Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. SIR****TMG

    SIR****TMG Registered Member

    Joined:
    May 31, 2004
    Posts:
    833
    Trying out the new build now.
     
  2. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    Without digital signature you installed new version?
     
  3. SIR****TMG

    SIR****TMG Registered Member

    Joined:
    May 31, 2004
    Posts:
    833
    Yes its running fine so far , also its under shadow mode. So no problems here
     
  4. haakon

    haakon Guest

    1.09.1.1201 New Features:
    • Hardened and more secure API hooking framework
    • Added self protection mechanisms
    • Added sandbox technique for Silverlight
    • Added Layer3 techniques against Macro exploits
    • Added Layer3 techniques against social engineering exploits
    • Added Java advanced configuration options for companies
    • Added dynamic configuration feature to manage conflicts
    • Added support for MS Play Ready
    • Changed balloon notification to off by default
    • Remove Run entry during uninstallation

    Fixes:
    • Fixed conflict with Symantec DLP
    • Fixed conflict with Chinese banking software
    • Fixed conflict with Office TabLoader
    • Fixed conflict woth Kobil mIdentity software
    • Fixed false positive with Adobe and .NET modules
    • Fixed issue when adding invalid custom shield
     
  5. haakon

    haakon Guest

    Yes. A developer's experimental release installed on an experimental (aka test) system.
     
  6. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    Stopping MBAE 1.09.1.1180 Protection locks my PC for as long as five minutes every time I do it. Nothing I can do other than to wait it out or hard reboot.

    Does MBAE have A.I. that punishes me for being a foolish/bad boy when I do this :)

    I usually disable all security products other than firewall when creating a Windows Restore Point.

    WIN 1067 64X OS
     
  7. loungehake

    loungehake Registered Member

    Joined:
    Mar 9, 2015
    Posts:
    201
    Location:
    Wigan
    Works faultlessly on my Windows 7 64bit and Windows XP SP3 (SSE2 processor) systems. As is typical of this reckless user, all Advanced Settings are checked with the exception of Ret Rop Gadget Protections (Chrome browser options ARE checked). Additional shields for SumatraPDF (pdf) and Mozilla Thunderbird (other) are in use.

    I guess that support for pre-SSE2 processors is at an end. If that is the case, I hope that automatic updating is inhibited for systems with SSE only processors.
     
  8. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    hawki

    I don't see that here on my system.
     
  9. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,
    The developer is investigating as to how this happened. In the meantime, the download link has been removed and will be replaced shortly with a link to a digitally signed version.
     
  10. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    Thank you for the news.
     
  11. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello Mister X,

    You are most welcome :) !
     
  12. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    A new experimental build, version 1.09.1.1208, has been released...
    Announcement and download link: MBAE 1.09 preview
    The issue with the no digital signature with build 1201 has been rectified and build 1208 is now digitally signed...
     
  13. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    I have voodoshield with a similar anti exploit function. I wonder if I need to shut one or the other off?
     
  14. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,008
    Thanks puff-m-d

    From 1.09.1.1180 to 1.09.1.1208 on Windows 10 Pro x64 (Version 1607 - Build 14393.321).
    Browser: Edge and IE11 only.

    No problems so far.
     
  15. SIR****TMG

    SIR****TMG Registered Member

    Joined:
    May 31, 2004
    Posts:
    833
    Yes its running fine so far , also its under shadow mode. So no problems here
     
  16. Houley456

    Houley456 Registered Member

    Joined:
    Feb 9, 2007
    Posts:
    199
    Anyone?
     
  17. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    From a logical point of view I would shut off one or another. Being the anti-exploit techniques a very complex set of algorithms per se and very complex its interaction with the shielded programs, I believe both working at the same time could result in a crash or something...
     
  18. Azure Phoenix

    Azure Phoenix Registered Member

    Joined:
    Nov 22, 2014
    Posts:
    1,560
    That's assuming anti-exploit component in VoodooShield is as complex as those in standalone exploit programs like EMET, MBAE, and HMP.Alert.

    @boredog @Houley456
    I recommend asking at the VoodooShield thread as well. But I believe Dan stated using both wouldn't be a problem. You can ask him to confirm.
     
  19. guest

    guest Guest

    VS isn't providing that kind of exploit-feature which Malwarebytes Anti-Exploit is providing.
    "Enable VoodooShield anti-exploit protection for all web apps in all file / folder locations"
    With this option VS "only" blocks child processes of web app parent processes. This feature is all about execution of files.
    MBAE is a different level of protection, and more complex (injecting into the protected app, mitigations, memory calls, etc.)

    So VS and MBAE shouldn't interfere with each other.
    (but for example HMP.A and MBAE can (and will) interfere with each other, because they are providing the same features ... more or less)
     
  20. Houley456

    Houley456 Registered Member

    Joined:
    Feb 9, 2007
    Posts:
    199
    Running VoodooShield and HitmanPro.Alert now and so far so good......will see how it goes.....
     
  21. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    actually I have at least three anti exploits. Cylance, Malwarbytes Anti exploit and Voodooshield. I also think Adguard does some because I see it block web pages also but I am not sure.
     
  22. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Why not add HMP.A as well, to make sure :)
     
  23. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    paul :thumb:

    and now I think about it I believe adguard just uses a black list.
     
  24. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes correct, normally anti-executable and anti-exploit should not interfere with each other because they are using different methods of protection. I didn't have any problems with the MBAE + EXE Radar combo.
     
  25. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Yep, my favorite combo is AntiExploit + AntiExecutable. Never was an issue b/w them.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.