ZeroVulnerabilityLabs ExploitShield

Discussion in 'other anti-malware software' started by sbwhiteman, Sep 28, 2012.

Thread Status:
Not open for further replies.
  1. guest

    guest Guest

    From trusteer rapport

     
  2. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Thanks for the confirmation!
     
  3. guest

    guest Guest

    I think that the combination of ExploitShield and Trusteer Rapport for browser protection is the best available, and both are free. I just need to confirm the compatibility of EMET with TR to add it to my config.
     
  4. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
    Yes they have been fully compatible for me since a month now, as I posted back then. I check Firefox and Chrome daily and IE8 from time to time. Both ES and TR inject their DLLs without an issue.
     
  5. Trespasser

    Trespasser Registered Member

    Joined:
    Mar 1, 2005
    Posts:
    1,204
    Location:
    Virginia - Appalachian Mtns
    Hi,
    At present I'm running Win 8 Pro 64 bit with Sandboxie 4.01.04 64 bit, ExploitShield 0.9.1 beta, and Software Restriction Policy. I've also added Dr. Pepper's two Sandboxie tweaks ($:ExploitShield64.exe, and *\BaseNamedObjects*\ZVL_IPC_Channel*) to Firefox's configuration. The problem is that in ExploitShield's log nothing is showing up and Shielded applications: 0 while Firefox is sandboxed. If I run Firefox outside Sandboxie then Firefox shows up in the log and Shielded applications: 1. There must be something else missing from the Firefox-Sandboxie configuration that prevents it from working correctly.

    Does anyone have any suggestions?

    Thank you.

    Later...

    Bob
     
  6. Skiaz

    Skiaz Registered Member

    Joined:
    May 28, 2010
    Posts:
    10
    Location:
    USA
    Been awfully quiet in here lately....I am not sure if it was deliberate or not but the windows media player issue seems to have vanished with 0.9.1. I have verified this on both of the computers that had issues previously with earlier versions or ExploitShield. Nice work! :D
     
  7. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    With 0.9.1 we added some new optimized detection logic which as a side benefit fixes some of these bugs. But its good to know that this one in particular is fixed. We will delete it from the "known issues" list. Thanks for confirming!
     
  8. kupo

    kupo Registered Member

    Joined:
    Jan 25, 2011
    Posts:
    1,121
    Hello, will you add an option to manually add shields in application in the free edition or will it only be available in the enterprise edition?
     
  9. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Yes, that's in the backlog. Right now we are working on exclusions to have an option to manage FPs. Here's a sneak peak of what it will look like:


    Screen 1: Ability to exclude from the LOG of blocked payloads.
    ScreenShot00299.png

    Screen 2: New Exclusions tab where you can also manually add to the list.
    ScreenShot00300.png
     
  10. kupo

    kupo Registered Member

    Joined:
    Jan 25, 2011
    Posts:
    1,121
    Hello, I installed latest version. I noticed that if after boot and you open Firefox (right after the system boots) it won't be shielded by ExploitShield. I also noticed that there is some kinda "loading time" for ExploitShield when starting up. (If you right click at the tray icon right after boot, it won't do anything, however my other system tray icon works)
     
  11. kupo

    kupo Registered Member

    Joined:
    Jan 25, 2011
    Posts:
    1,121
    Possible false positive report.
    1. Using Firefox go to this site (RebootRestoreRx) -http://www.horizondatasys.com/en/products_and_solutions.aspx?ProductId=18

    2. Download it, (ExploitShield triggers)
     
  12. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    What does it say in the log window?
     
  13. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    Web Browser Opera.
    Download file no problem
    0 pop-up ES.
     
  14. kupo

    kupo Registered Member

    Joined:
    Jan 25, 2011
    Posts:
    1,121
    Here is the log window.
    Capture.JPG
     
  15. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    I see. This is a known bug we've been fixing lately. We'll release a new version soon fix a fix for this and some other things.
     
  16. kupo

    kupo Registered Member

    Joined:
    Jan 25, 2011
    Posts:
    1,121
    Hello, I would just like to inform you that all downloads in Firefox are being counted as an exploit. :D. Hope to test the new version soon.
     
  17. kupo

    kupo Registered Member

    Joined:
    Jan 25, 2011
    Posts:
    1,121
    UPDATE: It is not a bug within ExploitShield, upon further testing, it seems to be a conflict when Firefox is guarded with AppGuard (lockdown).
    Doesn't happen when in "High" mode though.
     
  18. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Does it help to add ExploitShield to Power Apps? You could keep using 'lockdown'-mode if that works. :)
     
  19. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
  20. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,171
    Location:
    Canada
    Do we install over top of old version?
     
  21. 1000db

    1000db Registered Member

    Joined:
    Jan 9, 2009
    Posts:
    718
    Location:
    Missouri
    No don't do it...just uninstall the previous version first.
     
  22. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    Just tried to remove the old version before I install the Malwarebytes version...oops.

    ScreenShot_ZeroVulnerabilityLabs_uninstall_04.gif
     
  23. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,171
    Location:
    Canada
    Same thing happened to me, don't know what uninstall manually means. Delete folder or go into registry and start hacking away. I know when I tried to uninstall it got rid of maybe half of the files in the folder, had a hard time deleting the rest, had to do it in safe mode. Funny thing is after it tried to uninstall the program was still there on my task bar and still opened the gui. Gort rid of everything eventually but took awhile. Since then I've read you do not have to uninstall old version. Somebody correct me if I'm wrong.
     
  24. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    These problems are due to an incomplete uninstall of the previous version, probably because the DLL was still injected into some shielded process.

    Follow these instructions if you're upgrading from a ZVL ExploitShield:
    1- Close all shielded applications (browsers, etc.)
    2- Right-click on the traybar icon and choose Exit
    3- From Control Panel, Add/Remove Programs, uninstall ExploitShield
    4- Download and install the latest version.
     
  25. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    Further to my post above, the program is no longer installed but as per the following screenshots uninstaller.exe was launched and a subkey was deleted.

    ScreenShot_ZeroVulnerabilityLabs_uninstall_05.gif

    after which the C:\Program Files\ZeroVulnerabilityLabs\ExploitShield still remained, but I have deleted the folder, manually.

    ScreenShot_ZeroVulnerabilityLabs_uninstall_06.gif

    Also, these two system32 dll's have also have been deleted.

    *****************************
    COMPARING RECORDS FROM SYSTEM
    *****************************
    -----------------------------
    These files were present at:
    22 Jun 13 at 17:12:10
    but not on:
    18 Jun 13 at 18:57:56
    -----------------------------
    -----------------------------
    These files were present at:
    18 Jun 13 at 18:57:56
    but not on:
    22 Jun 13 at 17:12:10
    -----------------------------
    msvcp100d.dll
    msvcr100d.dll
    -----------------------------
    *****************************



    C:\WINDOWS\system32\msvcp100d.dll
    C:\WINDOWS\system32\msvcr100d.dll
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.