New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Check my post #3264.
    ;)
     
  2. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    I had already seen that post that's why I did a clean install :D, but I was already on what I think was the Final Beta Stable version that's why when I checked for updates, it said I was already up-to-date. Before on other Beta versions, it would tell me to update to 2.7.7.

    dja2k
     
    Last edited: Mar 18, 2014
  3. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Both of mine on my Main Computer say Tuesday, March 11, 2014 o_O. And those are from the installer located on the main NVT site.

    The same installer does say the correct dates when installed on my Virtual Machine though.

    dja2k
     
    Last edited: Mar 18, 2014
  4. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Not really sure I understand this. Who needs to use it -- and why??
     
  5. iammike

    iammike Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    345
    Location:
    SE Asia
    ^ Maybe because of this ?


    https://www.wilderssecurity.com/showpost.php?p=2307198&postcount=2831
     
  6. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    "If you are a v2.7.7 user, you should find this tool useful.
    This is a small tool useful to merge the command-line strings that used the MD5 hash with the wildcard-enabled strings."
     
  7. reyes

    reyes Registered Member

    Joined:
    Dec 8, 2013
    Posts:
    48
    Location:
    INDIA
    is there any reactivation limit for NVTERP?
     
  8. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @reyes

    If you see the ERP_Activation_Error.log file it is normal, it is useful to handle issues when ERP cannot be activated for some reasons. There are no reactivation limits, you can reactivate ERP as many times as you need.

    @dja2k

    These are the MD5 hashes for EXERadar.exe processes in the final version:

    EXERadar.exe (64-bit OS) = 440DDFE1C93535A10C7E1FBBD29BBC3F
    EXERadar.exe (32-bit OS) = 57EC7EDFCE0272CCE0BD93CEDF8EA6E8

    @TomAZ

    That tool is useful to copy the command-line rules from the list of whitelisted command-line strings (that used MD5 hash) present in ERP <= 2.7.7 to the new database file used in ERP v3.0, so it only applies to users of ERP <= 2.7.7
    all users that beta-tested ERP v3.0 do not need that tool.
     
  9. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    In 3.0, is there no longer the Menu option to Scan Folders?
     
  10. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Does this actually get installed, or is it just a run-once utility?
     
  11. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Where do you find the download link to this current version?
     
  12. Eru

    Eru Registered Member

    Joined:
    Mar 23, 2010
    Posts:
    108
    Location:
    Poland - Sosnowiec
    ERP is asking me every reboot about rundll32.exe, and I can't run Firefox & Thunderbird when it's on - i must exit ERP to be able to run them :(
     
  13. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @TomAZ

    The "Scan Folder" option is available if when you click on WhiteList->Processes right-mouse-button -> Add new...

    http://postimg.org/image/q0gr7alq3/

    Only once, when the command-line strings have been merged, you can remove the tool.

    http://downloads.novirusthanks.org/download-erp.php

    @Eru

    What is the command-line string used by rundll32.exe ?

    Please paste it here the complete command-line string.

    To do this you can switch ERP in "Trust Mode" and then check the "Events" tab for rundll32.exe process, right-click over each line and select "Copy to Clipboard"->"CmdLine", then paste all the data here.
     
  14. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
  15. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    Yes that is correct, I was speaking about the file EXERadar.exe located in the installation folder C:\Program Files\NoVirusThanks\EXE Radar Pro\EXERadar.exe :)
     
  16. Eru

    Eru Registered Member

    Joined:
    Mar 23, 2010
    Posts:
    108
    Location:
    Poland - Sosnowiec
    In Trusted Mode ERP isn't asking about rundll32.exe
    The CMDLine:
    And I can run FF & TB without any problems.
     
  17. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @Eru

    Follow these steps:

    1) Go to WhiteList TAB -> Command-Line TAB
    2) Right click and select "Add new..."
    3) Type the command-line string:

    Code:
    rundll32.exe NVCPL.DLL,NvStartupRunOnFirstSessionUserAccount 
    
    4) Switch back to "Alert Mode"

    See if now you can open FF & TB.

    In case you have still problems, in the alert dialog click always on "Allow" and then go to Events TAB and paste here all the command-line strings related to rundll32.exe.
     
  18. Eru

    Eru Registered Member

    Joined:
    Mar 23, 2010
    Posts:
    108
    Location:
    Poland - Sosnowiec
    It seems that now everything is ok :)
     
  19. Defenestration

    Defenestration Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    1,108
    Congrats on release of v3.0. Few more usability suggestions:

    1) Double left-click on command-line to open View/edit command-line string dialog
    2) Delete keypress deletes selected entries.
    3) A checkbox option to "Confirm deletions", which would display dialog on deletion when enabled.
    4) Have Date/Time column for all whitelist listviews
     
  20. TS4H

    TS4H Registered Member

    Joined:
    Nov 5, 2013
    Posts:
    523
    Location:
    Australia
    I would also like to add to these suggestions that, it would be great to see the Command-line strings that the user added apart from system default. ie; labelled with [custom].

    Regards.
     
  21. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello TS4H,

    I had made a post in regards to this subject:

    NVT had replied:

    Possibly adding a comment section to the "WhiteList > CommandLine" could be a solution for what you are asking?
     
  22. Defenestration

    Defenestration Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    1,108
    A "Cleanup" context menu item would help with this. When selected, ERP would scan for all program files in the list, and display any that were no longer present in a dialog, with the option to Remove them from the list. As you may not want to delete all of them, a checkbox next to each item on the dialog would allow the user to choose (listview on dialog should support multiple selection, and have context menu items to Check All, Check None, Check Selected, Invert Selection).

    A comment section would also be useful though.
     
  23. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Ah.... this feature has been there for quite a while.
     
  24. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    The problem with command line is that the actual program that launched it does not always appear within the command line itself. For example, I have program x on my system and it launches a command line beginning with rundll32.exe but no where in that command line is the program that launched it mentioned. Now say I have added it to my whitelist but later on remove program x. Now the "cleanup" routine sees rundll32.exe is a valid file still on the system, so it does not show the referenced command line in an option to "cleanup". If I had added a comment like "program x" to that command line when I added it, I would now know that particular command line is not needed so I can delete it. IMHO this is why a "cleanup" option would not really work with command lines (there is already a cleanup feature called remove non-existent processes available for the allowed process whitelist which works quite well) but having a comment section for command lines would allow you to manually reference what program needed it, so if program x is removed in the future you can manually delete the referenced command line. I beta test a lot of different products and it is very easy to end up with many command lines in your whitelist that you have no idea what program initiated them. This post turned out a bit longer than I had planned so I hope it makes some sense...
     
  25. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello Pete,

    Yes, for whitelisted processes (which works great) but not for whitelisted command lines (which I do not think would work well for reasons in my last post).
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.