Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Great! Thanks
    I use Sumatra Portable, can I add that as well?
     
  2. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,814
    Location:
    .
    Of course Overkill :thumb:
     
  3. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Are the default advanced settings good enough for media players?
     
  4. haakon

    haakon Guest

    I did. Works OK if opening a PDF from the File menu or double clicking a PDF if it's set as the app in the Default Programs\Set Associations Control Panel. As well when opening PDF links from a Mozilla browser if set in Options > Applications. Can't say for any other browser.
     
  5. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I see nothing is ticked under media players for application hardening, can this be tweaked without any problems?
     
    Last edited: Sep 6, 2015
  6. co22

    co22 Registered Member

    Joined:
    Nov 22, 2011
    Posts:
    411
    Location:
    router

    Attached Files:

  7. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,189
    Location:
    The Netherlands
    I had some problems with Anti-Exploit not starting with Qihoo 360 Total Security, but they are solved with the new beta 1.08.1.1016.
    Probably I will go tomorrow to my parents and see if the problems with Kaspersky 2016 are also resolved.
     
  8. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Can you repro this consistently? Does the problem continue after a reboot? If so please send me FRST logs.
     
  9. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    No, it is not gone forever. We're looking into alternatives.
     
  10. onigen

    onigen Registered Member

    Joined:
    Oct 26, 2009
    Posts:
    29
    Beta 1.08.1.1016 works fine, installed over previous.

    New options =)
     
  11. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,010
    Ok then.
     
  12. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    @ZeroVulnLabs

    I added Thunderbird.
    I have to add to the list also shield its plugin container.exe?
    TH.
     
  13. haakon

    haakon Guest

    No. If you try, MBAE will tell you it already exists. All plugin-container.exe is shielded by default no matter which Mozilla app opens it. The shield goes active even for Cyberfox64 Portable on my D: partition. Impressive.
     
  14. Pliskin

    Pliskin Registered Member

    Joined:
    Feb 8, 2009
    Posts:
    440
    I have installed MBAE 1.08 Beta and when I try to start Opera v12, I get this:
    http://postimg.org/image/llnj0ba97/

    Same false positive happens with QtWeb. K-Meleon works fine. I am using XP.
     
  15. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,189
    Location:
    The Netherlands
    @ZeroVulnLabs Sorry to report that I still have the problem that Anti-Exploit will not start with 360 Total Security 7.2.0.1053.
    Anything I can do to help to resolve this problem?
     

    Attached Files:

  16. co22

    co22 Registered Member

    Joined:
    Nov 22, 2011
    Posts:
    411
    Location:
    router
    check pm.i can install 1.07.1.1015 but not this test version
     
  17. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,010
    Try once again.
     
  18. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    @Pliskin can you please PM me your MBAE logs directory in a ZIP? (C:\ProgramData\Malwarebytes Anti-Exploit)

    @Gandalf_The_Grey & @co22 please do a fresh re-install as per this. If that still doesn't work, please send me your FRST and MBAE logs. Also check your 360 settings to make sure they are not disabling the MBAE startup entry.
     
  19. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,189
    Location:
    The Netherlands
    @ZeroVulnLabs Reinstalling did not solve my problem. Here are the requested files.
     

    Attached Files:

  20. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    TH.:thumb:
     
  21. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    @Gandalf_The_Grey I see that the MBAE service is installed, but not running. Can you try to start it manually from "services.msc"? Also check to make sure the service is set to Automatic.

    If the service starts, then run mbae.exe manually (double clicking on it).
     
  22. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,189
    Location:
    The Netherlands
    That works, but why the service is not running while set to automatic I don't know. As far as I can see it is not blocked by 360TS.
     
  23. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Maybe they blocked it from running right after install but didn't report it?
     
  24. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,189
    Location:
    The Netherlands
    Anyway to see or solve that?
     
  25. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Try enabling auditing on that directory/registry or find a util that will audit access to those startup locations (services and reg run key). Windows has a built-in auditing but it sucks. Try NirSoft. Their tools rock.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.