Jump to content

What custom shields are you using with MBAE Premium


MCFatTongue

Recommended Posts

  • Staff

Basically when you add a shield for "something.exe" MBAE will look for any process being created on the system with that process name. If a process executes with that name, then MBAE injects itself into the process space and monitor its behavior.

Link to post
Share on other sites

Outlook Express, Mozilla Thunderbird - both defined as browser

Comodo Dragon

 

A copy of the Comodo Dragon .exe file is named chrome.exe.  I do this because Agnitum Outpost Firewall recognises chrome.exe as a protected application so on systems with Outpost Firewall, I run Comodo Dragon thus.

Link to post
Share on other sites

So it will basically analyze the behavior for exploit techniques etc.?

 

And why doesn't it show Flash as being protected anymore? Is that included in the browser level protection or do I have to add a custom shield? It also doesn't show AcroRd32.exe or Acrobat.exe as being shielded, although I have premium.

 

Sometimes the shielded applications drop to 0 when I open a PDF in Internet Explorer too.

 

And one more question, I know it says in the known conflicts that it's not currently compatible with EMET, but I have EMET 4.1 Update 1 installed and just have the simexecflow mitigation disabled for IE. I've also had to remove the EMET mitigations for Acrobat.exe and AcroRd32.exe.

 

Will having EMET and MBAE at the same time cause a problem other than making things not function sometimes? Will it reduce the protection of either program to have them both on at the same time?

Link to post
Share on other sites

  • Staff

Yes, correct about analyzing behavior.

 

Flash is included in the browser, no need to add a custom shield for it.

 

The counter has some Known Issues: https://forums.malwarebytes.org/index.php?/topic/135127-known-issues-conflicts/

 

As for EMET, read the following thread, especially the posts by Kaine who has looked in-depth a both EMET and MBAE running alongside:

https://forums.malwarebytes.org/index.php?/topic/150689-mbae-emet-hmpalert-conflicts/

Link to post
Share on other sites

  • 3 months later...
  • 3 weeks later...

I've just upgraded and entered Nitro PDF Reader, Windows Media Center ( under media player), and Open Ofice and Libre Office.  For these last two, I had to make a single consolidated entry.

 

Those who have entered Thunderbird -- What category was used?

 

I used the browser profile for Thunderbird, which worked fine.  The current advice for which category to use for email, is at the end of this thread

https://forums.malwarebytes.org/index.php?/topic/156564-email-program-profile/

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.