Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,418
    Just installed the latest version, however it is missing the tray icon.

    I know it is a 'known' issue.
     
  2. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Are you sure it's not hidden?
    :D
     
  3. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,418
    :D No, not hidden. I just terminated the process, and relaunched. OK, now.

    However, it says "shielded applications: 0" That, is not correct.
     
  4. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    As you said, it is a known issue. The next beta, version 0.10.0, will fix this.
     
  5. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Looks like the counter is still an issue...:doubt:
     
  6. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,418
    I could close the browser, and relaunch. But, why bother. ;)
     
  7. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    The cosmetic issues are really not a priority right now. We are focused on finishing the engine so we can start on a new GUI for it, where most of these cosmetic issues will disappear since it will be a new GUI.
     
  8. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,418
    Will the new GUI follow on with a similar MalwareBytes theme as in the coming 'new look' MBAM?
     
  9. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Yes, that's the idea.
     
  10. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,418
    :thumb:
     
  11. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,277
    Location:
    Canada
    Installed new version, no problems.
     
  12. Drew99GT

    Drew99GT Registered Member

    Joined:
    Jun 27, 2006
    Posts:
    340
    Location:
    Colorado Springs
    I'm testing it; when you open a flash video in a browser or any other application like java applets through a browser, should it show up in the log that it's protecting themo_O Because it doesn't!

    :edit: OK, in Firefox with the plugincontainer disabled and Flash's sandbox disabled, no separate exe runs when viewing flash objects; will MBAE still protecto_O I also tried flash objects in IE11 and nothing popped up in the log.
     
  13. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    No it should not show up. Plugins/Addons that run within the browser process space will only show in MBAE as the browser as being protected.
     
  14. ratchet

    ratchet Registered Member

    Joined:
    Feb 20, 2006
    Posts:
    1,988
    I have Mb pro running. Would you recommend I install this application? Thank you!
     
  15. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    Yes, you should give it a try, either MBAE or EMET.
     
  16. luciddream

    luciddream Registered Member

    Joined:
    Mar 22, 2007
    Posts:
    2,545
    Just want to give props for your due diligence in being on top of things with this app. I expect big things from it. I think it's important that you make it very compatible with EMET, so that people can use both. Since it uses different methods they should be able to co-exist together and really form a formidable layer against exploits. I plan no keeping an XP box around after it's EOL, and can't stand .NET FW as it cripples my setup with bloat. And so I can't use EMET on it. So I'm really keeping an eye on this product. And even on my Win7 box I'd like to be able to use both.

    So keep up the good work. I look forward to stable releases.
     
  17. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    Just a curious question... I use the latest Opera version 19. It typically has the opera.exe parent process and then on average of 8 to 10 opera.exe child processes under it. I have checked and the the mbae.dll is injected into the parent and all of the children. Now the question... The MBAE logs will state Opera is being protected and the main page of the GUI states anywhere from 0 to 3 shielded applications (according to logs only Opera is being protected). I assume Opera is being shielded but the number of shielded applications shown is misleading. When the shielded application number is 0, am I protected? Should the number of shielded applications be with Opera a count of the parent and all opera.exe children or just 1 for the parent? I am a bit confused as to what I should be seeing...
     
  18. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Yes the counter is not terribly reliable and we've had problems keeping it accurate all along due to a multitude of reasons (unstable termination of processes, unreliable un-injection, etc.).

    This does not in any way interfere with the protection, but I understand it might introduce doubts to the average user, so we will probably change this in the future and have a different way of visibly showing protected programs. For example I like the idea of the yellow outline that Sandboxie uses for sandboxed apps. Any other ideas or suggestions?
     
  19. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    The idea of the yellow outline sounds interesting. I am not totally sure whether I would like this or not. It sounds like a good possibility but I think it may be one of those things I would like to see in action before I make a definitive opinion one way or the other. If this was implemented, you may want in option to turn this feature on and off.What about process that run without an obvious window, like Java or Windows Scripting Host? Hmmm, I will think on this and post back if I think of any better ideas (IMHO of course).
     
  20. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    How about a '#' in the titlebar of processes? '#' would indicate that the process is protected by MBAE.
     
  21. ExtremeGamerBR

    ExtremeGamerBR Registered Member

    Joined:
    Aug 3, 2010
    Posts:
    1,350
    It works with HP.Alert and EMET?

    Can I use MBAE + Sandboxie?

    This software will be free forever?

    Thanks!
     
  22. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    2,313
    Location:
    .
  23. ExtremeGamerBR

    ExtremeGamerBR Registered Member

    Joined:
    Aug 3, 2010
    Posts:
    1,350
    Thank you! :thumb: :thumb: :thumb:

    Too bad:

    I don't want to pay for security anymore. Anyway, this software looks very good! :)
     
  24. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    * Works with HP.Alert and EMET, although there are some conflicts with certain EMET configurations. See our Known Issues & Conflicts list.
    https://forums.malwarebytes.org/index.php?showtopic=135127

    * Sandboxie does not allow MBAE to inject into sandboxed processes.

    * We have no finalized plans for the 1.0 release mode, but a free + pro approach is up there in the list.
     
  25. ExtremeGamerBR

    ExtremeGamerBR Registered Member

    Joined:
    Aug 3, 2010
    Posts:
    1,350
    Thank you! :thumb: :thumb: :thumb:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.