Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. Sampei Nihira

    Sampei Nihira Registered Member

    Same problem with W.7 64 bit.
    EMET 4.1 (Deep Hooks on)
    Account SUA
    Uac Max
    no antivirus real time.

    Where I can download the ver 0.09.5.1000 ?
     
  2. Rasheed187

    Rasheed187 Registered Member

    I really hope that you can make the GUI a bit more attractive, of course I know that with a tool like MBAE it's not the most important thing, but still. :)

    Btw, I've installed the new version, it's quite stable, but IE 11 still won't run, and even more weird, I can't exclude any process.
     
  3. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Do you also have EMET installed by any chance? If so, uncheck its SimExecFlow mitigation to see if that makes a difference.
     
  4. Rasheed187

    Rasheed187 Registered Member

    No, I'm not using EMET. It's also not a big deal because normally I'm not using IE 11, but I don't like it when things break. ;)

    Also, am I correct that MBAE isn't protecting sandboxed apps? Because when I launch IE 11 via Sandboxie the problem disappears.
     
  5. FleischmannTV

    FleischmannTV Registered Member

    Sandboxie blocks the injection of mbae.dll into a sandboxed process.
     
  6. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Please download and run DDS and send me via PM or email (pbustamante at malwarebytes dot org) the logs.
     
  7. Rasheed187

    Rasheed187 Registered Member

    I get an error when I load the tool (can't run in ''Compatibility Mode''), any other options?

    It's also flagged as a trojan on VirusTotal, but I suppose that's a false positive. ;)
     
  8. Baserk

    Baserk Registered Member

    Yes, those FP's from Rising, Kingsoft and Norman can be neglected of course.
    The tool DDS, made by sUBs - well-known to anyone familiair with MBAM forum/history/testing - is fine.
    The same 'compression/packing=>flagging routine' will usually also show f.i ComboFix detected as malware by such AVs.
     
  9. ky331

    ky331 Registered Member

    Having an issue (F/P detection ??) with MBAE at Windows Updates site (IE8 ) on an XP system. Have e-mailed you all the logs for your consideration.
     
  10. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Got them, thanks. It's a known issue we've had under some weird conditions. We are fixing it now.
     
  11. Solarlynx

    Solarlynx Registered Member

    "Stop Protection" button is shaded from the very start of MBAE. Is it only on my PC?
     

    Attached Files:

  12. vojta

    vojta Registered Member

    On my PC (XP32) it's not shaded. Can you stop the protection via right-click on the tray system icon?
     
  13. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    It's normal if the user doesn't have full admin privs. From the changelog:

     
  14. Solarlynx

    Solarlynx Registered Member

    No in SUA (Win-7).

    Yes, in SUA I cannot. It's OK in Admin acc.
     
    Last edited: Mar 12, 2014
  15. aztony

    aztony Registered Member

    0.10.0.1000 blocking manual Windows update in XP. Error message on screen 'block exploit'.
     
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Yes we have this solved already. Sending you and ky331 a new version today to verify the fix.
     
  17. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Can't seem to PM you. Please email me at pbustamante at malwarebytes dot org.
     
  18. Rasheed187

    Rasheed187 Registered Member

    I missed this reply, thanks for the info. :)

    Is there a workaround for this?
     
  19. FleischmannTV

    FleischmannTV Registered Member

    I suppose it's definitely possible, but at the moment there seem to be no attempts on either side to make it happen. With other solutions like HitmanPro.Alert or NoVirusThanks EXE Radar Pro, the vendors themselves have given instructions on how to adjust Sandboxie in order to make it work together with their products.
     
  20. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Can you post some links to those advices?
     
  21. Tarnak

    Tarnak Registered Member

    I had been having a problem to get AdobeReader to show as a protected app in MBAE when running DW Personal Firewall. See Known Issues & Conflicts

    I believe it to be solved, after conferring with the developer, ILya Rabinovich by e-mail, recently.

    However, as posted here, the "Shielded Applications" counter does not work properly, now, since that AdobeReader problem was fixed.
     
  22. FleischmannTV

    FleischmannTV Registered Member

    NoVirusThanks EXE Radar Pro + Sandboxie:
    -http://novirusthanks.org/help-files/exe-radar-pro/#sbie-erp

    HitmanPro.Alert + Sandboxie:
    -http://www.wilderssecurity.com/showpost.php?p=2341146&postcount=1236
     
  23. Rasheed187

    Rasheed187 Registered Member

    Yes, it would be cool if MBAE could offer protection inside the sandbox. I didn´t know that HP.Alert already worked together with SBIE. :)

    Btw, a bit off topic, but I noticed that SpyShelter has the ability to monitor sandboxed processes for suspicious behavior.

    So it must be possible to monitor apps in the sandbox. ;)

    What conflict did ERP have with SBIE?
     
  24. siketa

    siketa Registered Member

    ERP was not detecting executions of sandboxed files.
     
  25. Brandonn2010

    Brandonn2010 Registered Member

    I've started using the beta again and have had 0 problems. Nice to see the conflict with HMP.Alert has been addressed.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice