![]() |
|
#26
|
|||
|
|||
|
The final version 2.4.1 is running fine here.
Thanks Xiaolin. |
|
#27
|
|||
|
|||
|
English version: http://www.torchsoft.com/download/md_setup.exe
French version: http://www.torchsoft.com/download/md_setup_fra.exe German version: http://www.torchsoft.com/download/md_setup_deu.exe Italian version: http://www.torchsoft.com/download/md_setup_ita.exe Spanish version: http://www.torchsoft.com/download/md_setup_esn.exe Russian version: http://www.torchsoft.com/download/md_setup_rus.exe What's new? - Fixed bugs that may cause protections to be bypassed by malware. |
|
#29
|
|||
|
|||
|
Quote:
__________________
Nick |
|
#30
|
|||
|
|||
|
Among other things, it appears to kill Malware Defender 2.4.1 (UI and service) at startup on XP SP3.
__________________
Nick |
|
#31
|
|||
|
|||
|
English version: http://www.torchsoft.com/download/md_setup.exe
French version: http://www.torchsoft.com/download/md_setup_fra.exe German version: http://www.torchsoft.com/download/md_setup_deu.exe Italian version: http://www.torchsoft.com/download/md_setup_ita.exe Spanish version: http://www.torchsoft.com/download/md_setup_esn.exe Russian version: http://www.torchsoft.com/download/md_setup_rus.exe What's new? - Fixed a bug that may cause file protection to be bypassed by malware. Sorry for the inconvenience. ![]() |
|
#32
|
||||
|
||||
|
Quote:
I don't think you incremented the build number when you compiled, mine still says 2.4.2 Edit: Nah it's cool, my browser must of had it cached. I switched browsers and got 2.4.3 Thanks Xiaolin. ![]()
__________________
NIS2010 - Malware Defender - MBAM |
|
#33
|
|||
|
|||
|
Looks like there is a 2.4.4 on its way soon, further bypasses fixed ......
|
|
#35
|
|||
|
|||
|
Quote:
__________________
Nick |
|
#37
|
|||
|
|||
|
Quote:
Edit: Please don't post links even to POC malware
__________________
Nick Last edited by Peter2150 : October 30th, 2009 at 11:18 PM. Reason: Removed Link to POC Malware |
|
#38
|
||||
|
||||
|
For those who are interested in bypassing MD,check <SNIP>. It's also why new versions come so frequently.
Last edited by Peter2150 : October 30th, 2009 at 11:21 PM. Reason: Removed questionable link. |
|
#39
|
|||
|
|||
|
Quote:
Quote:
__________________
Nick |
|
#40
|
||||
|
||||
|
Quote:
Well,I guess mj0011 will lose interest in attacking it soon. I'm not being ironical on MD though. |
|
#41
|
|||
|
|||
|
Quote:
__________________
Nick |
|
#42
|
||||
|
||||
|
Quote:
mj0011 is doing us a good favor here, I don't think he is making pocs to give MD a bad name, instead he is making pocs to improve MD and make it better by finding security holes. This indicates mj0011 must think very highly of MD. Its good to know we are using a product such as MD where an expert like mj0011 who also probably uses it. Anyway why all of a sudden can't anyone post harmless pocs any more? can some one please pm me a sample?
__________________
Sandboxie | Malware Defender | Admuncher | Kerio 2.15 | Macrium Reflect | Nat Router | TrueCrypt
FF Add On's | BetterPrivacy | Ghostery | Noscript | RandomUserAgent | Perspectives HARDENING TOOLS | Seconfig XP | WWDC | Security&Privacy | SafeXP | XP-Antispy | Bug Off COMMAND AND CONTROL |
|
#43
|
||||
|
||||
|
I'm sure this is a dumb question, but can someone tell me what the acronym POC stands for? Thanks!
__________________
RT: Malware Defender | Look 'n' Stop | Kaspersky Anti-Virus 2011 | SuRun | Acrylic DNS | Sandboxie | SAS Pro OD: HostsMan | Trojan Remover | Emsisoft CL | Vba32 CL | MBAM Pro | Acronis OS: Windows XP SP3 HW: Gigabyte GA-EP45T-UD3P | Intel QX9750 | OCZ Reaper 4GB | nVidia GTX285 | HT OMEGA Claro+ |
|
#44
|
|||
|
|||
|
Quote:
|
|
#45
|
||||
|
||||
|
Thanks DOSawaits!
__________________
RT: Malware Defender | Look 'n' Stop | Kaspersky Anti-Virus 2011 | SuRun | Acrylic DNS | Sandboxie | SAS Pro OD: HostsMan | Trojan Remover | Emsisoft CL | Vba32 CL | MBAM Pro | Acronis OS: Windows XP SP3 HW: Gigabyte GA-EP45T-UD3P | Intel QX9750 | OCZ Reaper 4GB | nVidia GTX285 | HT OMEGA Claro+ |
|
#46
|
||||
|
||||
|
So far, I'm failing to understand how to use "Groups" within MalwareDefender.
I understand how to CREATE a group: click "Rule" in the toolbar, then "Application Groups..." in its dropdown menu then, in the window titled "Application Groups", click "New Group". -=- A dialog box titled "Edit Group" pops up. an everpresent notice in the dialog box reads: "A group will not be displayed in the rule window after it is created, you must create a rule to use it." Here you type the label name for the group (filling the text name is the ONLY action you can perform in this dialog) and click "Okay" close the dialog. you must create a rule to use it CREATE a rule? Or does this mean 'empty' groups are not displayed -- must ASSIGN/MOVE at least one application (application rule item) to cause the groupname to show up in the treeview display? OR... regardless whether a custom group is empty or not empty, custom groups are NEVER displayed in the treeview? Right-clicking an application rule for one of the apps I wish to place in my newly-created custom group, when I hover at "Move to Group" in the context menu flyout, I DO NOT SEE MY NEW 'APPLICATION RULE GROUP' LISTED AMONG THE GROUP NAMES. While adding the application groupname, I noticed the "New Object" button, but I hadn't added any "object" (because I had expected that I would be adding an existing "application rule" item into the group)... so I return to the "Application Groups" window and click "New Object". I'm presented with the multi-tabbed window which is used to create new rules (any rules: network, file, application) with its "General" tab preselected. Both "select an application" and "select an application group" radio buttons are grayed-out, but the "File path" textbox shows a cursor (has focus)... so I browse/assign the exe file for one of the apps I wish the group to contain, and click "OK". -=- The icon for this "object" exe is now displayed beneath my custom group in the "Application Groups" popup window, but the custom group STILL isn't displayed in the treeview of the main (Rules tab) window. Thinking to myself "Gee, the custom group STILL doesn't have any unique permissions set"... once again I return to "New Object" and click the "Files" tab. (In this example, the intended purpose of the group is: restrict applications listed in it from writing to my D:\ drive.) At the files tab, I enter the D:\ path and tick "files and folders"... and clicking the "OK" button has no effect. This seems confusing and awkward. With every other similar app I've used, at this point I would expect to see an icon for the newly-created group in the treeview, and would expect to be able to drag one or several apps onto (into) the group. What aspect of the workflow am I missing here? |
|
#47
|
|||
|
|||
|
inka, an easy way to display the new Group is to right-click -> New Rule -> Application Rule, then select the radio button: "Select an Application Group" then find your newly created Group folder from the drop-down list and select it -> <OK> You should then see it just above "Application Rules - System".
__________________
Shameless lua and use-what's-already-built-into-the O/S troll (credit to Wilders member Windchild for the signature)
|
|
#48
|
||||
|
||||
|
Yes, it worked exactly as you described. Thank you!
|
|
#49
|
|||
|
|||
|
Quote:
You are welcome!
__________________
Shameless lua and use-what's-already-built-into-the O/S troll (credit to Wilders member Windchild for the signature)
|
|
#50
|
|||
|
|||
|
Somewhat OT, but it appears mj0011 has turned his attention from Malware Defender to Comodo Internet Security. No POC...just a demonstration video. Something about "RING3 kill any process in CIS".
__________________
Nick |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|