Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    Yes we will add more applications once we are out of the woods with the engine development. There's still a few more stage1 mitigation techniques to add and the Windows Service component and then we'll be in a better position to increase coverage to other apps.
     
  2. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    Is it going to be free or paid product?
    Any plans for integration in MBAM?
     
  3. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
  4. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    "error installing malwarebytes anti-exploit driver, the Malwarebytes anti-exploit process will be terminated."

    this error msg occurs after i press finish on the installation wizard.

    Running Outpost 8.1 firewall and kaspersky IS 2012.
    Win XP Pro SP3.

    I have added the install file and the directory where mbae is installed into kasperksy trusted applications. Also outpost is on auto learn rules and i edited the install file behaviour to "allow all activity"

    using version 0.09.4.2000

    Is the older 1000 version available to try?
     
    Last edited: Nov 24, 2013
  5. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    This is probably due to an incomplete or corrupt uninstall of a previous version.

    Please do the following:
    1- Close all shielded apps
    2- Uninstall from Control Panel if not yet done
    3- Reboot
    4- Delete HKLM\SYSTEM\Services\ESProtectionDriver
    5- Reboot
    6- Download and install again.
     
  6. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    Re: Malwarebytes Anti-Exploit 0.09.4.1000


    BTW there is no services under system in xp pro.

    I searched for esprotectondriver but it never arose in regedit.

    I did install again for interest and the same problem in that it immediately exits.


    thanks
    Martin
     
  7. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    Sorry, should be:
    HKLM\SYSTEM\CurrentControlSet\Services\ESProtectionDriver
     
  8. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    checked at the new registry location and nothing is present
     
  9. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    Completely uninstalled outpost 8.1.2 and MBAE is now working.

    I will see if i can get Outpost to work with MBAE.
     
  10. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    Interesting. Please do report your findings so that we may notify other users of Outpost and MBAE in the known issues and compatibility list:
    https://forums.malwarebytes.org/index.php?showtopic=135127
     
  11. chrome_sturmen

    chrome_sturmen Registered Member

    Joined:
    Apr 29, 2006
    Posts:
    875
    Location:
    Sverige
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    i'm running outpost 8.1.2 as well, and mwbae installed and is running fine, for a couple days now.

    is this program somewhat like a "run safer" or suchlike?
     
  12. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  13. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
  14. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    Re: Malwarebytes Anti-Exploit 0.09.4.1000


    What OS are you running?
     
  15. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    So, we ever find out how MBAE does its hooking? Or what it actually looks at to detect attacks?
     
  16. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    @Hungry Man: Just read your original enquiry, just two days ago. Like you I'm also interested in the details. Perhaps giving more details would be the downfall for the product? :p
     
  17. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    When I get told that being open would help attackers, I usually assume this. That goes double when 'intellectual property' gets used.

    This summer I've been hired to do basically nothing but reverse engineer and exploit software, so hopefully they've got something before then, because I'll be having a look and I'd love it if they saved me the trouble :)
     
  18. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    Ok finally got around to installing outpost again.

    MBAE seemed to interfere with installation as a driver could not be installed.
    Outpost v7.6.1 reported it was running in limited mode on reboot.

    I killed MBAE in task manager and it installed fine.
    It is however the older version of outpost 7.6.1 as i prefer its interface to 8.x
     
  19. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    Any idea where I can get Outpost v7.6.1 from to try to replicate this?
     
  20. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    1,938
    Location:
    North of the 38th parallel.
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    <http://www.agnitum.com/support/kb/article.php?id=1000290>

    Hi Pedro:

    I hope the above might be of some help.
     
  21. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    Outpost do keep an archive of all their versions at least back to 7.5

    Oh its 7.6 not 7.6.1 (which doesnt exist)
    sorry.

    So far things are co-operating fine including hitmanpro alert with mbae
     
  22. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    Thanks to both, I'll check it out!
     
  23. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    Just noticed MBAE blocked VLC from updating itself.
     
  24. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    Known Issue #8:
    https://forums.malwarebytes.org/index.php?showtopic=135127

    As a workaround simply exclude the VLC upgrade block event in the MBAE GUI-Log tab and then allow VLC to upgrade itself again.
     
  25. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
    Re: Malwarebytes Anti-Exploit 0.09.4.1000

    I have just found a problem when running Microsoft Update (Internet Explorer 8, Windows XP 32 Pro SP3).

    When selecting "search for new updates" the page just keeps on showing a running progress bar and nothing happens. A svchost.exe process that uses 25% of my Q6600 quadcore pops up on Windows Task Manager. This is not usual when I run Microsoft Update.

    The issue disappears by stopping MBAE protection. It could be a clash with some of the other security software that I have installed, see my sig for details.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.