Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. luciddream

    luciddream Registered Member

    Joined:
    Mar 22, 2007
    Posts:
    2,545
    Another feature I'd love to see is the option for manual updating. I don't like to allow ANYTHING to update automatically, or basically do anything at all without my say so. That's just how I like to run my ship. And also don't want to have to uninstall the old version and install the new every single time there's an update... because I'm VERY meticulous when I do that. I really dig to clean up all the left over "junk" first, reboot, defrag, reboot again, even format the partition if I have a program having it's own dedicated partition (which I often do because isolation is a big part of my approach).

    So yeah, that would be really nice, along with showing exactly which shields are working in addition to the mere number of them that are.
     
  2. syrinx

    syrinx Registered Member

    Joined:
    Apr 7, 2014
    Posts:
    427
    Right there with you, very few programs on my PC can 'dial out' and I actually partially depend on wilders to let me know when a program I use is updated though I do check myself occasionally. I was actually behind the curb when it came to MBAE as I wasn't even aware of the latest version until I read about it here!

    The shields issue, yeah, that's a peeve of mine....I'd like to see that in a GUI interface as well considering how often the count is off on my system. ;)
     
  3. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Value = 0x00000000(0)
     
  4. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    1,934
    Location:
    North of the 38th parallel.
    Hello bellgamin:

    That DWORD value is most likely why your XP system lacks Balloon Tips. Try changing to a "1" and restart XP. Please let us know if that helps.

    Thank you. :)
     
    Last edited: May 4, 2015
  5. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    If you go into MBAE -> Settings you can uncheck the "Automatically upgrade to new versions". This should have the effect you're looking for. When a new version becomes available via the auto-upgrade mechanisms then MBAE will let you know and ask (OK/Cancel) if you want to upgrade.
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Great news, I was able to make it work on Win 8.1 64 bit, with the help of syrinx's template, so thanks to you both! I only needed to add the lines to "C:\Program Files\Sandboxie\Templates.ini". Now MBAE automaticly injects the mbae.dll into sandboxed browsers, and so far it hasn't made SBIE malfunction at all. I even got proof that it actually works because it terminated Firefox, I had to disable "BottomUp ASLR Enforcement" to fix this false positive.

    The only things that I did notice is that even when you disable MBAE's protection, it keeps injecting code, so I'm not sure if protection is really disabled then. I also saw that FlashPlayerPlugin.exe kept hanging in memory, even when Firefox was closed, but maybe that was a one time thing.
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I agree, this option should have never been removed. I'm not really into tool-tips, so please give both options. It's also a handy logging tool to see when browsers and other apps were started.
     
  8. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,807
    Location:
    .
    I can second this too...
     
  9. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Agreed, many users seem to be requesting the same thing. We'll probably bring it back as an optional item for advanced users.
     
  10. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,172
    Location:
    Canada
    Would like to see it back as well.
     
  11. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Cool, I hope this will be fixed, and I'm very excited to see that MBAE is now able to work together with Sandboxie, it's just another selling point! I hope you can now fine tune MBAE and do regular tests to make sure that it will never conflict with SBIE in the future.
     
  12. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,807
    Location:
    .
    I second that too!
    @ZeroVulnLabs please remember Sandboxie is for many of us the first line of defense in our systems... Thanks a lot for your superb job!
     
  13. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Changed enable value to 1 per suggestions. Tool-tips are now working. Thanks to all who helped.
     
  14. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    1,934
    Location:
    North of the 38th parallel.
    @bellgamin: We're glad you have your balloon tips back. :)
     
  15. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Coming soon...

    Screen_25 2015-05-08 19.36.jpg
     
  16. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,807
    Location:
    .
    Thanks a lot !!!
     
  17. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,172
    Location:
    Canada
    Excellent pbust. Never has been a problem for me, the logs accumulating, I just delete them every couple weeks or so.
     
  18. quietman

    quietman Registered Member

    Joined:
    Dec 27, 2014
    Posts:
    511
    Location:
    Earth .... occasionally
    I was also clearing out accumulated logs from time-to-time.
    Now I don't appear to be getting any .
    I just had a look through settings and can't find any option to enable/disable logging.

    Any ideas ?
     
  19. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    1,934
    Location:
    North of the 38th parallel.
  20. quietman

    quietman Registered Member

    Joined:
    Dec 27, 2014
    Posts:
    511
    Location:
    Earth .... occasionally

    Many thanks 1PW , that explains the change that I noticed .
    It got quietly updated .....
    .... on checking further , I see that the " Auto-upgrade " box is ticked by default.

    I would normally be ok with that , because Malwarebytes is one of my more trusted developers ..
    .... but there's that faint alarm bell ringing in my head.

    Didn't they roll-out the " Borker King" of updates to MBAM a few years ago ?

    If so , I'm happy that I didn't get an Auto-upgrade on that occasion !
     
  21. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    1,934
    Location:
    North of the 38th parallel.
    I too had not been keeping up and I temporarily thought I was looking at a defective release. ...and I was wrong.
    I'm sure most developers/distributors have suffered those embarrassments. However, at the risk of slowing the release flow, the MBAM database updates now are expected to pass a more stringent approval process. The application upgrades pass through QA folks, and the extensive upgrades go through limited and public beta trials while the release versions seem to be throttled out. Yet adventurous users can still be early adopters of release versions.

    Cheers. :)
     
  22. wshrugged

    wshrugged Registered Member

    Joined:
    Jun 12, 2009
    Posts:
    266
    (Above bolded by me.)

    Hello 1PW,

    Has MB made an announcement concerning the above bolded sentence? If so, will you please post a link(s) to it?

    Thank you.
     
  23. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    1,934
    Location:
    North of the 38th parallel.
  24. wshrugged

    wshrugged Registered Member

    Joined:
    Jun 12, 2009
    Posts:
    266
    Thank you for taking the time to get the link, 1PW. :) I incorrectly inferred from your earlier statement that there had been a more recent announcement/development.

    Back on-topic -- @pbust -- :thumb: for the return (via option) of more verbose, event logs.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.