ZeroVulnerabilityLabs ExploitShield

Discussion in 'other anti-malware software' started by sbwhiteman, Sep 28, 2012.

Thread Status:
Not open for further replies.
  1. DBone

    DBone Registered Member

    Joined:
    Nov 24, 2010
    Posts:
    1,041
    Location:
    SoCal USA
    Thanks for the reply, and I look forward to the new beta release as well as the final. :thumb:
     
  2. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Sorry I missed this.

    I stopped updating it as it was very labour intensive. But you can easily get regularly updated exploit URLs from different sources, such as:

    http://www.malwaredomainlist.com/hostslist/mdl.xml
    http://www.malwareblacklist.com/mbl.xml
    http://malwaredb.malekal.com/export.php?type=url
    http://urlquery.net/rss.php (high volume, search for entries with alerts)
     
  3. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  4. guest

    guest Guest

  5. DBone

    DBone Registered Member

    Joined:
    Nov 24, 2010
    Posts:
    1,041
    Location:
    SoCal USA
  6. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Hmmmm.... probably missing the Visual C++ 2010 Redistributable. Do you have it installed?
     
  7. DBone

    DBone Registered Member

    Joined:
    Nov 24, 2010
    Posts:
    1,041
    Location:
    SoCal USA
    Negative, not installed.
     
  8. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    That's probably the problem. But it should have given the same error when installing 0.7.
     
  9. DBone

    DBone Registered Member

    Joined:
    Nov 24, 2010
    Posts:
    1,041
    Location:
    SoCal USA
    No, I never received the error in 0.7
     
  10. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    I get the same error on a Win 8 Pro 64 bit machine but ES goes ahead and installs. I have the x86 version of C++ installed. I notice on Win * x64 that when you start IE10, the parent process is 64 bit and then all the child processes it launches are 32 bit. The ES dll injects itself into the 64 bit parent but none of the 32 bit IE10 child processes have the ES dll injected. Is the correct operation?

    Also on the C++, I did not install the x86 version, it is just already on my machine also. Is there and should I also have a 64 bit version of C++ installed?
     
  11. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    I also noticed that in order to get the ES dll injected into all IE10 instances, first I must have ES running, start IE10, and then go to the ES GUI and stop protection and then restart it again. This is the only way that I can have the ES dll injected into all IE10 instances.
     
  12. guest

    guest Guest

    False Positive;
    When open pdf files on Firefox with Sumatra PDF integrated
     
  13. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,871
    Location:
    New York City
    No internet connection when installed.
    Windows 7, 32 bit
    IE 9
     
  14. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,237
    Location:
    USA
    .8 installed cleanly over the top of .7 (Win7x64) - color me lucky :) I often had the disappearing icon issue with .7 so I'll be watching for that over the next few reboots and Hibernation cycles. .8 looks pretty much the same as .7, so I guess all the good stuff happened under the hood. Will there be skin support? (just kidding!) :D
     
  15. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    500
    Location:
    italy
    the same for me
    i can not confirm this behaviour,

    Immagine 3.jpg

    Immagine 4.jpg
     
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    We'll have to take a closer look at the installation dependencies. Thanks for reporting.

    @guest, in regards to Sumatra PDF we'll try to replicate it here. Thanks.

    @Thankful, what do you mean with "No Internet connection when installed"? Do you mean it breaks your connection??

    @puff-m-d the injection should happen automatically to all IE child processes as @test shows. We will try it out here in some machines to see if we can replicate.
     
  17. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,871
    Location:
    New York City
    @ ZeroVulnLabs
    Yes. It breaks my internet connection.
     
  18. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Can you provide more information? What do you mean, your browser cannot connect to websites, your cable/wifi connection is completely down, your network adapter dissapears, ....?
     
  19. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,871
    Location:
    New York City
    My browser cannot connect to websites. Same thing happened with previous version.
     
  20. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Do you have some other HIPS installed like Comodo or something like similar that might be blocking the injection into the browser? If so check your other security products to make sure they are not interfering with ExploitShield.
     
  21. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,167
    Location:
    UK / Pakistan
  22. BrandiCandi

    BrandiCandi Guest

    Right, but it doesn't really protect the browser. It protects against drive-by exploits. There's no protection against cross site scripting, redirects, malware installed via downloading files from the browser, etc. etc.

    That's why I say it's a bit misleading. It doesn't protect the browser, not by a long shot. It protects against drive-bys. If it were my product I would call the free version "ExploitShield Drive-By Version."
     
  23. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    We detected a small bug and have uploaded version 0.8.1.

    If you have 0.8 installed please download and install the new 0.8.1.
     
  24. sevenstar

    sevenstar Registered Member

    Joined:
    Oct 19, 2010
    Posts:
    54
    I've downloaded the latest beta (0.8.1) and installed over the previous one. I've started both IE8 and Firefox. Exploitshield shows that both browsers are protected. If I close both browsers, the shielded applications shows -2. When I reopen both browsers, the shielded applications number shows zero.
    Foxit, Microsoft Word, and Excel don't appear to be protected when they are opened.
    Allen
    :oops:
     
  25. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    If desired, how do you uninstall ExploitShield?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.