Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. guest

    guest Guest

    You can use the command-line utility "Coreinfo" from Sysinternals.
    It prints some information about your CPU. Search for "SSE" in the output from this utility and if you can see at least SSE2 you can use newer versions of MBAE.
     
  2. act8192

    act8192 Registered Member

    Joined:
    Nov 9, 2006
    Posts:
    1,789
    Thanks, mood.
    I just did a quickie look using Everest. It says it supports IA SSE, IA SSE2 and IA SSE3.
    It's Pentium4 laptop.
    Do you think it's the same thing as the sysinternals job? I'll get it anyway later.
     
  3. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    I used cpuidmax2 from Major Geeks. Tiny program. Works great. Very fast. EASY to use. Doesn't make me use cmd.exe to run it. Yep - me got SSE2. Life is good, wot?
     
  4. guest

    guest Guest

    Ok, Everest is much better than a command-line utility ;)
    You have SSE3, there should be no problem with coming MBAE-updates.
     
  5. loungehake

    loungehake Registered Member

    Joined:
    Mar 9, 2015
    Posts:
    201
    Location:
    Wigan
    It's clear from the evidence from others that MBAE 1.09 will not run on systems with pre-SSE2, i.e. SSE only, processors.

    Those who use old SSE-only processors will find that MBAE 1.08.1.2572 persists in trying to offer MBAE 1.09.1.1235 in spite of it being unable to execute. I'm afraid that the opportunity to have coded MBAE 1.08.1.2572 so that it recognises pre-SSE2 hardware, and so does not install an unusable version update, appears to have been lost.
     
  6. SIR****TMG

    SIR****TMG Registered Member

    Joined:
    May 31, 2004
    Posts:
    833
    1.09.1.1235 is running fine here
     
  7. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,006
    Release Notes =
    https://www.malwarebytes.com/support/releasehistory/
     
  8. CeeBee

    CeeBee Registered Member

    Joined:
    Nov 20, 2015
    Posts:
    60
    To clarify this I opened a ticket with MBAE Support and on a direct question if pre-SSE2 is supported by 1.09 I was told: "The CPU\hardware type is unrelated to this issue that you’re experiencing as others are also having it and we’re collecting the same data so that we can try to find the cause."

    Still a bit fuzzy, but, it may imply that SSE only may still be supported .. or maybe not. Clear as mud...

    Postscript: MBAE Support has okayed posting the above quote!
     
    Last edited: Nov 3, 2016
  9. loungehake

    loungehake Registered Member

    Joined:
    Mar 9, 2015
    Posts:
    201
    Location:
    Wigan
    Pedro Bustamante sent me a message in the early days of MBAE 1.09 beta. I had raised the problem of the non-execution of the beta on my pre-SSE2 processor equipped hardware and he said something to the effect that the developers were concentrating on getting MBAE 1.09 to work on mainstream hardware. I wonder if Pedro's apparent current absence from the scene is reflected in the non-progress with this SSE issue.
     
  10. CeeBee

    CeeBee Registered Member

    Joined:
    Nov 20, 2015
    Posts:
    60
    I miss Pedro too. His answers are normally very reliable and to the point! Oh well. I contacted MBAE Support again and this is what I asked and what I was told:

    NOV 03, 2016 | 10:36AM PDT
    Support: Correct there are no specific hardware required to run 1.09 nor are there any documented issues at this time so no patches to be considered, especially in any case where we have no way to troubleshoot what else could be on the system causing the conflict.

    NOV 03, 2016 | 09:10AM PDT
    CeeBee: Sorry to sound a bit dense here .. but, in effect, what you are saying/confirming is that v.1.09 should work fine on a computer with SSE only CPU. In case of issues, that's not related to SSE or SSE2. If that's the case, let me know when you have an update to the current 1.09 and I'll give it another try.

    Postscript: MBAE Support has okayed posting the above quote!

     
    Last edited: Nov 3, 2016
  11. loungehake

    loungehake Registered Member

    Joined:
    Mar 9, 2015
    Posts:
    201
    Location:
    Wigan
    All I can add is to say that on both Windows XP SP3 SSE only PCs on which I installed it, MBAE 1.09.1.1235 refused to run after restart. It has successfully run on all other PCs on which it was installed or updated.
     
  12. haakon

    haakon Guest

    How much more obvious can they be? At best, an impasse.

    OK. We get it already. Very unfortunate.

    If you're running the free version you seem to be hosed.

    If Premium you need to get your money back.

    Or just keep trying and post up when you've had success. Please.

    And good luck.

    This is posted up on behalf of banned user DeaDhorsEbeaten. ;)
     
  13. CeeBee

    CeeBee Registered Member

    Joined:
    Nov 20, 2015
    Posts:
    60
    My experience as well. That's all I can say .. as well .. in spite of Support's nixing the SSE issue, sort of. We'll see what happens with the next 1.09 version. :cautious:
     
  14. loungehake

    loungehake Registered Member

    Joined:
    Mar 9, 2015
    Posts:
    201
    Location:
    Wigan
  15. Rules

    Rules Registered Member

    Joined:
    Mar 3, 2009
    Posts:
    704
    Location:
    EU
    @ZeroVulnLabs

    I wonder when the business branch are going to be upgraded to the 1.09 versions, did you know thato_O

    Thank you

    Rules.
     
  16. emmjay

    emmjay Registered Member

    Joined:
    Jan 26, 2010
    Posts:
    1,547
    Location:
    Triassic
    I downloaded MBAE from Bleeping Computer today (listed as freeware), however after it installed it says it is a trial version (2 weeks). I could not find the free version on the Malwarebytes website, just Premium and Trial. So there is no free version, just paid?
     
  17. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,188
    Location:
    The Netherlands
    The trial version is the free version. It asks when installing if you want to activate the premium/trial features. Say no and you have the free version.
     
  18. emmjay

    emmjay Registered Member

    Joined:
    Jan 26, 2010
    Posts:
    1,547
    Location:
    Triassic
    It didn't ask. I'll uninstall and try again.

    Edit: Just uninstalled and reinstalled - was not asked if i want Premium or Trial.
     
    Last edited: Nov 7, 2016
  19. Cache

    Cache Registered Member

    Joined:
    May 20, 2016
    Posts:
    445
    Location:
    Mercia
    I have always used the free version. If you activate the trial, would I be right in thinking that after 14 days it would just revert to the free version?
     
  20. Gandalf_The_Grey

    Gandalf_The_Grey Registered Member

    Joined:
    Jan 31, 2012
    Posts:
    1,188
    Location:
    The Netherlands
    I think that is correct, but I also remember it was asking when installing if you want to use the trial.
     
  21. haakon

    haakon Guest

    After 14 days it reverts to free in functionality but it's status is Trial (Expired).

    I forget exactly but somewhere in the UI is a selection to "deactivate trial" or something of that meaning. It's possible it's in the screen where you'd enter the license itself.

    Sorry, I'm running Free on only one system (Premium on everything else) and it's been a few months since I dealt with that. But it's in there! The UI isn't all that deep.
     
  22. Cache

    Cache Registered Member

    Joined:
    May 20, 2016
    Posts:
    445
    Location:
    Mercia
    Maybe next time I reinstall it, I will activate the trial and find out first hand whaif that's true!
    Thanks guys. I've always declined the trial on the few occasions I've installed MBAE, maybe next time I will give it a go. :)
     
  23. loungehake

    loungehake Registered Member

    Joined:
    Mar 9, 2015
    Posts:
    201
    Location:
    Wigan
    Unannounced by Malwarebytes, the RET ROP Gadget Detection features in OS Bypass Protection can now be checked without any apparent adverse on any of my protected applications on Windows XP SP3 and Windows 7 Ultimate (64-bit).

    I gleefully discovered that I can check every protection feature in MBAE Premium with versions 1.08.1.2572 and 1.09.1.1235 and all protected applications that are installed run just fine. This is some compensation for version 1.09 not being executable on my two pre-SSE2 processor equipped systems.

    Caveat: I imagine that there are applications that will fall foul of such monumentally reckless user behaviour but I am obviously not using any of them.

    On Windows XP SP3, I use Agnitum Outpost Pro Firewall 9.3, Panda Free Antivirus 17.0.1, BufferShield software DEP (by System-Safe), Mozilla Firefox ESR 45.4, Opera 12.17, Outlook Express 6, SumatraPDF 3.1.2, Acrobat Pro 6, MS Office 2003, MBAE 1.08.1.2572

    On Windows 7 Ultimate (64-bit), I use Agnitum Outpost Pro Firewall 9.3, Avast Free 12.3.2280, Google Chrome, Mozilla Firefox ESR 45.4 , Opera 12.17, Thunderbird 45.4, SumatraPDF 3.1.2, OpenOffice 4.1.2, Skype, MBAE 1.09.1.1235
     
  24. haakon

    haakon Guest

    For several months (about July I think) I haven't had any issues with the MBAE experimental/beta/preview 1.0.9 releases or the current .1235 with everything checked under all the tabs in Advanced settings.

    Two Windows 7 x64 systems, two Windows 10 x64, one 1607, the other 1151 > 1607. The latter a test system which was the first to get the experimental/beta/previews before the other three.

    I've got 17 custom shields on one of the three Premium installs, a few less on the other two.

    Except every time I updated I had to go in and re-check all the RET ROPs. Twelve mouse clicks! Every time! :'( :D

    So, after updating go in and check up on your checks.
     
  25. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    A new experimental build, version 1.09.1.1243, has been released...
    Announcement and download link: MBAE 1.09 preview
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.