DefenderUI

Discussion in 'other anti-virus software' started by digmor crusher, Aug 14, 2021.

  1. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    Joined:
    Sep 19, 2012
    Posts:
    519
    Location:
    Bulgaria
    It seems 1.16 is out:

    https://defenderui.com/Download/InstallDefenderUI116.exe
    https://defenderui.com/Download/InstallDefenderUIPro116.exe
     
  2. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,291
    Location:
    Pennsylvania.
    How do I install the new version? Overtop or uninstall the old one?
     
  3. ViVek

    ViVek Registered Member

    Joined:
    Aug 7, 2008
    Posts:
    584
    Location:
    Moon
    Overtop
     
  4. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,291
    Location:
    Pennsylvania.
    Thank you.
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    BTW, did you guys see the latest video on The PC Security Channel?

    Basically, Win Defender failed to block a certain ransomware sample with standard settings, but when DefenderUI was enabled it did block this sample. I wonder why on earth aren't these extra settings visible in Win Defender's GUI in the first place?

    You can of course also use a tool like ConfigureDefender, which doesn't need to run in memory all of the time. You can see the video on the DefenderUI website:

    https://www.defenderui.com
    https://www.softpedia.com/get/PORTABLE-SOFTWARE/System/System-Enhancements/ConfigureDefender.shtml
     
  6. Pat MacKnife

    Pat MacKnife Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    620
    Location:
    Belgium
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    OK thanks, very sad to see that MT is more active than WSF. But Andy Ful's (from ConfigureDefender) comment was quite interesting, according to him this is not how real attacks work:

     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    BTW, I decided to take a look at the latest version, and it seems to be improved, it works just fine. But does anyone know how the ''block abuse of exploited vulnerable signed drivers'' (ASR Rules) feature works? Is this something that was developed by VoodooSoft themselves, or a feature that was already hidden in Win Security?
     
  9. Freki123

    Freki123 Registered Member

    Joined:
    Jan 20, 2015
    Posts:
    337
    I can't tell you how it works but I'm pretty sure Configure Defender also has this feature and since it is listed as an ASR rule by microsoft I would say it is native in windows.
    https://learn.microsoft.com/en-us/m...reduction-rules-reference?view=o365-worldwide
     
  10. Pat MacKnife

    Pat MacKnife Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    620
    Location:
    Belgium
    The missed sample is probably because of a gangbang (throw malware so fast at defender) that was skipped by defender... but with DefenderUI or configuredefender seems pretty hard to get infected.
     
  11. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    OK thanks, it seems like I'm using an older version of ConfigureDefender, which didn't offer this feature. And I have found some more info, apparantly it blocks apps from creating/loading signed drivers, but apps can still abuse vulnerable drivers that are already present on the system. And I assume this list of vulnerable drivers is updated when you update Win Defender.

    https://hackdefense.com/publications/met-asr-regels-houd-je-criminelen-buiten-de-deur/

    Yes, I also don't believe that most malware works like this, on the other hand, I did read on MT that according to someone, certain malware downloaders can download/execute multiple samples quite fast. But it's strange that MS hides these hardening features in Windows.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.