ZeroVulnerabilityLabs ExploitShield

Discussion in 'other anti-malware software' started by sbwhiteman, Sep 28, 2012.

Thread Status:
Not open for further replies.
  1. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    Minecraft gets blocked from updating and starting. I'll have to uninstall ES.
     
  2. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Probably some WMP plugin or special operation. Can you provide more information such as what's installed under WMP and the type of problem/event/message that you receive?
     
  3. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,567
    Location:
    New York City
    "Windows Media player has stopped working. A problem caused the program from working correctly. Windows will close the program and notify you if a solution is available."

    Faulting application name: wmplayer.exe, version: 12.0.7601.17514, time stamp: 0x4ce7a485
    Faulting module name: SHLWAPI.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b9e2
    Exception code: 0xc0000005
    Fault offset: 0x00013898
    Faulting process id: 0x410
    Faulting application start time: 0x01ce0f95aaef852d
    Faulting application path: C:\Program Files\Windows Media Player\wmplayer.exe
    Faulting module path: C:\Windows\system32\SHLWAPI.dll

    Nothing installed under WMP, as far as I know.

    Windows 7, 32 bit, IE 10, WSA 8.0.2.109
     
    Last edited: Feb 20, 2013
  4. Boost

    Boost Registered Member

    Joined:
    Feb 2, 2007
    Posts:
    1,294
    I had the same issue when I tried out ZeroVulnerabilityLabs ExploitShield on a 32-bit Windows XP PC. I was just using windows media player at the time with no add-ons,etc.
     
  5. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,567
    Location:
    New York City
  6. popcorn

    popcorn Registered Member

    Joined:
    Apr 3, 2012
    Posts:
    239
    ExploitShield.dll is loading in chrome.exe :thumb:
     

    Attached Files:

  7. luciddream

    luciddream Registered Member

    Joined:
    Mar 22, 2007
    Posts:
    2,545
    No, I haven't tried ES yet at all. I don't have a test machine or VM, so I don't mess around with Beta apps. I'm waiting for it to go final and mature a bit.

    I may very well run into no problem at all. I rarely do. I don't have much installed on my box at all. That's why I rarely run into conflicts... there aint much there to conflict with. Comodo & SBIE are the only things running real-time. Besides that a browser, VLC, 2 cleaning tools+ Puran Defrag, a couple on demand scanners, and games/emulators. That's about it. And very few services running.

    Also none of the stuff you really need things like ES/EMET for in the first place... like Java, .NET FW, PDF reader. So the need for such a thing is far less than an average user. Still I'm sure there's some other things it could protect against that could benefit me.
     
    Last edited: Feb 22, 2013
  8. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    We've added the WMP issue to the list of known issues. However we have not been able to replicate it.

    Please send me the output of autoruns.exe or DDS to see what other software & addons you have at the time of the crash.
     
  9. Boost

    Boost Registered Member

    Joined:
    Feb 2, 2007
    Posts:
    1,294
    I used ZeroVulnerabilityLabs ExploitShield for a short time period,and have since uninstalled Windows media Player and using VLC player.
     
  10. luciddream

    luciddream Registered Member

    Joined:
    Mar 22, 2007
    Posts:
    2,545
    I'd be interested in hearing about any conflicts with VLC. I'm using version 2.0.5
     
  11. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    I should add that Minecraft is dependent of the Java library.
     
  12. Skiaz

    Skiaz Registered Member

    Joined:
    May 28, 2010
    Posts:
    10
    Location:
    USA
    I too am still having the issue with WMP as I reported earlier in this forum. I am using Windows 7 x64. At the time of the original posting I was using Webroot Secure Anywhere but that has since expired and is no longer on the system.

    I currently have NIS 2013, Zemana AntiLogger and EMET 3.5TP for security. I have tried uninstalling EMET and disabling AntiLogger and ExploitShield still causes WMP to not work correctly or not at all. As soon as I remove or disable ExploitShield and open WMP it works correctly and enumerates all the music again.

    When I install ES and open WMP it just takes a minute or two and al the media (music in this case) disappears from WMP thought it is still on the disk. I have not gotten to the point where WMP will not open again but I saw the exact errors listed a few posts back.

    Is autoruns output sufficient for you to look into this problem? I can provide most anything required as I would like to know what the problem is.
     
  13. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,567
    Location:
    New York City
    There seems to be a bug with Exploitshield since I removed WSA and ExplotShield still was causing WMP to crash. I sent an autoruns log file via email to ZeroVulnerabilityLabs. I hope it will be helpful.
     
  14. ZVL can you block Citidel? o_O
     
  15. RJK3

    RJK3 Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    862
    Install in a sandbox with appropriate restrictions, run Minecraft in that sandbox.
     
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    ZVL is payload agnostic. It simply blocks exploit payloads from executing.

    So if the exploit is dropping Citidel then it will block Citidel from running. If the exploit drops the Windows calculator then ExploitShield will block calc.exe from running. We really don't care WHAT is being executed, we only care about HOW it is being executed.

    In regards to WMP we'll have to take a closer look at it again. It might have to do with components that manage libraries which is something we haven't tested yet.
     
  17. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
    Is Citadel an exploit? No. ES is supposed to prevent exploits from downloading trojans like Citadel in your computer. Which trojan is the payload of the exploit is irrelevant.

    Edit: five seconds late. ZeroVulnLabs beat me to it.
     
  18. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
    I'm testing Trusteer Rapport and ExploitShield for the nth time now. TR doesn't show any injection blocking alert this time and the ExploitShield.dll is under Firefox in Process Explorer. Can anyone confirm this?

    I hope this means that they finally whitelisted ES and it's not just a Rapport's miss function on my system.
     
  19. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Are there any plans to provide ES in other idioms when it reaches the final version?

    P.S: I don't recall if it has been asked before, and it's a long thread by now, so I apologize if it has been asked.
     
  20. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Its in our backlog and we thought about community-driven translations, but it's still low priority right now.
     
  21. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
    Yesterday I had a block alert from ExploitShield when I hit 'play' on an embedded Youtube video at Tumblr. It said that USER32.dll had been blocked from executing through Firefox; the video was removed from the blog a couple of hours later.

    So it seems that ExploitShield and Trusteer Rapport are running along nicely in my system: XP 32 SP3.
     
  22. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
    Same here with the Sumatra plugin. But now Firefox 19 comes with its own pdf reader, still not very good though.
     
  23. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    Do you have a new version almost ready for release? Or do you plan to extend the expiration date of the current release? I was getting ready to install ES on a couple new machines but saw the current version was getting ready to expire. I decided to wait for a new version or an extended expiration date to make it easier as I am putting these on a friend's machines and there is no auto-update feature (that I know of)....
     
  24. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Which I still have a license for. Sorry for the late reply. It's near impossible to keep up with all threads with my work schedule. I was thinking about Linkscanner / Socketshield also when I learned about ExploitShield.
     
  25. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    There's a new version going to be released before the end of the month. It includes a lot of engine and performance improvements.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.