?or regular?
EASTER
December 20th, 2008, 02:00 AM
That's good. Give it time to iron out all the bugs. Then i'm more then ready to become a consumer statistic in it's market.
Watching this closely.
EASTER
Kees1958
December 20th, 2008, 03:08 AM
It is a brilliant classical HIPS, like EQS with groups like Comodo's D+ (only easier to implement) with a an active and dedicated developer (like OA, DW, SBIE, PrevX, DS)
Cheers Kees
LoneWolf
December 20th, 2008, 07:40 AM
-{ Quote: "is this beta?or regular?" }-
Not beta, v1.2.3 is final.
Up and running w/ no problems here :thumb:
demoneye
December 20th, 2008, 08:03 AM
only this HIPS give me hard time , its service going all of the sudden to 90-100% cpu usage ...
i did it on a clean only win installed same results....damn weird.....that happened when change to mode normal :( :thumbd:
andyman35
December 20th, 2008, 09:27 AM
-{ Quote: "It is a brilliant classical HIPS, like EQS with groups like Comodo's D+ (only easier to implement) with a an active and dedicated developer (like OA, DW, SBIE, PrevX, DS)
Cheers Kees" }-
Is Malware Defender as extensive in it's protection as the likes of D+ and OA?
demoneye
December 20th, 2008, 09:29 AM
-{ Quote: "Is Malware Defender as extensive in it's protection as the likes of D+ and OA?" }-
all the same goal difference gui
its more like SSM look like but missing net protection yet , so its kind half useless :)
andyman35
December 20th, 2008, 09:31 AM
-{ Quote: "all the same goal difference gui
its more like SSM look like" }-
Ahhh right thanks for that.I keep meaning to get around to trying this out due to all the positive reviews.:thumb:
Kees1958
December 20th, 2008, 09:39 AM
-{ Quote: "Is Malware Defender as extensive in it's protection as the likes of D+ and OA?" }-
OA does it all for you. So is in a different league.
D+ is a do it yourself. Malware Defender is as extensive as D+, only with some smart options of groups (D+ only has application rules per group, file protection and registry protection is applicable on all groups, MD offers this on a group basis, making it easier to fence/contain higher risk aps in a classical HIPS allow/deny environment).
Kees1958
December 20th, 2008, 09:43 AM
-{ Quote: "all the same goal difference gui
its more like SSM look like but missing net protection yet , so its kind half useless :)" }-
I disagree, it has the option to protect aps from spawning/access by others. So with a simpel outbound rule of TF it passes all matousec (except recursive DNS calls) or any other simple firewall it will protect you (e.g. ZA free)
andyman35
December 20th, 2008, 09:45 AM
-{ Quote: "OA does it all for you. So is in a different league.
D+ is a do it yourself. Malware Defender is as extensive as D+, only with some smart options of groups (D+ only has application rules per group, file protection and registry protection is applicable on all groups, MD offers this on a group basis, making it easier to fence/contain higher risk aps in a classical HIPS allow/deny environment)." }-
Interesting indeed,I'd not considered that Malware Defender was quite so advanced,definitely worth a look cheers.
demoneye
December 20th, 2008, 09:53 AM
-{ Quote: "I disagree, it has the option to protect aps from spawning/access by others. So with a simpel outbound rule of TF it passes all matousec (except recursive DNS calls) or any other simple firewall it will protect you (e.g. ZA free)" }-
it got no network protection mate , and all the "get along" stuff doesn't look good niter professional .
it should be buildin in future according to its builder
Kees1958
December 20th, 2008, 10:00 AM
-{ Quote: "it got no network protection mate , and all the "get along" stuff doesn't look good niter professional .
it should be buildin in future according to its builder" }-
I was disagreeing on the fact that it is half useless, you are right it has no network protection. But I pass all matousec stuff with TF's outbound rule and MD (except recursive DNS call).
demoneye
December 20th, 2008, 11:13 AM
-{ Quote: "I was disagreeing on the fact that it is half useless, you are right it has no network protection. But I pass all matousec stuff with TF's outbound rule and MD (except recursive DNS call)." }-
yes u can do it Np but also make your PC memo usage much more grater if it was bee build in from the first place mate:)
MeFer
December 20th, 2008, 12:11 PM
-{ Quote: "only this HIPS give me hard time , its service going all of the sudden to 90-100% cpu usage ...
i did it on a clean only win installed same results....damn weird.....that happened when change to mode normal :( :thumbd:" }-
I was problems whit this also.I played more too.
Then added Kees's some rules (Thanks Kees)
Also added Malwaredefender.exe and mdservice.exe to Child Applications on explorer.exe (there was no)
After 10 days learning mode now it is working with no problem now.
demoneye
December 20th, 2008, 12:41 PM
-{ Quote: "I was problems whit this also.I played more too.
Then added Kees's some rules (Thanks Kees)
Also added Malwaredefender.exe and services exe to Child Applications on explorer.exe (there was no)
After 10 days learning mode now it is working with no problem now." }-
mefer i look at your screen shoot , i cant understand its point ???
and the most disturbing issue , why MD owner doesn't fix this BUG ? or why MD doesn't put this files as it suppose to work ?
nick s
December 20th, 2008, 01:15 PM
-{ Quote: "...and the most disturbing issue , why MD owner doesn't fix this BUG ? or why MD doesn't put this files as it suppose to work ?" }-
Have you sent Xiaolin your System Information NFO file?
Nick
demoneye
December 20th, 2008, 01:37 PM
-{ Quote: "Have you sent Xiaolin your System Information NFO file?
Nick" }-
no i didn't , been emailed him about this and he didn't success reproduce this problem again.
how can i send him my nfo info?
i did test MD on clean os , nothing install unless drivers (on VM) and it stuck also....making cpu goes out of the blue randomly to 90-100% cpu usage
i try mefer suggestion "Also added Malwaredefender.exe and services exe to Child Applications on explorer.exe (there was no)"
lets see what the hell is going on with this software
nick s
December 20th, 2008, 01:52 PM
-{ Quote: "how can i send him my nfo info?" }-
Go Start > All Programs > Accessories > System Tools > System Information. Then go File > Save.
If your system can handle the extra load, you could try running Sysinternals' Process Monitor for a short interval while MD's CPU usage is high.
Nick
demoneye
December 20th, 2008, 02:12 PM
-{ Quote: "Go Start > All Programs > Accessories > System Tools > System Information. Then go File > Save.
If your system can handle the extra load, you could try running Sysinternals' Process Monitor for a short interval while MD's CPU usage is high.
Nick" }-
10x a lot for the info , i don't much like the idea to expose my pc info coz of MD
anyway i did try mefer idea , adding MD to child appz , it doesn't help :( , MD keep stuck my pc randomly
nick s
December 20th, 2008, 02:31 PM
-{ Quote: "anyway i did try mefer idea , adding MD to child appz , it doesn't help :( , MD keep stuck my pc randomly" }-
I did not expect it to work. I run MD on four systems (Vista and XP) and MD's processes are not listed as child apps of explorer.exe. I would give Process Monitor a try.
Nick
MeFer
December 20th, 2008, 03:06 PM
Demoneye,
Sorry,may i ask how many days did you stay MD in learning mode.
And when in learning mode all protection enable or not?
MeFer
December 20th, 2008, 03:13 PM
-{ Quote: " MD's processes are not listed as child apps of explorer.exe.
Nick" }-
i d'not know is there any objection but i am trying to stabile with my system.coz my system was a lot of freeze.
demoneye
December 20th, 2008, 03:40 PM
-{ Quote: "Demoneye,
Sorry,may i ask how many days did you stay MD in learning mode.
And when in learning mode all protection enable or not?" }-
i don't understand what is matter the time pc was in "learn mode" and MD stuck ??
if new process is on the run , i can add him easy to "trusted application"... so learn mode time isnt a factor in this issue
the time is about 2-3 days , till i made in purpose all action , so MD learn fast :)
demoneye
December 20th, 2008, 03:45 PM
-{ Quote: "I did not expect it to work. I run MD on four systems (Vista and XP) and MD's processes are not listed as child apps of explorer.exe. I would give Process Monitor a try.
Nick" }-
cool mate , what i know that i am not the only one having such problem, some buddy i know in other forum (none English) also complain on such problem
xiaolin
December 20th, 2008, 09:50 PM
-{ Quote: "cool mate , what i know that i am not the only one having such problem, some buddy i know in other forum (none English) also complain on such problem" }-
Hi,
I cannot resolve it because I cannot recreate the problem yet.
Which process cause high cpu usage? (malwaredefender.exe or mdservice.exe)
Thanks,
xiaolin
xiaolin
December 20th, 2008, 09:54 PM
-{ Quote: "Also added Malwaredefender.exe and mdservice.exe to Child Applications on explorer.exe (there was no)" }-
This is not necessary. Malwaredefender.exe and mdservice.exe will be allowed to execute by internal rule.
thx
demoneye
December 21st, 2008, 05:49 AM
-{ Quote: "Hi,
I cannot resolve it because I cannot recreate the problem yet.
Which process cause high cpu usage? (malwaredefender.exe or mdservice.exe)
Thanks,
xiaolin" }-
10x for the reply xiaolin
the malwaredefender.exe cause it , it append after switch to normal mode, it happen randomly after 10 minutes top ,i also test this issue even on clean only os + drivers on me VM testing machine .
i run it on Pentium 3 winxp SP3 ...maybe this can help some how
just for the knowledge record i try RTD,SSM(all builds),commodo(all builds),zA and many more HIPS based application on the same machine , and all work perfectly
cheers
lu_chin
December 21st, 2008, 06:27 PM
Does MD v1.2.3 work with KIS 2009?
Thanks.
demoneye
December 21st, 2008, 07:43 PM
-{ Quote: "Does MD v1.2.3 work with KIS 2009?
Thanks." }-
as far as i know why not? it should
wat0114
December 21st, 2008, 09:11 PM
You'd probably have to disable some protective features on either KIS or MD to avoid redundant and conflicting coverage.
,.-
December 22nd, 2008, 08:04 AM
"only this HIPS give me hard time , its service going all of the sudden to 90-100% cpu usage ...
i did it on a clean only win installed same results....damn weird.....that happened when change to mode normal "
-----------------
I also have huge problems with Malware Defender. It constantly freezes/crashes my P4 Laptop as soon as I enable normal mode. (Prior to enabling normal mode, I extensively used learning mode.)
I experienced a freeze in the following situations:
1.
I downloaded a file from a filesharing service with Opera. I got a permit query whether Opera shall be allowed to save the file in a temp folder. Thereafter, Opera opens the ordinary windows save file dialogue and asks me where to save the file. This is when Malware Defender froze Opera and itself. If you try to kill Opera with the Windows task manager there is a good chance that also the task manager will be freezed. After the freeze, CPU usage (caused by Malware Defender) is constantly around 40-50%.
2.
I tried to start a portable version of Nero 9 Burning Rom Express. This version most likely includes the launch of the main programm by the loader. It will also include registry writes and, possibly, inter process memory operations. Again, Malware Defender froze everything. After the freeze, CPU usage (caused by Malware Defender) is constantly around 40-50%.
In my opinion, the problem is that Malware Defender does not create a visible permission window. This also happened with early versions of System Safety Monitor.
In principle, I like Malware Defender's concept, GUI, tools etc. The missing network monitor is not important. This can be done by the personal firewall.
Due to the above-described bugs, Malware Defender is currently useless for me.
I used the latest version 1.2.3.
demoneye
December 22nd, 2008, 08:39 AM
-{ Quote: ""only this HIPS give me hard time , its service going all of the sudden to 90-100% cpu usage ...
i did it on a clean only win installed same results....damn weird.....that happened when change to mode normal "
-----------------
I also have huge problems with Malware Defender. It constantly freezes/crashes my P4 Laptop as soon as I enable normal mode. (Prior to enabling normal mode, I extensively used learning mode.)
I experienced a freeze in the following situations:
1.
I downloaded a file from a filesharing service with Opera. I got a permit query whether Opera shall be allowed to save the file in a temp folder. Thereafter, Opera opens the ordinary windows save file dialogue and asks me where to save the file. This is when Malware Defender froze Opera and itself. If you try to kill Opera with the Windows task manager there is a good chance that also the task manager will be freezed. After the freeze, CPU usage (caused by Malware Defender) is constantly around 40-50%.
2.
I tried to start a portable version of Nero 9 Burning Rom Express. This version most likely includes the launch of the main programm by the loader. It will also include registry writes and, possibly, inter process memory operations. Again, Malware Defender froze everything. After the freeze, CPU usage (caused by Malware Defender) is constantly around 40-50%.
In my opinion, the problem is that Malware Defender does not create a visible permission window. This also happened with early versions of System Safety Monitor.
In principle, I like Malware Defender's concept, GUI, tools etc. The missing network monitor is not important. This can be done by the personal firewall.
Due to the above-described bugs, Malware Defender is currently useless for me.
I used the latest version 1.2.3." }-
exactly my situation in here :( :'(
its freeze my PC when switch to normal mode , i uses SSM last build ATM and it run perfectly for couple of weeks
xiaolin
December 22nd, 2008, 11:41 AM
It seems MD cannot show the alert windows or make the alert windows topmost in some cases. I will try to recreate the problem and fix it.
If anyone encounter such problem, please try using hotkey to permit the action. The default hotkey is Ctrl+Shift+Alt+P.
Thanks,
xiaolin
demoneye
December 22nd, 2008, 12:22 PM
-{ Quote: "It seems MD cannot show the alert windows or make the alert windows topmost in some cases. I will try to recreate the problem and fix it.
If anyone encounter such problem, please try using hotkey to permit the action. The default hotkey is Ctrl+Shift+Alt+P.
Thanks,
xiaolin" }-
i will try this solution and report if it resolve this matter
10x xiaolin 8)
proactivelover
December 28th, 2008, 02:03 AM
problem with ESS v4 beta
demoneye
December 28th, 2008, 04:15 AM
-{ Quote: "i will try this solution and report if it resolve this matter
10x xiaolin 8)" }-
it doesnt work ,its keep jump to 90-100% cpu usage.......very odd ???
Miyasashi
December 28th, 2008, 12:10 PM
Would've been good if it didn't use 90-100% cpu on Vista Ultimate and crash all the time >_<
Once it crashed and had to turn it on otherwise I couldn't do anything else since it blocked access to everything.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums