Wilders Security Forums  

Go Back   Wilders Security Forums > Security Software > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old October 28th, 2009, 09:12 PM
smith2006 smith2006 is offline
Frequent Poster
 
Join Date: Mar 2006
Posts: 464
Default Re: Malware Defender 2.4.1 beta

The final version 2.4.1 is running fine here.

Thanks Xiaolin.
  #27  
Old October 29th, 2009, 11:04 PM
xiaolin xiaolin is offline
Frequent Poster
 
Join Date: Aug 2008
Posts: 244
Default Malware Defender 2.4.2 final is released

English version: http://www.torchsoft.com/download/md_setup.exe
French version: http://www.torchsoft.com/download/md_setup_fra.exe
German version: http://www.torchsoft.com/download/md_setup_deu.exe
Italian version: http://www.torchsoft.com/download/md_setup_ita.exe
Spanish version: http://www.torchsoft.com/download/md_setup_esn.exe
Russian version: http://www.torchsoft.com/download/md_setup_rus.exe

What's new?
- Fixed bugs that may cause protections to be bypassed by malware.
  #29  
Old October 29th, 2009, 11:53 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,426
Default Re: Malware Defender 2.4.2 final is released

Quote:
Originally Posted by ssj100
Could you please provide any further details on that? Thanks.
Google killmdfile.rar. Xiaolin will have explain it to us in layman's terms: ProbeBypass attack techniques. The POC download link is at the end of the post.
__________________
Nick
  #30  
Old October 30th, 2009, 12:02 AM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,426
Default Re: Malware Defender 2.4.1 beta

Among other things, it appears to kill Malware Defender 2.4.1 (UI and service) at startup on XP SP3.
__________________
Nick
  #31  
Old October 30th, 2009, 03:54 AM
xiaolin xiaolin is offline
Frequent Poster
 
Join Date: Aug 2008
Posts: 244
Default Malware Defender 2.4.3 final is released

English version: http://www.torchsoft.com/download/md_setup.exe
French version: http://www.torchsoft.com/download/md_setup_fra.exe
German version: http://www.torchsoft.com/download/md_setup_deu.exe
Italian version: http://www.torchsoft.com/download/md_setup_ita.exe
Spanish version: http://www.torchsoft.com/download/md_setup_esn.exe
Russian version: http://www.torchsoft.com/download/md_setup_rus.exe

What's new?
- Fixed a bug that may cause file protection to be bypassed by malware.

Sorry for the inconvenience.
  #32  
Old October 30th, 2009, 04:09 AM
1boss1's Avatar
1boss1 1boss1 is online now
Frequent Poster
 
Join Date: Jun 2009
Location: Australia
Posts: 397
Default Re: Malware Defender 2.4.3 final is released

Quote:
Malware Defender 2.4.3

I don't think you incremented the build number when you compiled, mine still says 2.4.2

Edit: Nah it's cool, my browser must of had it cached. I switched browsers and got 2.4.3

Thanks Xiaolin.
__________________
NIS2010 - Malware Defender - MBAM
  #33  
Old October 30th, 2009, 02:31 PM
Scoobs72 Scoobs72 is offline
Frequent Poster
 
Join Date: Jul 2007
Posts: 308
Default Re: Malware Defender 2.4.1 beta

Looks like there is a 2.4.4 on its way soon, further bypasses fixed ......
  #35  
Old October 30th, 2009, 03:56 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,426
Default Re: Malware Defender 2.4.1 beta

Quote:
Originally Posted by ssj100
Where are these bypasses suddenly coming from?
The 3 POCs are the work of a Chinese security researcher known as mj0011. mj0011 coded the Tophet POC rootkit/bootkit last year. The English version of MD 2.4.4 beta 1 is available here: http://www.torchsoft.com/download/md_setup_2.4.4_b1.exe. It addresses the third and most recent POC.
__________________
Nick
  #37  
Old October 30th, 2009, 04:04 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,426
Default Re: Malware Defender 2.4.1 beta

Quote:
Originally Posted by ssj100
Thanks for the information. Any chance we can get our hands on those POCs?
You can get them here: <Snip>. Don't use Google translate. The POCs can be found in the fourth folder down.




Edit: Please don't post links even to POC malware
__________________
Nick

Last edited by Peter2150 : October 30th, 2009 at 11:18 PM. Reason: Removed Link to POC Malware
  #38  
Old October 30th, 2009, 10:20 PM
bonedriven's Avatar
bonedriven bonedriven is offline
Frequent Poster
 
Join Date: Jan 2007
Posts: 434
Default Re: Malware Defender 2.4.1 beta

For those who are interested in bypassing MD,check <SNIP>. It's also why new versions come so frequently.

Last edited by Peter2150 : October 30th, 2009 at 11:21 PM. Reason: Removed questionable link.
  #39  
Old October 30th, 2009, 11:02 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,426
Default Re: Malware Defender 2.4.1 beta

Quote:
Originally Posted by bonedriven
It's also why new versions come so frequently.
and the contest may go on for a while...

Quote:
This is the third issued a breakthrough MD file protection code, all current attacks are directed at treatment of MD right NtCreateFile hook, while the rest of the hook MD Department are about 3,40 ~ just NtCreateFile, at least there are five kinds of The attack left
__________________
Nick
  #40  
Old October 30th, 2009, 11:20 PM
bonedriven's Avatar
bonedriven bonedriven is offline
Frequent Poster
 
Join Date: Jan 2007
Posts: 434
Default Re: Malware Defender 2.4.1 beta

Quote:
Originally Posted by nick s
and the contest may go on for a while...

Well,I guess mj0011 will lose interest in attacking it soon. I'm not being ironical on MD though.
  #41  
Old October 30th, 2009, 11:47 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,426
Default Re: Malware Defender 2.4.1 beta

Quote:
Originally Posted by bonedriven
I'm not being ironical on MD though.
This is a good thing for MD. I want the security apps that I use to be given serious scrutiny.
__________________
Nick
  #42  
Old October 31st, 2009, 02:31 AM
arran's Avatar
arran arran is offline
Frequent Poster
 
Join Date: Feb 2008
Posts: 980
Default Re: Malware Defender 2.4.1 beta

Quote:
Originally Posted by bonedriven
Well,I guess mj0011 will lose interest in attacking it soon. I'm not being ironical on MD though.

mj0011 is doing us a good favor here, I don't think he is making pocs to give MD a bad name, instead he is making pocs to improve MD and make it better by finding security holes.

This indicates mj0011 must think very highly of MD. Its good to know we are using a product such as MD where an expert like mj0011 who also probably uses it.


Anyway why all of a sudden can't anyone post harmless pocs any more? can some one please pm me a sample?
__________________
Sandboxie | Malware Defender | Admuncher | Kerio 2.15 | Macrium Reflect | Nat Router | TrueCrypt
FF Add On's | BetterPrivacy | Ghostery | Noscript | RandomUserAgent | Perspectives
HARDENING TOOLS | Seconfig XP | WWDC | Security&Privacy | SafeXP | XP-Antispy | Bug Off
COMMAND AND CONTROL
  #43  
Old October 31st, 2009, 06:26 PM
0strodamus's Avatar
0strodamus 0strodamus is offline
Frequent Poster
 
Join Date: Aug 2009
Location: New York / Arizona, USA
Posts: 310
Default Re: Malware Defender 2.4.1 beta

I'm sure this is a dumb question, but can someone tell me what the acronym POC stands for? Thanks!
__________________
RT: Malware Defender | Look 'n' Stop | Kaspersky Anti-Virus 2011 | SuRun | Acrylic DNS | Sandboxie | SAS Pro
OD: HostsMan | Trojan Remover | Emsisoft CL | Vba32 CL | MBAM Pro | Acronis
OS: Windows XP SP3
HW: Gigabyte GA-EP45T-UD3P | Intel QX9750 | OCZ Reaper 4GB | nVidia GTX285 | HT OMEGA Claro+
  #44  
Old October 31st, 2009, 06:29 PM
DOSawaits DOSawaits is offline
Regular Poster
 
Join Date: Dec 2008
Posts: 165
Default Re: Malware Defender 2.4.1 beta

Quote:
Originally Posted by Derelict_NY
I'm sure this is a dumb question, but can someone tell me what the acronym POC stands for? Thanks!
Proof of Concept
  #45  
Old October 31st, 2009, 07:50 PM
0strodamus's Avatar
0strodamus 0strodamus is offline
Frequent Poster
 
Join Date: Aug 2009
Location: New York / Arizona, USA
Posts: 310
Default Re: Malware Defender 2.4.1 beta

Thanks DOSawaits!
__________________
RT: Malware Defender | Look 'n' Stop | Kaspersky Anti-Virus 2011 | SuRun | Acrylic DNS | Sandboxie | SAS Pro
OD: HostsMan | Trojan Remover | Emsisoft CL | Vba32 CL | MBAM Pro | Acronis
OS: Windows XP SP3
HW: Gigabyte GA-EP45T-UD3P | Intel QX9750 | OCZ Reaper 4GB | nVidia GTX285 | HT OMEGA Claro+
  #46  
Old November 1st, 2009, 03:15 PM
inka's Avatar
inka inka is offline
Regular Poster
 
Join Date: Oct 2009
Posts: 122
Default Re: Malware Defender 2.4.1 beta

So far, I'm failing to understand how to use "Groups" within MalwareDefender.

I understand how to CREATE a group:
click "Rule" in the toolbar, then "Application Groups..." in its dropdown menu
then, in the window titled "Application Groups", click "New Group".
-=-
A dialog box titled "Edit Group" pops up.
an everpresent notice in the dialog box reads: "A group will not be displayed in the rule window after it is created, you must create a rule to use it."
Here you type the label name for the group
(filling the text name is the ONLY action you can perform in this dialog)
and click "Okay" close the dialog.

you must create a rule to use it
CREATE a rule? Or does this mean 'empty' groups are not displayed -- must ASSIGN/MOVE at least one application (application rule item) to cause the groupname to show up in the treeview display? OR... regardless whether a custom group is empty or not empty, custom groups are NEVER displayed in the treeview?

Right-clicking an application rule for one of the apps I wish to place in my newly-created custom group, when I hover at "Move to Group" in the context menu flyout, I DO NOT SEE MY NEW 'APPLICATION RULE GROUP' LISTED AMONG THE GROUP NAMES.

While adding the application groupname, I noticed the "New Object" button, but I hadn't added any "object" (because I had expected that I would be adding an existing "application rule" item into the group)... so I return to the "Application Groups" window and click "New Object". I'm presented with the multi-tabbed window which is used to create new rules (any rules: network, file, application) with its "General" tab preselected. Both "select an application" and "select an application group" radio buttons are grayed-out, but the "File path" textbox shows a cursor (has focus)... so I browse/assign the exe file for one of the apps I wish the group to contain, and click "OK".
-=-
The icon for this "object" exe is now displayed beneath my custom group in the "Application Groups" popup window, but the custom group STILL isn't displayed in the treeview of the main (Rules tab) window. Thinking to myself "Gee, the custom group STILL doesn't have any unique permissions set"... once again I return to "New Object" and click the "Files" tab. (In this example, the intended purpose of the group is: restrict applications listed in it from writing to my D:\ drive.) At the files tab, I enter the D:\ path and tick "files and folders"... and clicking the "OK" button has no effect.

This seems confusing and awkward. With every other similar app I've used, at this point I would expect to see an icon for the newly-created group in the treeview, and would expect to be able to drag one or several apps onto (into) the group.

What aspect of the workflow am I missing here?
  #47  
Old November 1st, 2009, 03:54 PM
wat0114 wat0114 is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: S.W. Alberta, Canada
Posts: 2,024
Default Re: Malware Defender 2.4.1 beta

inka, an easy way to display the new Group is to right-click -> New Rule -> Application Rule, then select the radio button: "Select an Application Group" then find your newly created Group folder from the drop-down list and select it -> <OK> You should then see it just above "Application Rules - System".
__________________
Shameless lua and use-what's-already-built-into-the O/S troll (credit to Wilders member Windchild for the signature)
  #48  
Old November 1st, 2009, 08:14 PM
inka's Avatar
inka inka is offline
Regular Poster
 
Join Date: Oct 2009
Posts: 122
Default Re: Malware Defender 2.4.1 beta

Yes, it worked exactly as you described. Thank you!
  #49  
Old November 1st, 2009, 08:32 PM
wat0114 wat0114 is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: S.W. Alberta, Canada
Posts: 2,024
Default Re: Malware Defender 2.4.1 beta

Quote:
Originally Posted by inka
Yes, it worked exactly as you described. Thank you!

You are welcome!
__________________
Shameless lua and use-what's-already-built-into-the O/S troll (credit to Wilders member Windchild for the signature)
  #50  
Old November 1st, 2009, 11:32 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,426
Default Re: Malware Defender 2.4.1 beta

Somewhat OT, but it appears mj0011 has turned his attention from Malware Defender to Comodo Internet Security. No POC...just a demonstration video. Something about "RING3 kill any process in CIS".
__________________
Nick
 

Wilders Security Forums > Security Software > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:38 AM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums