New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    No...this Wilders Thread is for ERP .... I posted what I would do. Again, not in the know re influence Quietzone. I missed that you felt Quietzone as causal in your original post. I noted you pulled v3.0. I note v3.1 is improved. Hopefully, others more in the know re Quietzone. I'll close with ERP cleanly installs/integrates OS.
    NVT ERP developer is active here...
     
    Last edited: May 16, 2015
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
  3. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I am using beta version v3.1.0.0 BUILD1-15052015.

    I have just made $20 donation.

    If I do 'check for update', a panel shows there is newer version (is there a newer beta?) but if I click on link it does not open on my system ...

    Where can I get latest (beta) version on the NVT site?

    Maybe it would have been better if I had purchased license for stable version at this point, rather than donate for beta version?

    Edit: My question answered:

    Thanks a lot for you donation, much appreciated.

    The latest (stable) beta version can be downloaded from this link:
    https://www.wilderssecurity.com/thre...ks-exe-radar-pro.300552/page-185#post-2490985

    Since it is a beta build, you should disable the option on "Settings" -> "Notify me when a new version is available" and you should not check for updates as it checks only stable version, that is at version 3.0 (older).

    Very soon we will release officially the new stable version v3.1.

    We only miss two features to add.

    Regards,
    Andreas
     
    Last edited: May 22, 2015
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    @novirusthanks

    On my system, ERP's process monitor can not list sppsvc.exe (Microsoft Software Protection Platform Service). The process is visible with Process Explorer and System Explorer. Other requests: give an option to sort "Vulnerable Processes" and "Command Lines". And please try to get rid of the ugly focus rectangle.
     
  5. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    Issue : Exe Radar Pro, doesn't appear anymore on the system tray when it starts automatically. How to fix it ?
     
  6. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    I have been running a snapshot that has Online Armor installed, together with ERP.

    However, I launched Maxthon browser portable version from a USB stick a little while ago, and have had no end of problems getting it to run, when previously there had been no problem running with ERP.

    Anyway, I have shutdown ERP, and am just relying on OA for protection, so I can continue to run Maxthon portable.

    Looking at the logs in ERP is confusing to say the least.
     
  7. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I have a portable apps folder and I have it whitelisted in ERP, but when I launch IObit uninstaller I still get 3 alerts (2 when opening and 1 when closing) and I have the command-lines whitelisted but they still keep alerting me everytime I open IObit. Is there a way to stop the alerts by tweaking the command-lines?
    opening
    "C:\Windows\System32\cmd.exe" /c Schtasks /run /tn "Uninstaller_SkipUac_Family"

    "C:\Windows\System32\cmd.exe" /c WMIC QFE GET /format:list >"C:\Users\Family\AppData\Local\Temp\IObitUninstallerPortableTemp\hotfix.ini"
    closing
    "C:\Users\Family\AppData\Local\Temp\nsfBE77.tmp\ns7680.tmp" "schtasks.exe" /delete /tn Uninstaller_SkipUac_Administrator /f
     
  8. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Um, I have C:\Users\user\AppData\Local\Google\Chrome\User Data\SwReporter\3.20.1\software_reporter_tool.exe in Blacklist.
    Filename: software_reporter_tool.exe just ran as detected by Norton.
    Version 3.21.0.0 Identified 5/31/2015 at 7:52:52 PM
    MD5 that just ran is C4EF32C1C0473392EF4204890AF8E457
    I have 9 Events with same MD5 same timestamp within second.

    MD5 already in Blacklist is EB81815F1628247337DCF5C44A137366

    As a bunch of new SwReporter are already in Whitelist. I cannot Blacklist.
    Process = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Command-Line = is huge.

    How do I identify and Block new SwReporter to ERP.
    ERP did not Alert
    I'm Sandboxed. But have Full File Access to ERP

    Update: Now ERP is showing a bunch+++ more with same MD5. Different PID's.
    How do I Blacklist...?

    Update: software_reporter_tool.exe ran again. Norton Download Insight flag's the event.
    Anyway to make ERP see the event (again)..? I was able to Blacklist once 15/05/2015
    ERP build 15052015
     
    Last edited: Jun 3, 2015
  9. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    Salutations,

    Is ERP ready for Windows 10 coming up shortly? If need not? could you give a time frame?:thumb:
    For Windows 10? Many thanks!:isay:
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    Only issue on 10 I've seen is the activation windows comes up. I just click cancel and all is well.
     
  11. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    Salutations,

    @Peter2150, Appreciate your insight and thank you for the information.



     
  12. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Update to #4636
    SwReporter wanted to run again. ERP prompted. I Blacklisted. The MD5 is different each call.
    I don't know if SwReporter run on a schedule or trigger. Chrome dialog asked if I wanted to run. "If your having Chrome problems run SwReporter". No thanks. In theory. I think SwReporter is looking for conflicts. I think SwReporter calls home. Since the MD5 changes each run. ERP will catch it..? Or, I'll have to catch Chrome dialog window. Norton logs the event. I may have missed toast flyout. Focused on ERP window. ERP logs at least a dozen Events. Same MD5 different PID.
     
  13. TerryWood

    TerryWood Registered Member

    Joined:
    Jan 14, 2006
    Posts:
    1,039
    Hi All

    New to No VirusThanks. On Win 7 SP1 64 Bit.

    When I boot Windows (With NoVirusThanks permanently in LockDown Mode) NVT EXE blocks rundll32.exe even though I white listed it. When I try to whitelist it again it says it is already whitelisted.

    The process and Cmd Line are shown below:

    C:\Windows\System32\rundll32.exe

    "C:\Windows\System32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart

    Question, why is something that is whitelisted being blocked (as shown in Red on the events tab) and what is shadowPlayOnSystemStart?

    How do I stop it being blocked?

    Thanks

    Terry
     
  14. NSG001

    NSG001 Registered Member

    Joined:
    Jul 14, 2006
    Posts:
    682
    Location:
    Wembley, London
    Andreas the developer hasn't been seen for around 3 weeks.
    Anyone know if he is still active :doubt:
     
  15. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I am sure he is.
     
  16. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Please see http://novirusthanks.org/help-files/exe-radar-pro/#vulnerable-processes Hope helps.
    When a process that is listed in the "Vulnerable Processes" is executed, and if the commandline string is not whitelisted, NoVirusThanks EXE Radar Pro will generate an alert so you can allow or block the execution of the process, even if you have the process present in the whitelist.
    http://www.shouldiblockit.com/nvspcap64.dll-50194.aspx

    IMO FWIW ~ Alert Mode is just as safe as Lockdown. Lockdown offers less Alerts. Thereby IMO less information. Once ERP is trained. ERP is quiet. So, I prefer Alert. Or, Lockdown > Ask user what to do. Maybe you're at Lockdown > Block Process Execution
     
    Last edited: Jun 7, 2015
  17. TerryWood

    TerryWood Registered Member

    Joined:
    Jan 14, 2006
    Posts:
    1,039
    Hi BJM

    Thankyou, an excellent reply. The link was very helpfull as well.

    Terry
     
  18. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Hello,
    Since, recent Norton update. ERP prompts with numeric string. Only string goes to Command-Lines. How to wildcard..?
    ODD NORTON ERP.png ODD NORTON ERP 2.PNG ODD NORTON ERP 3.PNG ODD NORTON ERP 4.PNG
     
  19. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Has anyone heard from Andreas?
     
  20. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Nope. Maybe he's on vacation....
     
  21. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @siketa

    Not yet in vacation, just very busy with an external errand :)

    @boredog

    I will try to install Quietzone and ERP to see if there is any conflict.

    @Rasheed187

    When Install Mode is activated for a parent process, all processes started by that process (including sub-processes) are auto-allowed.

    If you get an alert about a vulnerable process it should mean the vuln rocess was not started by a parent process related to the main parent process present in the Install Mode.

    Do you have any example or software I can download to reproduce the issue ?

    @bjm_

    To stop SwReporter you should run ERP in Lockdown Mode so that only whitelisted processes/cmdlines are allowed.

    As of now there is no option to blacklist a process by commandline or path.

    @bjm_

    You should whitelist the Norton's process, that is best way.

    @Overkill

    About these commandline strings:

    What is the parent process ?
     
  22. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    parent process = C:\Portable Apps\IObitUninstallerPortable\IObitUninstallerPortable.exe
     
  23. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Guess, I forget...by thinking Alert is same as Lockdown only with more "Alerts"
     
  24. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    I don't believe this is correct. You can test it with TCP Optimizer and SSD Tweaker as mentioned before. In the first screen-shot, you will see that powershell.exe is launched by TCP Optimizer, and in the second one, cmd.exe is launched by ngen.exe. However, this is a mistake from ERP, because both Process Explorer and System Explorer report that the parent process is SSD Tweaker. I want "Install Mode" to make ERP stop alerting about vulnerable processes that are launched by the parent process, without having to make permanent rules.
     

    Attached Files:

  25. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    @ novirusthanks

    Two requests:

    1 Is it possible to make a "terminate parent process" option, unless the parent is a system process, to avoid problems.
    2 Please give an option to sort by "folder path" instead of PID: Events tab--> Process column
     
    Last edited: Jun 27, 2015
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.