Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Difficult to say without logs. You can either post them here or PM them to me. Instructions here:
    https://forums.malwarebytes.org/ind...e-first-posts-here-need-to-include-mbae-logs/
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  3. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Will this new fingerprinting feature in any way cause problems when trying to access online financial accounts (Bank, PayPal, Brokerage, etc..)?
     
  4. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
  5. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    The mbae log shows that chrome and IE are protected even though i have them deactivated.
     
  6. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    I wouldn't call it a gimmick but to each his own. It's a feature our researchers particularly like as it allows them to track the movement of certain Exploit Kits which try to avoid us on purpose:
    https://blog.malwarebytes.org/explo...s-anti-exploit-adds-fingerprinting-detection/

    Yes we've had this bug reported last week and we've fixed it. Maybe we'll release a hotfix for 1.08 with this fix.
     
  7. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Advanced settings > Restore defaults does not reverse to default. I know don't touch unless told to.
    Still, Restore defaults does not enable Apply.
    So, without a reference default matrix no way for Free to get back to default.
    Current stable version: 1.08.1.1044
    Where may I find image of Advanced settings Tabs at default.
     
    Last edited: Nov 12, 2015
  8. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Restore defaults does not enable Apply unless you have something different in advanced configuration from the default.
    To test this, go to advanced config, change a setting and click Apply.
    Then open advanced config again and click restore defaults.
     
  9. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    That's exactly what I did and that's why I report Restore default does nada.
    I'm left with all boxes checked after I checked all boxes expecting Restore default to work.
     
  10. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Hmm I'm not sure I understand what you're trying to say. Let's do the following tests:

    TEST 1
    1- Open Advanced settings -> Application Enforcement
    2- Enable BottomUp ASLR for Browsers
    3- Click Restore defaults
    4- Does the BottomUp ASLR checkbox become unchecked?

    TEST 2
    1- Open Advanced settings -> Application Enforcement
    2- Enable BottomUp ASLR for Browsers
    3- Click Apply
    4- Open Advanced settings -> Application Enforcement again
    5- Click Restore defaults
    6- Does the BottomUp ASLR checkbox become unchecked?
     
  11. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    No and No
    That's exactly how I started. BottomUp was the first check I added after new MBAE install.
    When BottomUp check was not removed by Restore default.
    I checked all the boxes and ended up with all boxes checked.
    Trying to Restore defaults with a broken button.
    Which is why I reported Restore defaults does nada.
     
    Last edited: Nov 13, 2015
  12. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Hmm that's weird.

    Let's do the following:

    1- Stop MBAE Service
    2- Delete the contents of C:\ProgramData\Malwarebytes Anti-Exploit (keep a copy of applications.dat if you have custom shields)
    3- Start the MBAE Service
    4- Run C:\Program Files (x86)\Malwarebytes Anti-Exploit\MBAE.EXE
    5- Repeat tests 1 and 2 above

    Does it still not work?
     
  13. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    I am repeating a post I made in the EMIS 11 and HitmanPro Alert thread. - I am not spamming - just that it is a critical problem possibly being caused by MBAE or those two other programs and I have yet determined which.

    I have installed on my Win 8.1 PC, in addition to EMIS 11, I have installed MBAE and HitmanPro Alert. In combination with Bitdefender IS 2016 there were no major issues. But I know BD IS 2016 on its own was giving me browsing issues, particularly with https: sites. But with EMIS 11 I have a critical issue. Since installing EMIS 11 my PC has been misbehaving in ways that I have never seen before. My PC will totally freeze from time to time, seemingly at random. It's not associated with any particular activity. Happens when surfing and while playing games. Another strange thing is that if I hit Escape while frozen, my PC restarts. So I don't know what the conflict is. I hated to do it, but I have started by uninstalling HitmanPro Alert. And will see. After uninstalling HitmanPro Alert, I think I should have started with uninstalling MBAE because it is known to have caused an issue at least with KIS, but that was of an entirely different nature = browsers refused to open, and it remains an issue only because of Kaspersky's arrogant attitude in not speaking with MBAE peeps who have a solution which they are being forced to do on their own within MBAE (beta). But my issue is a deal breaker for someone.
     
    Last edited: Nov 13, 2015
  14. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    Just don't run HMPA and MBAE at the same time. By running MBAE and HMPA you're not improving your level of protection but potentially only worsening due to stacked hooks.
     
  15. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    One definitely should not use HMPA, and MBAE together.
     
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    FWIW we managed to bypass this issue with KIS completely in the final 1.08 version. So this is completely solved.
     
  17. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    Yes Zero I know. Is that now a release or still beta?
     
  18. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  19. Pirate_fin

    Pirate_fin Guest

    Sometimes i get error 0xc0000018 when starting Firefox, but if i disable MBAE or restart pc it works fine and error doesn't appear for several days (or weeks)

    MBAE seems to block Firefox sometimes for some reason :(

    I'm using Panda Free Antivirus with Windows 10 and no other real-time protection running.
     
  20. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,010
    Same story with IE11 or Edge on Windows 10 Pro x64 & Avira Pro.
     
  21. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    My experiment has shown that it is HitmanPro Alert does not play nice with EMIS 11, at least on my PC. It runs fine with MBAE.

    I have used BOTH MBAE and HMPA together with NO issues with Bitdefender IS 2016 and Norton Security. Dunno why it doesn't get along with Emisoft IS 11.
    OS Win 8.1
     
  22. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  23. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    This seems to be a problem with certain Editions of Windows 10. It seems to happen mostly on Home Edition. We are investigating this issue but it has to do with a new behavior introduced in Windows 10 when injecting into a process.
     
  24. pcalvert

    pcalvert Registered Member

    Joined:
    May 21, 2005
    Posts:
    237
    On Windows XP I am frequently seeing some kind of "exception" error with MBAE version 1.08.1.1044. Unfortunately, it occurs during shutdown, so the error "pop-up" is only visible for a brief moment. If this information is being logged somewhere, where should I look to find it?
     
  25. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    See if any information is logged in the Event Viewer. If so, export it and send it to me via PM.

    Also please send me your FRST logs to see if anything might be conflicting with MBAE.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.