Is Malwarebytes still useful

Discussion in 'other anti-malware software' started by ako, Jan 25, 2015.

  1. ako

    ako Registered Member

    Joined:
    Nov 16, 2006
    Posts:
    667
    I have used MBAM now for a while without any problems. An example of resource usage:

    System idle process 11.48.09
    mbam.exe 6.17
    mbamservice.exe 5.59
    avgnt.exe 4:53
    Winpatrol.exe 4:25
    avguard.exe 4.14
    Avira.OE.servicehost.exe 2.20

    The resource usage of Avira and MBAM are thus similar.

    Overall 6% for the Avira + MBAM + Winpatrol combo
     
  2. AdvancedSetup

    AdvancedSetup Security Expert

    Joined:
    May 8, 2008
    Posts:
    141
    Location:
    USA
    We stop all current known droppers (but that said new ones come out all the time and why it's an hourly battle to update against threats)

    We are hoping to have a new version out sometime in March but will be doing another public beta before then.
     
  3. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    Thank you! :thumb:
     
  4. Krysis

    Krysis Registered Member

    Joined:
    Dec 28, 2012
    Posts:
    371
    Location:
    DownUnder
    Use MBAM Pro V1.75 in Windows 7 and free V2.0.4 in 8 Pro as 'on demand' only to scan downloaded stuff. Run daily scheduled scans in Windows 7.
    No AVs used in either Win 7 or 8

    MBAM has picked up stuff which another well known 2nd opinion scanner failed to do – so, as far as I'm concerned, MBAM does it's job and has been part of my security setup for a long time.
     
  5. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    A couple of comments regarding Malwarebytes Pro:

    1). A comment was made above Cryptologgers that "We stop all current known droppers". A more correct comment would be that "We stop all current droppers that we are aware of". If no definition is in place against the threat, files will be encrypted. I just ran an Encryptor sample that has been in the Wild for over 48 hours and it infected the system quite well indeed.

    2). A more important concern would be MB's ineffectiveness against vbs scriptors, a rapidly growing class of malware. The vector can be either via a direct script or running a legitimate application onto which a vbs script is attached. A wide variety of actions can occur, but the most popular are as info stealers- the script is run, a daughter is spawned that will autostart on Windows and will connect to a malware site that will receive whatever info is transmitted and can also act as a source of uploading other malware to the infected system. A cute thing is that even if the spawn is detected by a scan, a mechanism is in place to to re-spawn on file deletion.

    So although MB may have some benefit as a second opinion scanner and as an adjunct to a primary security application, relying on it as the primary and sole line of defense may not be a good idea.
     
    Last edited: Jan 29, 2015
  6. ako

    ako Registered Member

    Joined:
    Nov 16, 2006
    Posts:
    667
    I thought script viruses were a major threat 20 years ago. Why again?
     
  7. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    The scriptors are quite powerful and have been making a comeback for the past few years. Recently they have been used as simple vehicles for trojan downloaders and also showed up as a part of the newest Critoni class encryptors in the past few months. The scripts have also been used as part of cyber-espionage malware, Red October being one.

    Also, most worms (which are common) are VBS scriptors.
     
    Last edited: Jan 29, 2015
  8. 142395

    142395 Guest

    Almost same thing can be applied to macro virus too.
     
  9. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Certain scriptors involved in exploits, like CVE-2014-6332 for example, are blocked with Malwarebytes Anti-Exploit.

    Word macro exploits are also blocked by Malwarebytes Anti-Exploit. The same applies for other file-format exploits (pdf, xls, ppt, doc, ...).

    This approach for these type of threats is more effective than signature-based approaches.
     
  10. ako

    ako Registered Member

    Joined:
    Nov 16, 2006
    Posts:
    667
    Very nice, but should not this be part of MBAM?
     
  11. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,286
    Location:
    USA, MICHIGAN
    x2
     
  12. metmichallica

    metmichallica Registered Member

    Joined:
    Mar 16, 2005
    Posts:
    183
    I use it and like it. I have a lifetime subscription that I will be expecting to use as long as I am alive. Anyway my dad has one too and had Avira installed on his computer as antivirus and the only thing that got this bugger off his computer was Malwarebytes. The trojan made my dad's screen blurry and I thought it was the computer. Malwarebytes was worth every penny for that lifetime license. We have two computers and two licenses.
     
  13. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    Malwarebytes Anti-Exploit is also ineffective against all of the VB scriptors that I mentioned in the previous post.
     
  14. ako

    ako Registered Member

    Joined:
    Nov 16, 2006
    Posts:
    667
    So who is blocking them. Normal antivirus? I am using always LUA (or normal user) How vulnerable I am to script malware?
     
    Last edited: Jan 30, 2015
  15. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    Ako- Sadly that would be an A vs B discussion which is not allowed on Wilders.

    And forgot to mention- neither MB nor MBAE are very good at java script exploits either.
     
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    What do you mean by script exploits? Can you share or PM me an example of an exploit that is not blocked by MBAE?
     
  17. Frank the Perv

    Frank the Perv Banned

    Joined:
    Dec 16, 2005
    Posts:
    881
    Location:
    Virginia, USA

    Cruelsis,

    I've always read your posts with interest -- as you seem to know what you are talking about.

    A vs. B discussion aside, please then start a thread and tell us what you are finding, what you are thinking, what is effective in your experience.

    To stay topical.. MBAM is incredibly useful. Just looking at recent pro-test results clearly shows that MBAM is effective in detection as well as removal. Yes, there are new 'things' out there that few products are effective against. But this is where MBAM has shown its resilience in the past... rapidly adapting to the changing threat environment.


    Thanks,

    v/r Frank
     
  18. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,882
    The latter is in the premium version. The free version offers protection for browser and java exploits which are the kind most people encounter in web surfing.
     
  19. Mortal Raptor

    Mortal Raptor Banned

    Joined:
    Oct 6, 2014
    Posts:
    1,013
    Me too, I never come to this stupid junk. False positives only! a good antivirus fully updated is all you need if your machine is already clean. People running MBAM + some other AV in real time are just killing their performance.
     
  20. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,626
    In my opinion Malwarebytes is brilliant because of its excellent detection rate. I have a liftetime licence which I purchased solely to support the developer rather than to get the extra features, as I refuse to use any form of web protection / blocking, and I don't use the realtime protection. However, the faster scan speed is nice.

    In all my years of using MBAM I've probably only ever seen about three false positives. There are however, quite often items detected that I want to keep (e.g. unwanted programs that I use, or installers with adware).
     
  21. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    Is your opinion based on actually using the latest version? In my experience it has little impact on performance and I've been running it for years without false positives.
     
  22. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,286
    Location:
    USA, MICHIGAN
    You sure spread allot of false information on here,, Really this is your thinking?, with todays PC specs and the RAM they come with there is plenty of performance to handle these programs with out slowdowns. I think most developers work hard to make these programs light.
     
  23. Mortal Raptor

    Mortal Raptor Banned

    Joined:
    Oct 6, 2014
    Posts:
    1,013
    Yes sir, read below post
     
  24. Mortal Raptor

    Mortal Raptor Banned

    Joined:
    Oct 6, 2014
    Posts:
    1,013
    I don't buddy, I say what I experienced, this product is not for me. Heck, I had my Adobe CS6 suite activation DLLs backups saved so when I need to reinstall, I don't have to activate everytime as I have many CS 6 products like Photoshop, Illustrator, InDesign, Audition.....

    When I run a scan with MBAM (full scan) it always fails.... so I contact them on the forums and submitted the logs....you know what they say?

    Their reply:

    "Your computer has files to help steal Adobe Software and thus we can offer you no support!"

    so they want to play the anti-copy right police and those DLLs are not cracks, they are my personal backups. My thread was locked when I asked for help. MBAM never ever found anything . Not that it's bad, I just don't see the point of having a good AV PLUS MBAM. Like it's good for people who use MSE or WD for example but running any of the good AVs like Trend, F-Secure, Norton, Kaspersky, Bitdefender with MBAM is just overkill IMHO

    just my 2 cents worth

    PS: @daman1, I know you don't like me because I put your beloved Bitdefender to shame by saying the ugly truth about how buggy it is, awwww
     
  25. kardokristal

    kardokristal Developer

    Joined:
    Jan 6, 2012
    Posts:
    1,091
    Location:
    Estonia
    Hi,

    I can say that Malwarebytes Anti-Malware saved two systems (coworker's laptops) recently.. so my conclusion is that it is still one of the best AM product. :)

    Regards,
    Kardo
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.