DefenderUI

Discussion in 'other anti-virus software' started by digmor crusher, Aug 14, 2021.

  1. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    Joined:
    Sep 19, 2012
    Posts:
    520
    Location:
    Bulgaria
    It seems 1.16 is out:

    https://defenderui.com/Download/InstallDefenderUI116.exe
    https://defenderui.com/Download/InstallDefenderUIPro116.exe
     
  2. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,293
    Location:
    Pennsylvania.
    How do I install the new version? Overtop or uninstall the old one?
     
  3. ViVek

    ViVek Registered Member

    Joined:
    Aug 7, 2008
    Posts:
    584
    Location:
    Moon
    Overtop
     
  4. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,293
    Location:
    Pennsylvania.
    Thank you.
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,711
    Location:
    The Netherlands
    BTW, did you guys see the latest video on The PC Security Channel?

    Basically, Win Defender failed to block a certain ransomware sample with standard settings, but when DefenderUI was enabled it did block this sample. I wonder why on earth aren't these extra settings visible in Win Defender's GUI in the first place?

    You can of course also use a tool like ConfigureDefender, which doesn't need to run in memory all of the time. You can see the video on the DefenderUI website:

    https://www.defenderui.com
    https://www.softpedia.com/get/PORTABLE-SOFTWARE/System/System-Enhancements/ConfigureDefender.shtml
     
  6. Pat MacKnife

    Pat MacKnife Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    621
    Location:
    Belgium
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,711
    Location:
    The Netherlands
    OK thanks, very sad to see that MT is more active than WSF. But Andy Ful's (from ConfigureDefender) comment was quite interesting, according to him this is not how real attacks work:

     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,711
    Location:
    The Netherlands
    BTW, I decided to take a look at the latest version, and it seems to be improved, it works just fine. But does anyone know how the ''block abuse of exploited vulnerable signed drivers'' (ASR Rules) feature works? Is this something that was developed by VoodooSoft themselves, or a feature that was already hidden in Win Security?
     
  9. Freki123

    Freki123 Registered Member

    Joined:
    Jan 20, 2015
    Posts:
    337
    I can't tell you how it works but I'm pretty sure Configure Defender also has this feature and since it is listed as an ASR rule by microsoft I would say it is native in windows.
    https://learn.microsoft.com/en-us/m...reduction-rules-reference?view=o365-worldwide
     
  10. Pat MacKnife

    Pat MacKnife Registered Member

    Joined:
    Mar 31, 2014
    Posts:
    621
    Location:
    Belgium
    The missed sample is probably because of a gangbang (throw malware so fast at defender) that was skipped by defender... but with DefenderUI or configuredefender seems pretty hard to get infected.
     
  11. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,711
    Location:
    The Netherlands
    OK thanks, it seems like I'm using an older version of ConfigureDefender, which didn't offer this feature. And I have found some more info, apparantly it blocks apps from creating/loading signed drivers, but apps can still abuse vulnerable drivers that are already present on the system. And I assume this list of vulnerable drivers is updated when you update Win Defender.

    https://hackdefense.com/publications/met-asr-regels-houd-je-criminelen-buiten-de-deur/

    Yes, I also don't believe that most malware works like this, on the other hand, I did read on MT that according to someone, certain malware downloaders can download/execute multiple samples quite fast. But it's strange that MS hides these hardening features in Windows.
     
  12. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,200
    Location:
    The Netherlands
    Mail from Dan:
     
  13. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,305
    Location:
    Ontario, Canada
    Email from Dan:

     
  14. Petrovic

    Petrovic Registered Member

    Joined:
    Mar 14, 2014
    Posts:
    82
    Location:
    Russia
    1.20 is out:
    Code:
    https://defenderui.com/Download/InstallDefenderUI120.exe
     
  15. Eru

    Eru Registered Member

    Joined:
    Mar 23, 2010
    Posts:
    109
    Location:
    Poland - Sosnowiec
  16. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,305
    Location:
    Ontario, Canada
    Email from Dan:


     
  17. aldist

    aldist Registered Member

    Joined:
    Nov 8, 2017
    Posts:
    1,132
    Location:
    Lunar module
    v1.22 (May 24 2024)
     
  18. TerryWood

    TerryWood Registered Member

    Joined:
    Jan 14, 2006
    Posts:
    1,040
    Hi @ Wilders

    I need some advice please. I have just started using DefenderUI v1.22 so I am unfamiliar with it. I am on Windows 10 latest version.

    I have chosen the recommended profile and I notice on the Advanced Tab there are Threat Default actions. These are seen when Tamper Protection is disabled. In my case for the 4 threat levels i.e. Low to Severe all are set at DEFAULT as opposed to 1) Remove 2) Quarantine 3) Clean 4) Block 5) Allow 6) No Action

    1) I am unsure whether to leave at DEFAULT or whether to select from 1 to 5 above or is the default setting set elsewhere if so where?
    2) If you have to select from 1to 5 above what would be the appropriate settings for the 4 threat levels?

    Thanks

    Terry
     
  19. A_mouse

    A_mouse Registered Member

    Joined:
    Jul 29, 2019
    Posts:
    97
    Location:
    A field
    Todays v1.20 update seems to conflict with 0patch on both my Win 11 and 10 rigs.
    Any time 0patchLoaderX64.dll is accessed I get a warning that it is not safe according to the WhitelistCloud

    The file is from 2022
    ~ Removed VirusTotal Results as per Policy ~

    Adding the folder as an exception hasn't helped.
     
    Last edited by a moderator: May 27, 2024
  20. A_mouse

    A_mouse Registered Member

    Joined:
    Jul 29, 2019
    Posts:
    97
    Location:
    A field
    Looks like the cloud based check is now passing the file as Safe.
    . . .which is nice but doesn't stop Defender asking me if I want to allow 0patchloader every time it is accessed.
    Web browsers are the worst due to spawning lots of instances
     
  21. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,305
    Location:
    Ontario, Canada
    Email from Dan:


     
  22. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,305
    Location:
    Ontario, Canada
    Email from Dan:


     
    Last edited: Jun 3, 2024
  23. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,887
    I'm running DefenderUI Pro integrated with WDACLockdown.

    Plays well with Microsoft Defender for Business.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.