MZWriteScanner

Discussion in 'other anti-malware software' started by Mr.X, Feb 16, 2017.

  1. AEG

    AEG Registered Member

    Joined:
    Mar 12, 2018
    Posts:
    29
    Location:
    Middlesbrough
    I agree it's ultimately more secure with a proper whitelist, but I've come to the conclusion that it either has to be run with windows updates turned off or as a blacklisting system for vulnerable system apps like browsers. The trouble is windows now updates many things without a reboot and these updates become corrupted due to being blocked. These KBxxxxx updates write to many different parts of the disk and are different for every update so it's impossible to whitelist all possible locations except by using very wide wildcard paths on system folders and this creates huge holes in the security rendering MXWriteScanner almost useless. The forensics folder also becomes filled with huge numbers of system files that will eventually seriously degrade sytem performance due to reading the hashes in that folder. If updates are turned of, they can be manually installed say once a week with MZWriteScanner turned off and this avoids all these problems. Or you can just whitelist the C drive and blacklist vulnerable app processes which considerably hardens things like browsers.
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I agree it has to be off with most updating. One of the many reasons I stay with Win 7. I am still in control.
     
  3. guest

    guest Guest

    An updated build (beta) of MZWritescanner is available ("compiler-stamp: Mon Mar 19 07:30:54 2018")
    Download (BetaCamp)
    or: https://excubits.com/content/files/MZWriteScanner.7z
     
  4. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    And one of the reasons I remain with Windows 8.1 likewise over here.

    In fact Win9, uh I mean Win 10, normally is offline 90% and so when it is updated all security is in the 0ff position for that time it's digesting whatever it gets fed at the time. Which must be quite a diet.
     
  5. AEG

    AEG Registered Member

    Joined:
    Mar 12, 2018
    Posts:
    29
    Location:
    Middlesbrough
    After reinstalling windows 10, I get an error telling me the security certificate isn't recognised when I try to install the latest MZWriter beta. Anyone know what's causing this.
     
  6. guest

    guest Guest

    The driver (MZWriteScanner.sys) is not co-signed by Microsoft. You need to use the stable version if you want a co-signed driver.
     
  7. AEG

    AEG Registered Member

    Joined:
    Mar 12, 2018
    Posts:
    29
    Location:
    Middlesbrough
    Ok thanks. The funny thing is this was working before I reinstalled windows
     
  8. guest

    guest Guest

    Because the current version is expired, the developer uploaded a new version today.
    ("Demo driver will stop working in 2019. A follow up demo version will be available then which will work for another year.")
    Website
    mzwritescanner_demo.exe (Digital signature of the driver: April 2, 2018)
     
  9. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,811
    Location:
    .
    Thanks. Gonna check out for a FIDES refresh.
     
  10. guest

    guest Guest

    Yes, an updated driver is available :)
     
  11. guest

    guest Guest

    An updated build (beta) of MZWritescanner is available ("compiler-stamp: Wed Apr 04 16:31:53 2018")
    Download (BetaCamp)
    or: https://excubits.com/content/files/MZWriteScanner.7z

    More info:
    Newsblog: Demo and Beta Updates (2018/04/08)
     
    Last edited by a moderator: Apr 8, 2018
  12. 4Shizzle

    4Shizzle Registered Member

    Joined:
    May 27, 2015
    Posts:
    179
    Location:
    Europe
    :thumb: I hope they will soon finalize MZW so it is part of full version
     
  13. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Link: https://excubits.com/content/en/news.html
    Beta: https://excubits.com/content/en/products_beta.html
     
  14. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    New Stable Release:

    Link: https://excubits.com/content/en/news.html
    Download: https://excubits.com/content/en/products_mzwritescanner.html
     
  15. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Do we need to purchase a new license?
     
  16. 4Shizzle

    4Shizzle Registered Member

    Joined:
    May 27, 2015
    Posts:
    179
    Location:
    Europe
    No, use your individual download link. Worked for me. :thumb:
     
  17. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Does this program still demand manual typing in or copy/paste into notepad for rule making?
     
  18. guest

    guest Guest

    Yes, you still need "notepad".
     
  19. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Ok thanks. Formidable app for sure but not for me without workable user-friendly GUI. Probably something they feel better off without adding but it would create a flood of new users to it if they did.
     
  20. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I don't think they want those "new" users. Florian feels a GUI opens doors he'd rather not open. Easter, if you dropped your bias, and took a look you would find it's not nearly as bad as you think
     
  21. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Suits this user just fine. There is no corner in this particular market.
    Plus the variety is good but user friendly automation even better :)
     
  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    What else would you say is comparable.
     
  23. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    Downloads folder is on blacklist.
    I download a file. It is blocked from execution. What's the easiest way to unblock?
    Forensics is disabled.
    I tried clearing log and restarting driver, but it still blocks.
     
  24. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Sounds great. I will give it a try soon.
     
  25. guest

    guest Guest

    Try to look into the folder c:\Windows\$FORENSICS\ to find out if the hash of the blocked file is there.
    If the hash is there (as Forensics has been disabled, it should have a size of 0 bytes), then this is the reason why the file has been blocked.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.