Smart Object Blocker (Block EXE, DLL, Drivers)

Discussion in 'other anti-malware software' started by novirusthanks, Jul 29, 2015.

  1. constantine76

    constantine76 Registered Member

    Joined:
    Dec 18, 2010
    Posts:
    191
    Any news (next release)?
     
  2. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    Should be released soon, can't say an exact date for now.

    Nope, it's a direct memory write and not a DLL on disk. Windows stores no file information on it (no name etc).
    Microsoft's definition of DLL injection is what we block, the file must be on disk for LoadLibrary variants to load it.
    Trying to detect executable memory access that we'd label malicious would be a nightmare full of false positives.
     
  3. Okay,

    Always good to stick your stronghold

    Thx
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    When will you implement a user friendly GUI? I would love to be able to block DLL injection and driver loading, but then with an alert window like in ERP.
     
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Well, it can be done. Eset's HIPS process modification function for example monitors these API calls:

    VirtualAllocEx/VirtualFreeEx
    WriteProcessMemory
    CreateRemoteThread
     
  6. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Count EASTER in on the GUI support feature. An alert function like in ERP would be the visual icing on the cake IMO.
     
  7. guest

    guest Guest

    SoB definitely needs a Gui , it is too boring to type rules especially if you have many softs...
     
  8. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    Yup, I'm stuck with it, the lack of a nice GUI is painful lol
    Same goes to SOB's rival: Bouncer.

    Moreover, I want to see ERP to evolve or rest peacefully once and for all and SOB to shine with a nice GUI if it's going to be an ERP on steroids.

    I'm with @guest : no GUI = boring and frustrating to configure.
     
  9. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes exactly, and we all know that Andreas has the skills to do it, ERP is one of the best apps ever.
     
  10. guest

    guest Guest

    no , we just need buy him large amount of coffee , he shouldn't be allowed to sleep until we have a GUI ! :p


    i totally agree.
     
  11. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    I'm in. You are receiving all this right Andreas? :rolleyes:
     
  12. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I agree, you can also count me in. :D
     
  13. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Wow it's got kind of quiet in here after that suggestion :oops:
     
  14. guest

    guest Guest

    *

    yep it was the "killing demand" :p
     
  15. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @EASTER

    Even if I am quiet I always read the posts :)

    We'll think about the GUI, before that we want to release the new build that has many fixes and improvements.

    We are busy with few internal projects, will be more active very soon :)
     
    Last edited: Nov 23, 2015
  16. Andreas,

    Could you share some information about the improvements ?

    regards Kees
     
  17. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    Sure, here it is:

    The remained bug to fix is the blocking of DLLs that are loaded by protected processes in Windows 8+ OS.
     
  18. guest

    guest Guest

    i think what is crucial right now, if not a real GUI , in the meanwhile is at least a popup alert that create rules.
     
  19. Okay, thanks
    Thanks for the info. Because protected objects are protected by internal mechanisms of the OS, it will be harder to tackle than the others. May be an idea to release a version with other improvements so Wilders folks can test it?
     
  20. solhuebner

    solhuebner Registered Member

    Joined:
    Oct 9, 2013
    Posts:
    7
    Location:
    Malta
    Why is this in the Exclude\Lockdown\Process.DB?

    [%PROCESSCMDLINE%: *rundll32*Shell32.dll*Control_RunDLL*\*.exe*]
    [%PROCESSCMDLINE%: *rundll32*javascript:*]
    [%PROCESSCMDLINE%: *rundll32*;*eval*(*]
    [%PROCESSCMDLINE%: *vssadmin*Delete*Shadows*/All*/Quiet*]
    [%PROCESSCMDLINE%: *bcdedit*/set*recoveryenabled* No*]
    [%PROCESSCMDLINE%: *bcdedit*/set*bootstatuspolicy*ignoreallfailures*]
    [%PROCESSCMDLINE%: *bcdedit*-set*loadoptions*DDISABLE_INTEGRITY_CHECKS*]
    [%PROCESSCMDLINE%: *bcdedit*/deletevalue*safeboot*/set*safebootalternateshell*false*]

    This does not make sense or?

    As the same are under Block\Process.DB
    //Block command-line strings used by Cryptolocker family
     
  21. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @solhuebner

    Lockdown mode means "allow any process that matches the rules", so in the exceptions I added to not-allow that bad command-lines, this because if the user allows "C:\WINDOWS\*" then that commandlines would be allowed.
     
  22. solhuebner

    solhuebner Registered Member

    Joined:
    Oct 9, 2013
    Posts:
    7
    Location:
    Malta
    Yeah that makes perfect sense :)

    Only one minor thing. I use a dual screen setup with the second screen above the first one. When I start your great program it always center in the middle of the two screens so that half the program is on one screen and the other half on the other one. Can you maybe just center it on one screen or remember the position from last time? Your program is very cool! Keep up the great work. And sorry for my question. After re-reading the manual it makes perfect sense...
     
  23. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    No problem, you're welcome ;)

    I'll check the dual-monitor issue.
     
  24. solhuebner

    solhuebner Registered Member

    Joined:
    Oct 9, 2013
    Posts:
    7
    Location:
    Malta
    If it blocks something like this:

    [29-Nov-15 10:27:56] Blocked Process: C:\Windows\splwow64.exe
    Rule: [%PARENTPROCESS%: *\firefox.exe]
    Command Line: C:\WINDOWS\splwow64.exe 8192
    Process Id: 8788
    Parent Process Id: 4888
    Parent Process: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    it would be nice if you could add a line how to whitelist this specific blocked action :)

    Kind regards
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.