Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    Same problem with W.7 64 bit.
    EMET 4.1 (Deep Hooks on)
    Account SUA
    Uac Max
    no antivirus real time.

    Where I can download the ver 0.09.5.1000 ?
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I really hope that you can make the GUI a bit more attractive, of course I know that with a tool like MBAE it's not the most important thing, but still. :)

    Btw, I've installed the new version, it's quite stable, but IE 11 still won't run, and even more weird, I can't exclude any process.
     
  3. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Do you also have EMET installed by any chance? If so, uncheck its SimExecFlow mitigation to see if that makes a difference.
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    No, I'm not using EMET. It's also not a big deal because normally I'm not using IE 11, but I don't like it when things break. ;)

    Also, am I correct that MBAE isn't protecting sandboxed apps? Because when I launch IE 11 via Sandboxie the problem disappears.
     
  5. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    Sandboxie blocks the injection of mbae.dll into a sandboxed process.
     
  6. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Please download and run DDS and send me via PM or email (pbustamante at malwarebytes dot org) the logs.
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I get an error when I load the tool (can't run in ''Compatibility Mode''), any other options?

    It's also flagged as a trojan on VirusTotal, but I suppose that's a false positive. ;)
     
  8. Baserk

    Baserk Registered Member

    Joined:
    Apr 14, 2008
    Posts:
    1,321
    Location:
    AmstelodamUM
    Yes, those FP's from Rising, Kingsoft and Norman can be neglected of course.
    The tool DDS, made by sUBs - well-known to anyone familiair with MBAM forum/history/testing - is fine.
    The same 'compression/packing=>flagging routine' will usually also show f.i ComboFix detected as malware by such AVs.
     
  9. ky331

    ky331 Registered Member

    Joined:
    Jun 25, 2008
    Posts:
    158
    Having an issue (F/P detection ??) with MBAE at Windows Updates site (IE8 ) on an XP system. Have e-mailed you all the logs for your consideration.
     
  10. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Got them, thanks. It's a known issue we've had under some weird conditions. We are fixing it now.
     
  11. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    "Stop Protection" button is shaded from the very start of MBAE. Is it only on my PC?
     

    Attached Files:

  12. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
    On my PC (XP32) it's not shaded. Can you stop the protection via right-click on the tray system icon?
     
  13. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    It's normal if the user doesn't have full admin privs. From the changelog:

     
  14. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    No in SUA (Win-7).

    Yes, in SUA I cannot. It's OK in Admin acc.
     
    Last edited: Mar 12, 2014
  15. aztony

    aztony Registered Member

    Joined:
    Sep 9, 2012
    Posts:
    737
    Location:
    The Valley Arizona
    0.10.0.1000 blocking manual Windows update in XP. Error message on screen 'block exploit'.
     
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Yes we have this solved already. Sending you and ky331 a new version today to verify the fix.
     
  17. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Can't seem to PM you. Please email me at pbustamante at malwarebytes dot org.
     
  18. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I missed this reply, thanks for the info. :)

    Is there a workaround for this?
     
  19. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    I suppose it's definitely possible, but at the moment there seem to be no attempts on either side to make it happen. With other solutions like HitmanPro.Alert or NoVirusThanks EXE Radar Pro, the vendors themselves have given instructions on how to adjust Sandboxie in order to make it work together with their products.
     
  20. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Can you post some links to those advices?
     
  21. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I had been having a problem to get AdobeReader to show as a protected app in MBAE when running DW Personal Firewall. See Known Issues & Conflicts

    I believe it to be solved, after conferring with the developer, ILya Rabinovich by e-mail, recently.

    However, as posted here, the "Shielded Applications" counter does not work properly, now, since that AdobeReader problem was fixed.
     
  22. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    NoVirusThanks EXE Radar Pro + Sandboxie:
    -http://novirusthanks.org/help-files/exe-radar-pro/#sbie-erp

    HitmanPro.Alert + Sandboxie:
    -http://www.wilderssecurity.com/showpost.php?p=2341146&postcount=1236
     
  23. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes, it would be cool if MBAE could offer protection inside the sandbox. I didn´t know that HP.Alert already worked together with SBIE. :)

    Btw, a bit off topic, but I noticed that SpyShelter has the ability to monitor sandboxed processes for suspicious behavior.

    So it must be possible to monitor apps in the sandbox. ;)

    What conflict did ERP have with SBIE?
     
  24. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    ERP was not detecting executions of sandboxed files.
     
  25. Brandonn2010

    Brandonn2010 Registered Member

    Joined:
    Jan 10, 2011
    Posts:
    1,854
    I've started using the beta again and have had 0 problems. Nice to see the conflict with HMP.Alert has been addressed.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.