New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. hjlbx

    hjlbx Guest

    I'd ask Andreas about it. I brought it to his attention, but since typical user rarely, if ever, installs softs using Windows' hidden, primary Admin account I am not sure how big of an issue it is. I would simply think he would say "Don't install it that way, unless you intend on being signed into the primary Admin account all the time..."

    Any how ask @novirusthanks
     
  2. marzametal

    marzametal Registered Member

    Joined:
    Mar 19, 2014
    Posts:
    766
    Come on @novirusthanks ! hehehe...

    EDIT: I gave it a test run, mightaswell suss things out first hand so-to-speak...

    Removed ERP from Stock Admin and installed in Hidden Admin, followed by reboot.
    In Hidden Admin, made the modifications and rebooted into...
    a) Stock Admin - tickboxes via settings committed, but lists were prepopulated
    b) Standard User - tickboxes via settings didn't commit, and lists reflected this

    So...
    Removed ERP from Hidden Admin, reset Hidden Admin to default and returned the account back to hide-mode.
    Installed ERP again into Stock Admin and followed with a reboot.
    Prompted with Startup Wizard, went through that (removing whitelisting)
    No lists were prepopulated, commenced adding prompted rules via command line, avoiding "allow process".
    Performed 2-3 reboots to flush out extra prompts, then slapped ERP into LockDown Mode and rebooted into Standard User.
    The settings tickboxes didn't commit (still appears to be default), only populated list is Whitelisted Command Lines.

    Security issue with this is as follows: the vulnerable apps list is empty as well. So user will have to pay attention to what is entered into command line list.
     
    Last edited: Oct 1, 2015
  3. hjlbx

    hjlbx Guest

    @novirusthanks

    Is there a way to disable the annoying Update prompt ? It is causing issues on my particular system.
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Go to File>settings and on the general tab, untick notify me of an update
     
  5. marzametal

    marzametal Registered Member

    Joined:
    Mar 19, 2014
    Posts:
    766
    Depends on the type of profile... if Admin, then it will stick. If it is Standard User, then it will not, which will require unticking every time SU boots... which is why I made my post @ #4808...
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @ novirusthanks

    I'm having system shutdown problems when I combine ERP with either MBAE or SpyShelter. When I put ERP in "learning mode", the problem seems to be solved but it will always reappear when putting the system in standby. If I uninstall MBAE or SS, the problem is solved. Do you have any idea why ERP combined with these tools might cause such a problem?

    EDIT: And can you perhaps add a "sort by process name" option in the events log?
     
  7. marzametal

    marzametal Registered Member

    Joined:
    Mar 19, 2014
    Posts:
    766
    @novirusthanks
    I am having weird window issues, revolving around the Settings window.
    In Admin account, the window is mega small, in Standard User account, the window is fine. I have provided screenshots...
    This is Admin...
    settings1.jpg
    This is Standard...
    settings2.jpg
    I am on W7 HP x64.
    I have configured AppGuard and Sandboxie to work with NVT-ERP.

    I have tried the following via Admin account with AppGuard switched off, to see if it would help:
    1) Close ERP from trayicon->exit
    2) Uninstall ERP completely
    3) Reboot the PC (very important)
    4) Install ERP

    The screen shrinks regardless of reboot after install and then change settings, or if I use the initial wizard to choose recommended or custom settings / import my own backup, and then reboot.
     
  8. hjlbx

    hjlbx Guest

    I think there might be SpyShelter - NVT ERP driver issue. After all, both monitor essentially the same way.

    When I install SS + ERP together, shutdown and startup is delayed. Takes SS about 45 secs... and I have SSD. W\O SS, boot takes < 10 secs.

    I am going to try and create mutual exclusions to see if it helps. Stay tuned...
     
  9. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,997
    Location:
    Poland - Cracow
    It's confusing...SS + ERP togheter with Kerio 2.1.5 are working fine more then 1 year on my wife's XP...no issue, no slowdown...just ecelent. I think you should try
    - include ERP to the list in Keystroke Encryption/Process Filter/Do not encrypt keystrokes of...
    - switch on "better compatibility mode" in "Advanced" tab.
    BTW...SS and ERP doesn't cover the same protection area, its role is different.
     
  10. hjlbx

    hjlbx Guest

    "Better Compatibility" setting already enabled for Sandboxie.

    Yes, different role... but both use kernel mode drivers to monitor system.

    Thanks @ichito
     
  11. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes, perhaps it's some weird driver issue. I did notice that I don't have to uninstall SS Free, I only have to kill the SS GUI to solve this problem. BTW, does it also take long to put your system into standby? It takes about 10 to 15 seconds on my machine (SSD), I'm not sure if ERP plays a role in this.
     
    Last edited: Oct 11, 2015
  12. hjlbx

    hjlbx Guest

    I don't use Stand By mode... so I couldn't say.
     
  13. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I turned on my laptop today and found out all my whitelisted commandlines and safe apps were gone, i'm assuming this is a bug?
     
  14. TS4H

    TS4H Registered Member

    Joined:
    Nov 5, 2013
    Posts:
    523
    Location:
    Australia
    Had the same thing happen after I restored a backup and performed general maintenance tasks. Not sure why that happened. You may just have to restore a configuration backup if you have one, otherwise just restore to default and the default rules will comeback although you will have to retrain ERP.

    regards.
     
  15. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Like I said it's probably a bug. I can't wait for a new version!:)
     
  16. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    Yes, it happens to me lately with last build.
    @novirusthanks we need a fix asap please.

    TIA
     
  17. hjlbx

    hjlbx Guest

    :thumb:
     
  18. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    With all the image restore testing I do I've never seen this happen. Strange
     
  19. hjlbx

    hjlbx Guest

    There are problems with it... fixes needed.
     
  20. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    Sure but Andreas is on vacation or having fun with SOB :D
     
  21. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    How do I try and reproduce the problems. Note, I never use hibernate or sleep mode
     
  22. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Hmm, thanks for reminder to Export. :D
    Probably not related. I had one off when tray Icon vanished.
    I set 'Enable self defense against process termination'.
    IDK if 'self defense' is good, bad or other.
    Icon has been okay since...
     
    Last edited: Oct 17, 2015
  23. guest

    guest Guest

    Sure, dont expect weekly updates of ERP as before :D
     
  24. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I'm glad it's not just me, thought it was my pc :confused:
     
  25. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    How would I go about reproducing it
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.