Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    unchecked all from stackpiviotong and same results
     
  2. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Try completely disabling Cylance and rebooting to see if the problem persists.
     
  3. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    that would mean uninstalling cylance and I am not ready to do that so for now I will either leave antiexploit disabled or go back to the previous version.
     
  4. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    I detest "combinations". I went to the hardware store yesterday to buy a shovel. The only one they had in stock was a combination shovel/can opener/FM radio, with an optional enema bag attachment. I fear that that is the sort of thing that MBAM is headed toward.
     
  5. SIR****TMG

    SIR****TMG Registered Member

    Joined:
    May 31, 2004
    Posts:
    833
    Bellgamin bought 2 of them shovels, just what he was looking for.Ha Ha....
     
  6. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    I echo your feeling. But we're not trying to bundle unnecessary crap like traditional Security Suites. From the perspective of a regular joe blow user that's not security conscious, they really need a good proactive security product (anti-malware + anti-exploit + anti-ransomware + etc). For folks like us, we'll still be able to layer different components and different products. We're designing it in a way that will allow you to do that. Plus you'll always be able to keep your MBAE standalone. So you'll really have two ways with the new MBAM to keep your setup as is.
     
  7. syrinx

    syrinx Registered Member

    Joined:
    Apr 7, 2014
    Posts:
    427
    Great news, I'm making a screenshot of this in case I need to remind you of that statement later. :p
     
  8. Now I understand why you are sticking to XP, you detest combinations.

    Windows 10 Home version got a 2-way Firewall, a Sandbox (AppContainer), HIPS (UAC and Protected processes), Anti-executable (Parental control and ACL), Anti-exploit (DEP, Sehop, ASLR, EMET and Control Flow Guard), Whitelist (Smartscreen) and a Blacklist (Windows Defender). You just wanted an OS.
     
    Last edited by a moderator: Jun 28, 2016
  9. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    zero I am wondering why all of a sudden antiexploit stopped working with cylance after the last beta install? it always worked before that.

    Edge still opened with antiexploit active.

    update: I went into advanced and unchecked one by one while clicking on IE until all were unticked. IE would still not open. then went into shields and deactivated IE then tried opening IE and it worked.
     
    Last edited: Jun 28, 2016
  10. Trying the beta 1.09

    For Office apps I enabled RET ROP Gadget Detection 32 bits and protection message box payload, Office WMI abuse and Office VBA7 abuse. Seems to run fine with Office 2007 with hardened Trustcenter settings (block macro's, active X and plug-ins)

    regards Kees
     
  11. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    Kees I know you don't use IE but if you still have it, could you try open it with this new beta please? I only have edge and ie on this windows 10 machine so my ie is 11
     
  12. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Are you completely closing IE between changes to the advanced settings? A change of advanced setting only applies after the application has been completely closed and then re-opened again.
     
  13. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    yes I close IE after each one. I check a box click apply then try open IE. repeat, repeat ect.
    even look at task manager to make sure it is not running
    only thing that works is deactivating IE in shields.

    should I try reinstalling over this build?

    update: I uninstalled the last version and installed 1.08 and now antiexploit does work again.
     
    Last edited: Jun 28, 2016
  14. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    We'll add Cylance to our QA test process.

    Any idea where I can get a Cylance trial/test product?
     
  15. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    why do you think it is cylance? you can get a demo from their site.
    when I go back to 1.08 everything works again. what did you YOU do different?
     
    Last edited: Jun 28, 2016
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    It's the one from the items in your sig that's the best candidate for a conflict since AFAIK it includes some basic anti-exploit. But if you send me your complete FRST I'll have a better idea.

    Btw, no download from Cylance website, just request for sales people to contact you. Is the product available for download somewhere?
     
  17. haakon

    haakon Guest

    A waste of time and resources. The source of this opinion? The "Ever heard of Cylance?" thread and the waste of bandwidth regarding it in this thread. :isay:
     
  18. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    LOL

    As for me I like DIY layered approach. That's why still having Windows 7, MBAE, 3-d party FW etc.
     
  19. guest

    guest Guest

    So you have no problems or other negative side-effects with enabling all checkboxes with the old version?
    I'm using only default-settings at the moment, but i think about to harden MBAE a little bit.
     
  20. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Actually there's persistent problem in my Windows 7 SUA when all advanced settings are checked:

    The same is for "Advanced settings" button and some others.

    There's no "shading" in Admin account. I can tweak MBAE in Admin account.
    No other problems when I set MBAE at maximum.

    Capture.PNG Capture2.PNG Capture3.PNG
     
  21. liba

    liba Registered Member

    Joined:
    Jan 21, 2016
    Posts:
    344
    Exploit Test Tool
    http://dl.surfright.nl/hmpalert-test.exe
     
  22. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,006
    =
    https://www.wilderssecurity.com/threads/malwarebytes-anti-exploit.354641/page-67#post-2458888
    -----
    https://www.wilderssecurity.com/sear...Test Tool&t=post&o=relevance&c[thread]=354641
     
    Last edited by a moderator: Jun 29, 2016
  23. I have MBAE on my Windows 10 Pro 32 bits, also disabled IE11. On my Asus transformer I run Office 2013 without outlook.
     
  24. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    " But if you send me your complete FRST I'll have a better idea.

    I reinstalled the new beta and now cylance ark grrrrrr

    still appears to be running after reboot though.

    where should I send the FRST file to?
     

    Attached Files:

    Last edited: Jun 29, 2016
  25. guest

    guest Guest

    Maybe choose Cylance or MBAE :cautious:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.