Author Topic: Can ExploitShield browser version be used next to avast resident av?  (Read 66451 times)

0 Members and 1 Guest are viewing this topic.

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7170
  • When you think you know, Think Again
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #15 on: October 02, 2012, 05:33:51 PM »
@Polonus, thank you very much for the information you have added.
I appreciate that :)

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7170
  • When you think you know, Think Again
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #17 on: October 02, 2012, 07:08:46 PM »
Interestingly, I am experiencing a lot more BS reaction (set to Ask) since ExploitShield has been installed. ???
And thats OK, it just interesting to see the BS so active when previously performing the same tasks, I hardly had any pop-ups from BS.  8)

For example:
« Last Edit: October 02, 2012, 07:14:45 PM by schmidthouse »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #18 on: October 02, 2012, 07:40:50 PM »
Hi schmidthouse,

Yes, the last bs alert was when I opened Resource Hacker. Seems that Z is somehow enhancing or hardening.
From the logfile:
ZeroVulnerabilityLabs Loader <<INFO>> Argument
2012-10-02 10:46:23   C:\Program Files\ZeroVulnerabilityLabs\ExploitShield\ExploitShield.exe
2012-10-02 10:46:23   ZeroVulnerabilityLabs Loader <<INFO>> return TRUE  (being evaluated http://systemexplorer.net/file-database/file/loader64-exe )
2012-10-02 10:46:24   ZeroVulnerabilityLabs ExploitShield <<INFO>> Checking OS .....
2012-10-02 10:46:25   ZeroVulnerabilityLabs ExploitShield <<INFO>> Windows XXXX
2012-10-02 10:46:25   ZeroVulnerabilityLabs ExploitShield <<INFO>> Standard xxx Edition
2012-10-02 10:46:26    ExploitShield Driver is already Installed
2012-10-02 10:46:26   ZeroVulnerabilityLabs ExploitShield <<INFO>> Checking OS .....
2012-10-02 10:46:27   ZeroVulnerabilityLabs ExploitShield <<INFO>> Windows XXXXX
2012-10-02 10:46:27   ZeroVulnerabilityLabs ExploitShield <<INFO>> Standard xxx Edition
2012-10-02 10:46:31    Starting Injection with: ExploitShield.dll
2012-10-02 10:46:31   C:\Program Files\ZeroVulnerabilityLabs\ExploitShield\ExploitShield.dll
2012-10-02 11:06:07   ZeroVulnerabilityLabs ExploitShield <<INFO>> Checking OS .....
2012-10-02 11:06:07   ZeroVulnerabilityLabs ExploitShield <<INFO>> Windows XXXXXXX
2012-10-02 11:06:07   ZeroVulnerabilityLabs ExploitShield <<INFO>> Standard xXX Edition
2012-10-02 11:06:11   Google Chrome is now protected......

Interesting blog read: http://www.zerovulnerabilitylabs.com/home/blog/page/2/
See what was found in log data.dat....

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7170
  • When you think you know, Think Again
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #19 on: October 02, 2012, 07:47:28 PM »
Hi schmidthouse,

Yes, the last bs alert was when I opened Resource Hacker. Seems that Z is somehow enhancing or hardening.
From the logfile:
ZeroVulnerabilityLabs Loader <<INFO>> Argument
2012-10-02 10:46:23   C:\Program Files\ZeroVulnerabilityLabs\ExploitShield\ExploitShield.exe
2012-10-02 10:46:23   ZeroVulnerabilityLabs Loader <<INFO>> return TRUE  (being evaluated http://systemexplorer.net/file-database/file/loader64-exe )
2012-10-02 10:46:24   ZeroVulnerabilityLabs ExploitShield <<INFO>> Checking OS .....
2012-10-02 10:46:25   ZeroVulnerabilityLabs ExploitShield <<INFO>> Windows XXXX
2012-10-02 10:46:25   ZeroVulnerabilityLabs ExploitShield <<INFO>> Standard xxx Edition
2012-10-02 10:46:26    ExploitShield Driver is already Installed
2012-10-02 10:46:26   ZeroVulnerabilityLabs ExploitShield <<INFO>> Checking OS .....
2012-10-02 10:46:27   ZeroVulnerabilityLabs ExploitShield <<INFO>> Windows XXXXX
2012-10-02 10:46:27   ZeroVulnerabilityLabs ExploitShield <<INFO>> Standard xxx Edition
2012-10-02 10:46:31    Starting Injection with: ExploitShield.dll
2012-10-02 10:46:31   C:\Program Files\ZeroVulnerabilityLabs\ExploitShield\ExploitShield.dll
2012-10-02 11:06:07   ZeroVulnerabilityLabs ExploitShield <<INFO>> Checking OS .....
2012-10-02 11:06:07   ZeroVulnerabilityLabs ExploitShield <<INFO>> Windows XXXXXXX
2012-10-02 11:06:07   ZeroVulnerabilityLabs ExploitShield <<INFO>> Standard xXX Edition
2012-10-02 11:06:11   Google Chrome is now protected......

Interesting blog read: http://www.zerovulnerabilitylabs.com/home/blog/page/2/
See what was found in log data.dat....

polonus

"Seems that Z is somehow enhancing or hardening."

Exactly what I assumed. "somehow" is the interesting addition:> :D

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #20 on: October 04, 2012, 10:02:20 AM »
What I found strange was the contents of the config.dat file, see attached image.
Worked the Chinese txt found there through Google translate and it is just a Chinese poetical txt about a first annual festivity !?!
Or just an unicode misrepresentation of the code...
What is this?
Quote
㜉 Კ 5 븯 knock, Ji-silver carp , Yang Da first birthday of a child ำ Nou ᝟ tools Ping ꚗ SHYE Hui ᨢ ꈕ  䔀 ⯪ Biao  촙 㰭  ጒ Ben 䌡 돗 h. 鿹 every ᚡ ᭫ 궭 Jiu 㔆 㽴 Cheng 떥 ἖ ∓ 뒠 zero Chan 뾳 music ㏄ ┼ 벹 ᗹ public bathhouse Yang??? Wei 꺖??? 컶 䦠 䄼 ꥼ ⡰ 䂛 읤  䘱  䡒 㯻 ঐ heave 쵈뎳 ϋ 퇋   꺈?????? 텫 Ming 䠞 ⾠ ൱ Lou  not Ⱌ ꃃ  ベtree knot 쨓 ع 곒   묙쵵  Yin 외  넍 ⷌ Tan E ± 첂 TSZ MUI 뒷꾊 ꮵ ᄫ 㓛 걭 㼢 ꉈ ꣪??? ዦ ㅠ Jie Bing 퉯 Kechuanxunzang Wu Inspectors 쟜 퐘뱏 ݨ chromium Vitex ⇓ Kazuhiko ditch ⺽ ꮲ 꼏 the [ 먍 늾뻈??? the ᦜ sound of water 㗞 Tao zinc 멒 dawn ꗄ 뜤  ь 왺 ꖽ 뙁 ㎱??? 솮 સ 㧙   ㏓ ممي Lu Zan Peng 됢틱 Tian 핔휔 Di 쵐 decrease Wei Jie ஐ mystery Dai Mo 䴳  ᫳ ȍ 띞 bamboo with thin wide leaves 䶤 㠧 traduce Qi Zhu thulium 㼜 meet unexpectedly 솈뿄 boron ் Wo 쑼푑 door of an inner 엙 Sensing 턃 for Previous ో lin 䯡 Intellect 댷 platinum 듐 stern ⃼ Wei ࣌  돾 silver carp 䢅  䦘 䁣 servant 䲓 Ṿ ❗ DetailsStyleArtist ꇧ Nie 䝊 salt shy ᩯ ꪆ  ॿ 㜼  촲 Alex ⟗ 럴 ꪚ etc. etc. 䲏 䎃    
Sys file certification through Issuer: DigiCert High Assurance CA-3, www.digicert.com, DigiCert Inc, US

polonus
« Last Edit: October 04, 2012, 03:17:33 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #21 on: October 04, 2012, 02:04:11 PM »
Well analyzed the loader executable (loader is the full version actually) of this stand-alone application written in Borland Delphi. SetProcessDEPPolicy is being checked against default winlogon, ScDebugPrivilegeWins and v.c tools site.exe, also the ative startup.state is being ascertained and Unknown Runtime check agains stack corruptions. Local writes are found up before being initialized, loss of data ascertained with Data Wsprint, SQuery User token and Output Debug Strings. It gets the Current Process checks Xpt Filter and looks for locks and unlocks with Debugscr. Use of API-hooks are disallowed to enhanced security..
See additional info here: https://www.virustotal.com/file/93b91c37f042f6a1c4a33929e804a0fdb9dfb04b4fafc042f2848453fe92ce60/analysis/1349350811/
and the analysis here: http://anubis.iseclab.org/?action=result&task_id=13fc8b69a988273c4417c8923d685549c&format=html
This last analysis gives Description Times Exception 0xc0000135 at 0x7c96478e 1. Sometimes is used for Anti-Anubis, it was found ON The crypter and the stub. OWNZ crypter being used. But the issue here is that the separate DLL was not found. https://www.virustotal.com/file/5c7114aa44eaa3295208fb86dfa6106722f7936d2ba92ee19a4cb15d4f9a0052/analysis/
But clamav gives a PUP warning for the dll..-> .http://anubis.iseclab.org/?action=result&task_id=14be0edbecfad675469658e01f0ea17bb&format=html
Aimbot like tmp code -> .regsvr32.exe /c /s .\d1.tmp.dll found terminate the d2 process whenever they like it...spyware like code as
Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\​comctl32.dll, reads the shell folderts to the defaults.
Settings in a device control preset are used during logging, capturing, and output. Device\KsecDD 0x00390008 8 - Memory Mapped Files..
Observations given for what they are worth....later will give some additional binairy.txt viewer conclusions...

polonus
« Last Edit: October 04, 2012, 03:20:06 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48552
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #22 on: October 04, 2012, 03:56:30 PM »
Damien,
Can you also explain this in a less technical term for those of us that are not as well versed with code as you but,
are still interested in following your dissection of this new tool ???
Thanks
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline SpeedyPC

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3398
  • Avast shall conquer the whole world
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #23 on: October 04, 2012, 05:08:39 PM »
Damien,
Can you also explain this in a less technical term for those of us that are not as well versed with code as you but,
are still interested in following your dissection of this new tool ???
Thanks

+1 We aren't computer wizard or a real nerd ;) ;D
Gigabyte 670 LGA1200 Full ATX MB | Intel Core i9-13900 CPU/LGA 1700 | GeForce Nvidia RTX-4070/12GB | 32GB DDR4 | 2 x 1TB Samsung SSD | W11 Home 64bit | Avast Premium v24.3.6108 | Avast SecureLine VPN | Avast Secure Browser | Avast Driver Updater | Avast BreachGuard | Firefox 64bit | MalwareBytes Premium | Adguard Premium | CCleaner Portable | Macrium Reflect | 7-Zip

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #24 on: October 04, 2012, 05:36:03 PM »
Hi bob3160,

Well the clever thing is that the sofware consists of three separate parts in the software folder and is a stand-alone application protection tool for certain third party software applications that could be vulberable to zero day exploits. The three parts are the shield executable, a separate shield dll and the loader executable. The one does not work without the other, so advanced security achieved there. Api's are denied to run for security reasons. The processes that are being protected are constantly being monitored by the software against security breaches deep inside the OS on a kernel level, constantly being checked against the default situation. So when the malcode attempts to perform anything that seems specific performance of 0-day malcode,  the ExploitShield software turns red for an alert, blocks and saves logs. Some protection gets locked as it is being protected when active, meaning when process is active.  Adobe Reader is being protected, Foxit Reader, Microsoft Office Application, Windows Media Player, also VLC player, Winamp and QuickTime Player, Java, GoogleChrome, Firefox and Safari browsers and off course IE. The software is MS certified. When malware tries to write onto the computer without being initialezed by user intervention (typical gor malware performance) it is found up by the shield tool. Crypting and debugging is going on all of the time. It sits silently on the taskbar, a bit like you experienced with RUBotted. So all is contantly compared to a default situation and if not so alarm bells should ring. In my actual section on the computer 130 applications are being shielded. To early days to give a final verdict, but what I have seen is encouracing to try it out. Keep you all informed. You will sure like it.

Damian


« Last Edit: October 04, 2012, 05:58:45 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #25 on: October 04, 2012, 05:47:44 PM »
@SpeedyPC,

You know how difficult that really is to "translate" and popularize technical terms? This so all can grasp what is meant, more or less. I tried to explain to you and bob what I found out so far about the inner workings of this "amazing, innovative" protection tool. I do that firing the files up in a binairy txt viewer and going through the executables and dll of the software one by one and line after line of code. All that info  translated from code is further been investigated with the best friend we all have online and that is Google's search. Then I give the information integrated as I find it and so slowly and surely I come to the analyzing stage I have reached. I had several years here with a lot of good friends in the forums to learn to do this. !Donovan for instance has been a very inspiring friend, and also Pondus came up with a lot of inspiring information, etc. And I also have to mention our good friend schmidthouse who through his enthusiasm made me decide to beta test the tool.
A good searcher could do many times more than the best hacker can ever achieve, remember that lesson from me. Well I hope I have explained a couple of things about this software protection tool and users will get wise by asking. I do not know all the answers, but I try,

pol
« Last Edit: October 04, 2012, 06:09:02 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline CraigB

  • Avast Überevangelist
  • Serious Graphoman
  • *****
  • Posts: 11239
  • No support PM's thanks
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #26 on: October 04, 2012, 06:28:17 PM »
Been using it for several hours now and all's well, doesn't conflict with anything i have installed, only three items protected here for me IE which is my main reason for this added protection tool, Media Player and foxit but I run my systems very light - no java or unneccesary rubbish.

It's also running quite light at 1.2Mb so other than the icon in the taskbar i dont notice it at all, it's a better (smarter) and simpler solution to Emet imo.
« Last Edit: October 04, 2012, 09:46:05 PM by craigb »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48552
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #27 on: October 05, 2012, 12:44:28 AM »
Thanks for the dummy's explanation. :) It's greatly appreciated.


I can now tell every one that my computer is protected from a to Z
I've also added some M and W into the mix
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7170
  • When you think you know, Think Again
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #28 on: October 05, 2012, 02:26:33 AM »
Fourth (4th.) day installed with not an issue.
I have also done a XP repair because of unrelated issue and had to Reinstall IE8, SP3 and 107 updates with no interference from 'Z'
Very nice. :o ;) :)

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7170
  • When you think you know, Think Again
Re: Can ExploitShield browser version be used next to avast resident av?
« Reply #29 on: October 06, 2012, 08:08:33 PM »
I've been following this thread:
http://www.zerovulnerabilitylabs.com/forum/viewtopic.php?f=2&t=51&p=183#p183

And have also replicated the issue with the "Help Center".
 Z did Block and quarantine the file:OLEAUT32.dll  ???
« Last Edit: October 06, 2012, 08:11:55 PM by schmidthouse »