Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Yes, it is in the Premium version. I have many custom shields.
     
  2. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    That's exactly what I wanted to know, Thank you.

    Now, hopefully they'll add a default shield/profile for Edge.
     
  3. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Yes, that's the plan. However since the naming of the browser and its filename has changed a few times over the last few months, we are waiting on a final release of Windows 10 before adding it. When that happens, the shield will be a default shield and part of MBAE Free.
     
  4. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    I think waiting for final release is a smart move :thumb: and I am glad that the shield will be added in later versions

    Thanks for letting us know
     
  5. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
    Pedro, your signature still shows 1007 as the current beta build. :)
     
  6. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    1.07.1.1010 is still running great on Windows 7X64 Ultimate after upgrading from build 1.07.1.1009. I have been using build 1010 for 2 days now.
     
  7. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  8. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
  9. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Can I just install over the top of the old version?
     
  10. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Yes of course!
     
  11. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
  12. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    1.07 just installed and lets see what happens now.
     
  13. Infected

    Infected Registered Member

    Joined:
    Feb 9, 2015
    Posts:
    1,135
    Outlook is blocked by MBAE, saying a exploit was detected. It happens with Application Hardening. BottomUP ASLR is blocking it. And IE is blocked by Anti-Heap v1.07
     
  14. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  15. Infected

    Infected Registered Member

    Joined:
    Feb 9, 2015
    Posts:
    1,135
    Windows 8 64b. No, everything is set to default. I had Comodo shut down.
     
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Try uninstalling Comodo and/or the workaround. Simply turning it off might not do the trick.
     
  17. Infected

    Infected Registered Member

    Joined:
    Feb 9, 2015
    Posts:
    1,135
    Ok, I'll try it soon and let you know.
     
  18. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    Some of my extension icons freeze up with chrome using MBAE 1.07. It probably did it in 1.06 also that is one reason why i had to use HitmanPA for chrome. I tied 1.07 with chrome to see if any problems had been fixed that i had with 1.06. It looks like i have the same problems with 1.07 so back to HMPA for chrome. I don't have any problems using dragon with MBAE only chrome.
     
  19. act8192

    act8192 Registered Member

    Joined:
    Nov 9, 2006
    Posts:
    1,789
    Opera has three flavors by now.
    The original one is what I use - current version 12.17.
    Then there is the chrome-Opera and, finally, Vivaldi under construction.
    Does one shield manage all of them? Just curious.
     
  20. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Can you send logs from FRST to try to replicate it in an environment similar to yours? Which extensions freeze up? Does the freeze mean it takes them long to open or that chrome itself freezes?

    As long as they are all called opera.exe then the same shield applies to all of them. Currently the ChromeBrowser shield is used in MBAE to protect Opera.
     
  21. reyes

    reyes Registered Member

    Joined:
    Dec 8, 2013
    Posts:
    48
    Location:
    INDIA
    OS Win 8.1 64bit
    MBAE 1.07.1.1010

    In Appguard If i add C:/sandboxie to Userspace and include set to "Yes", it blocks mbae64.dll when i open sandboxed IE. But no problem running Firefox under sandboxie
    http://i.imgur.com/29qJY3u.jpg
     
  22. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
  23. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    The new version is OK:

    Immagine.jpg

    Tested with Chrome/I.E. 64 bit.
     
  24. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Can you send me crash dumps of the various chrome.exe processes that are running when you encounter the freeze? You can right-click on each chrome.exe process from Process Explorer and choose Create Dump -> Create Full Dump.
     
  25. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    @ ZeroVulnLabs

    Is this (see link) something that should be covered by MBAE? And BTW, at the moment v1.07 seems to be working just fine, also with some self-added shields. I've not yet tested it with Sandboxie, but I'm not expecting any problems.

    http://seclists.org/bugtraq/2015/Jul/23
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.