Malware Defender 2.1.0 beta

Discussion in 'other anti-malware software' started by xiaolin, Mar 11, 2009.

Thread Status:
Not open for further replies.
  1. nick s

    nick s Registered Member

    Joined:
    Nov 20, 2002
    Posts:
    1,430
    I did some quick tests and can confirm that MD's network functionality depends on Vista's Base Filtering Engine (BFE) service. The Windows Firewall (MpsSvc) service is not a factor. Given this dependency, I added a new registry rule to protect BFE from being tampered with...
     

    Attached Files:

  2. Espresso

    Espresso Registered Member

    Joined:
    Aug 1, 2006
    Posts:
    976
    Thanks for confirming this. I can't believe no one else noticed this or had an issue with it, considering how many people disable the built in windows firewall. It's also unusual that the dev didn't point this out as a possible cause.

    MD doesn't appear to turn the service on automatically or notice when it's shut down. A serious oversight for such a critical element, IMO (unless it's only an issue on my system).
     
  3. xiaolin

    xiaolin Registered Member

    Joined:
    Aug 11, 2008
    Posts:
    248
    I will fix it in next release. thx
     
  4. mike21

    mike21 Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    416
    Hi, after extensive testing, I would like to make a request if possible:

    When an alert window pops up, under create rule for this action there are 2 options:
    - Permanent Rule
    - Temporary rule (until process exits)

    Since some process automatically re-launched, I would really like a 3rd option, like:

    - Temporary rule for the next ** minutes (like RTD)
    - Temporary rule which will be deleted on next system reboot

    Please consider implementation, thanks.
     
  5. xiaolin

    xiaolin Registered Member

    Joined:
    Aug 11, 2008
    Posts:
    248
    Thanks for the suggestion. I will think about it but the alert window is already big. You can put those processes in a special group and delete it manually later.
     
  6. xiaolin

    xiaolin Registered Member

    Joined:
    Aug 11, 2008
    Posts:
    248
    Malware Defender 2.1.1 beta1 is released

    The beta version is available for download at http://www.torchsoft.com/download/md_setup_2.1.1_b1.exe

    what's new?
    - Added protection against controlling processes using DDE.
    - Added support for Windows 7 build 7068.
    - Added support for running in safe mode to change rules and settings.
    - Moved rundll32.exe out of system applications rules.
    - Changed the default initial file rules of explorer.exe to allow accessing all files.
    - Fixed a bug when renaming rule group.
    - Fixed a bug when verifying file signatures.

    It's recommended to search rundll32.exe and delete all rundll32.exe in child applications rules. You may need to restart your system in learning mode to create new rules for rundll32.exe.
     
  7. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Xialin,

    Would it be possible to also show the comment line when showing a pop up (of thet specific rule)

    Thx
     
  8. xiaolin

    xiaolin Registered Member

    Joined:
    Aug 11, 2008
    Posts:
    248
    Actually, the feature is implemented in this beta release. :)
     
  9. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Thanks, but I do not see my own description in teh pop-up using beta 2.1.1 b1 at teh moment?
     
    Last edited: Apr 7, 2009
  10. demoneye

    demoneye Registered Member

    Joined:
    Dec 30, 2007
    Posts:
    1,356
    Location:
    ISRHell
    Re: Malware Defender 2.1.1 beta1 is released

    i think this change will fix the all hangout or cpu high load +sysytem hangout


    will check for some times and see :)
     
  11. demoneye

    demoneye Registered Member

    Joined:
    Dec 30, 2007
    Posts:
    1,356
    Location:
    ISRHell
    Re: Malware Defender 2.1.1 beta1 is released


    can u write step by step how to do it?

    10x
     
  12. xiaolin

    xiaolin Registered Member

    Joined:
    Aug 11, 2008
    Posts:
    248
    Re: Malware Defender 2.1.1 beta1 is released

    This change is intend to reduce alerts when manipulating files with explorer.exe. It's only affect the initial rules (fresh installation or select Rule menu->Restore Default rules). If you upgrade from old versions, you can create a permit * rule in explorer.exe.

    Thanks,
    Xiaolin
     
  13. mike21

    mike21 Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    416
    You press "CTRL + F". Then you type "rundll32" in the searchbox and then you delete all instances found (including child applications' rules)
     
  14. xiaolin

    xiaolin Registered Member

    Joined:
    Aug 11, 2008
    Posts:
    248
    Re: Malware Defender 2.1.1 beta1 is released

    1. Edit menu -> Find Rules -> search "rundll32.exe"
    2. Double click the item in the Rule Find Results to jump to the rule, if it's a child app rule, delete it.
    3. Restart system in learning mode.
     
  15. demoneye

    demoneye Registered Member

    Joined:
    Dec 30, 2007
    Posts:
    1,356
    Location:
    ISRHell
    i did fresh install an a never installed MD before , i still found like u said "rundll32.exe" rules , so do i need to dell them all ?
     
  16. mike21

    mike21 Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    416
    Yes delete them all and then reboot and put MD in learning mode for 30 minutes and during this, do some ordinary PC jobs, including windows update
     
  17. demoneye

    demoneye Registered Member

    Joined:
    Dec 30, 2007
    Posts:
    1,356
    Location:
    ISRHell
    10x mate but Xiaolin says i need not if its a fresh MD install...
     
  18. Hunter42

    Hunter42 Registered Member

    Joined:
    Nov 19, 2008
    Posts:
    7
    Question:

    Does the new beta support Windows 7 x64 ? :)

    Hunter42
     
  19. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Running the latest beta. Smooth as silk. Cleaned the rundll32.exe schtuff easily.

    MD is THE most actively maintained HIPS. Simply superb! :thumb: :thumb: :thumb:
     
  20. tony62

    tony62 Registered Member

    Joined:
    Aug 26, 2005
    Posts:
    214
    Location:
    UK
    Yes, thanks very much xiaolin:)
     
  21. xiaolin

    xiaolin Registered Member

    Joined:
    Aug 11, 2008
    Posts:
    248
    MD do not support x64 yet. thx
     
  22. wat0114

    wat0114 Guest

    Thanks again for the update xiaolin! BTW, can you or someone provide an example test for the DDE control?
     
  23. tony62

    tony62 Registered Member

    Joined:
    Aug 26, 2005
    Posts:
    214
    Location:
    UK
  24. wat0114

    wat0114 Guest

    Attached Files:

    Last edited by a moderator: Apr 7, 2009
  25. xiaolin

    xiaolin Registered Member

    Joined:
    Aug 11, 2008
    Posts:
    248
    Actually, it's a bug that DDE messages are not handled in previous releases. :)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.