Author Topic: Can ExploitShield browser version be used next to avast resident av?  (Read 66520 times)

0 Members and 1 Guest are viewing this topic.

ZeroVulnLabs

  • Guest
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #105 on: December 04, 2012, 04:12:11 AM »
I have microsoft EMET installed alongside avast,would i be able to run exploitshield alongside these
Yes you can run ExploitShield and EMET at the same time. In fact we recommend this as it increases very much your level of protection. As both EMET and ExploitShield use totally different anti-exploit techniques, having both installed provides an excellent coverage against exploits.

ZeroVulnLabs

  • Guest
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #106 on: December 04, 2012, 04:14:03 AM »
The crash of Exploit Shield was for the browser used.
We are preparing a special version with verbose logging to find out the source of potential bugs or problems. If you would like to test this I can send it to you once it is ready so that you may try to reproduce it and then see the source of the problem in the verbose logs. Just let me know if you can test this in a couple of weeks and I'll send you a PM once its ready.

Arnold72

  • Guest
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #107 on: December 04, 2012, 07:54:40 PM »
Is there a way of adding programs to be shielded manually in the free browser edition?

ZeroVulnLabs

  • Guest
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #108 on: December 05, 2012, 01:36:41 PM »
Not yet, but it's something we want to include in the future.

Arnold72

  • Guest
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #109 on: December 05, 2012, 08:27:33 PM »
Thanks.
I tried the browser version of exploitshield yesterday and unfortunately it does not in its present form protect any programs that i have installed.
If i can add programs manually then i will certainly give it another go.
Best of luck to you with this interesting program. 8)

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #110 on: January 14, 2013, 10:05:52 PM »
To those that use and test of ExploidShield 0.8.1 beta next to their resident avast av solution,

Just to revive this thread after using the beta now for quite some time and it closed down just only once in all that time. I could restart it easily. I gave the Exploit Shield executable a run of a nice exploration tool called exeinfoPE power pack and got back some interesting results (to whom it may concern). ExeinfoPE is a great tool for  packer determination.
For ExploitShield executable we get EntryPoint 0011C50 oo File Offset 00011050 File Size etc. But interesting is Overlay 000024D8 encoding 0x000024D8 (24d8)
Unpack info try :
   Protection_ID.exe  from http://pid.gamecopyworld.com , true ep
-only and signature patterm 8B FF 55 8B EC is for Visual C++ 2003 DLL -> Microsoft  UPolyX v.0.5 gives ???? so cannot be established but as false
Also interesting would be to perform a walk with dependency walker as seen from the signature pattern we land here: http://www.nirsoft.net/articles/windows_7_kernel_architecture_changes.html (article and info from Nir Sofer, an exellent developer with a list of very helpful tools: hxtp://www.softpedia.com/developer/Nir-Sofer-10197.html) and we see that the executable is all about kernel protection.
Thanks also for !Donovan for inspiring me to test out the ExeinfoPE_PowerPack tool as we both rather like the interesting  interface of it.
This while we went over some ins and outs of packer detection....

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #111 on: January 19, 2013, 11:27:16 PM »
ExploitShield browser actually prevented javaw.exe from executing through java. Clicked on a file in browser file location ssecurity.java and ExploitShield prevented javaw, with which there exists no associated console. The window isn't necessarily created (for example, when you run from an existing console window or completely in background). If this had been a zero-day it would have been blocked by ExploitShield 0.8.1.......

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

ZeroVulnLabs

  • Guest
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #112 on: January 19, 2013, 11:37:21 PM »
Yes, ExploitShield blocks all recent Java zero-days.

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #113 on: January 29, 2013, 05:44:20 PM »
Hi users of ExploitShield 0.8.1 next to avast resident av solution,

ExploitShield blocks an attempt to scan for UPnP-hole with this tool, that is stopped in it's tracks: http://www.rapid7.com/resources/free-security-software-downloads/universal-plug-and-play-jan-2013.jsp (seen in the logs swt-win-3740.dll blocked from executing through java and swt-win-3740.dll sent to Exploit Shield's quarantine folder)...ExploitShield protects against  UPnP-hole exploits. Just wanted to let u know...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #114 on: June 20, 2013, 12:41:01 PM »
Hi folks,

News from Exploit Shield.
Quote
ZeroVulnerabilityLabs and ExploitShield
are now part of the Malwarebytes
family and will be known as
Malwarebytes Anti-Exploit.

It seems it is no fud and snake-oil as ithas now been acquired and  incorporated by MBAM.
The new beta can be downloaded here: http://downloads.malwarebytes.org/file/mbae_beta

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #115 on: June 20, 2013, 12:48:09 PM »
Quite interesting. Thanks Pol.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #116 on: June 20, 2013, 12:49:54 PM »
Hi folks,

News from Exploit Shield.
Quote
ZeroVulnerabilityLabs and ExploitShield
are now part of the Malwarebytes
family and will be known as
Malwarebytes Anti-Exploit.

It seems it is no fud and snake-oil as ithas now been acquired and  incorporated by MBAM.
The new beta can be downloaded here: http://downloads.malwarebytes.org/file/mbae_beta

polonus

Polonus is Malwarebytes Anti-Exploit going to be free when it become a final release ???
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip

Offline CraigB

  • Avast Überevangelist
  • Serious Graphoman
  • *****
  • Posts: 11239
  • No support PM's thanks
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #117 on: June 20, 2013, 01:01:38 PM »
Polonus is there a link to some information about it, I cant find anything about it at Malwarebytes.

Online polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline CraigB

  • Avast Überevangelist
  • Serious Graphoman
  • *****
  • Posts: 11239
  • No support PM's thanks
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #119 on: June 20, 2013, 01:33:23 PM »
Thanks Damian, I eventually found the info at the Malwarebytes press room http://press.malwarebytes.org/2013/06/20/malwarebytes-completes-acquisition-of-zerovulnerabilitylabs/ I'm wondering if this technology will be incorporated into MBAM Pro ???