Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    Just got this update, to v1.11.1.45 a little while ago.

    MBAE_updated to v1.11.145_01.JPG
     
  2. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    But, ReHIPS did tell me it was coming, initially. I allowed it: "Only in This Session".

    MBAE_updated to v1.11.145_02.JPG

    Then VoodooShield popped up, and I allowed that, too! :)

    MBAE_updated to v1.11.145_03.JPG

    MBAE_updated to v1.11.145_04.JPG
     
  3. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Sir, this link has a trojan on it. I just had Eset block it, and it's no false positive. My browser was immediately hijacked, and redirected to a scam page that locked my browser after that. I'm using the latest build of Firefox. The infection may not run for everyone, but believe me, it's there.

    Time;Scanner;Object type;Object;Threat;Action;User;Information;Hash;First seen here
    12/6/2017 5:12:03 PM;Real-time file system protection;file;C:\Users\achilles\AppData\Local\Mozilla\Firefox\Profiles\zd2s79wq.default\cache2\entries\95845F8BC2CAB5A3158A5A8309D4AC9F0A4FEB69;HTML/FakeAlert.HG trojan;cleaned by deleting:DESKTOP-HITL62R\achilles;Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe (84B6E75B69D0E459C0D72088BC92786E13114D29).;121B034DD79216985FB1CC869DC838CD1A11F2A6;12/6/2017 5:12:00 PM

    Edited 12/6/17 @ 5:29 That page also shows signs of having an exploit on it, but I don't have time to verify if there is one. I have to take a huge Cisco Final in an hour. Basically my browser began to alert me that content from that page was still running in the browser (even though I closed that page about 20 minutes ago), and slowing down the browser. I then attempted to shut down the browser, and run ccleaner, but the browser would not shut down. I ended up having to kill it from the task manager.
     
    Last edited: Dec 6, 2017
  4. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    ~Virus total results removed as per Wilders policy

    I can not delete the post.
    If a moderator thinks it is necessary to delete it, he has my approval.:thumb:

    My pc (XP) is clean.
    (Scan Hitman Pro + Zemana Antimalware portable + log Hijackthis + adwcleaner)
     
    Last edited: Dec 7, 2017
  5. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
    No problem watching the video here.
    I'm on Windows 7 pro and using Chrome.
     
  6. cyberlost24

    cyberlost24 Registered Member

    Joined:
    Mar 11, 2004
    Posts:
    145
    Not wanting to risk going to that site for the video----What exactly is the video showing/telling you about??...Is it proving anything good/bad?
     
  7. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
    It shows what Sampei wrote in post referenced by post#3679.
     
  8. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    The video shows the correct intervention of MBAE ver.24.
    With the ver 45 there are all the problems that I have described in the Malwarebytes forum.
     
    Last edited: Dec 7, 2017
  9. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
  10. cyberlost24

    cyberlost24 Registered Member

    Joined:
    Mar 11, 2004
    Posts:
    145
  11. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
  12. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,918
    some1 dropped the ball for xp already, so why? :p

    if a program like this also supports xp its codebase is outdated, it has to carry ancient routines which are vulnerable in itself.
     
  13. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    Also HPA3..................:rolleyes:
     
  14. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
  15. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,003
    For Windows XP users:

    OSArmor
    : free Malwarebytes Anti-Exploit alternative
    https://www.wilderssecurity.com/threads/novirusthanks-osarmor-an-additional-layer-of-defense.398859/
    https://www.neowin.net/news/osarmor--free-malwarebytes-anti-exploit-alternative
     
  16. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
  17. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    It is OK.

    Tested with:

    • Exploit Test Tool (HPA3)
    • I.E. VB Scripting (Wicar.org)
     
  18. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    My hero ===>Sampei
    10Q very much!
     
  19. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
  20. Holysmoke

    Holysmoke Registered Member

    Joined:
    Jun 29, 2014
    Posts:
    139
    do these programs phone home with the URL's you visit like AV's do?
     
  21. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
  22. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    No updates in a while -- all is well?
     
  23. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,003
    o_O

    Dec 20, 2017
     
  24. act8192

    act8192 Registered Member

    Joined:
    Nov 9, 2006
    Posts:
    1,789
    Strange events on XP-SP3.
    Yesterday, during installing 1.11.1.48, as admin, when extracting looked done, Word opened. Totally weird.
    I was baffled, stared at it for a while, eventually closed Word and saw MBEA notice to reboot placed over that extracting thing and behind the empty Word window.
    After reboot, my firewall (Sunbelt) wasn't there and network was limited. Hmmm.
    I shutdown. Booted again, same situation. I could not restart the firewall. Just nothing. As if it didn't exist.
    Windows event log had just one related event around the installation time that MBAE didn't start within 30.... miliseconds (I don't recall exact number of zeros).

    Uninstalled 1.11.1.48, rebooted, firewall is back, network is fine.
    Today XP booted up just fine. I installed 1.10.1.24 and all is well. MBAE, Firewall icons are there. MBAE injects its DLL just fine as it always did.

    Any idea what went wrong with the installation in such a strange way? Should I try again or give up?
     
  25. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Runs fine on my XP-3. Could it be a conflict with some specific aspect of your computer's set-up?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.