New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. iammike

    iammike Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    342
    Location:
    SE Asia
    Thanks, but I have the "Always show all icons and notifications ...." enabled so that I can see all notifications and icons

    1.JPG
     
  2. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Oh....I see.
     
  3. iammike

    iammike Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    342
    Location:
    SE Asia
    Yeah that's also why I see it's gone. Very strange.

    ooh forgot :oops:

    Running v 3 Build 15 10032014 (Registered Version)

    Ps: I will uninstall and re-install and see what happens (will report back)
     
    Last edited: Apr 11, 2014
  4. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Yep, happened to me again today. I recovered quite easily with an "import," but it has been a little annoying.
     
  5. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    I am running it again and it is looking good so far :)
     
  6. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @jmonge

    Great :D

    @iammike

    I can add a timer that every N minutes ERP checks if the tray icon is visible and auto-reload it.

    @TomAZ

    I'll take a look at that issue this week.

    Regarding the issue with PrivaZer, an user has reported us that the issue is appening only when the option "Restart PC after cleanup" is checked.

    Can someone confirm it ? I have no VMs available for testing until saturday.
     
  7. iammike

    iammike Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    342
    Location:
    SE Asia
    Thanks !!! :thumb:
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    @ novirusthanks

    1 Is PowerShell.exe (and powershell_ise.exe) a vulnerable process in ERP? I can´t check it myself, I´m on an old PC without ERP.

    This should stop these kind of attacks:

    http://blog.trendmicro.com/trendlab...xcel-files-infected-using-windows-powershell/

    2 Also, is it possible to make Exe Radar act like Applocker on Win 7 and 8? Or is this already possible? :)

    3 And lastly, is it technically possible to stop the installation of browser extensions, for example in IE, Firefox, Opera and Chrome?
    That would be cool. :cool:
     
    Last edited: Apr 14, 2014
  9. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    Sorry for this, perhaps trivial question, but following an uninstall I've seen file injhlp32.dll in windows\system32\, and wonder if it may be safely just deleted? Thanks.
     
  10. clubhouse1

    clubhouse1 Registered Member

    Joined:
    Sep 26, 2013
    Posts:
    1,124
    Location:
    UK
    Does MBAE make a good bedfellow with NVTE?
     
  11. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @Rasheed187

    Nopes, but it can be added.

    You should add to the "Vulnerable Processes" every process that is responsible to handle the execution of that file extensions, for example, cmd.exe handles .com/.bat executions, wscripts.exe handles .vbs executions, rundll32.exe handles loading of .dll files, etc. So everytime a file extension is executed, you are notified.

    Mhh I don't know as of now, if it is involved the execution of a process, then it could be possible to handle it. I'll have to make some tests :)

    @Dermot7

    Sure, you can safely delete it. That file was part of old versions of ERP.

    @clubhouse1

    Yes, we have some users that use NVTERP with MBAE without problems.
    If for some unknown cause a payload bypasses MBAE, there is NVTERP that can block it.
     
  12. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    @novirusthanks Thanks for your reply, and I may install later version also again, once I've done looking at a few setups. :)
     
  13. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    @ novirusthanks

    Thanks for the feedback. ;)

    About browser extensions, AFAIK at the moment, no security tool is able to block extensions in Opera, Firefox and Chrome. Blocking of BHO´s in IE is possible, for example with Neoava Guard, an old skool HIPS on Win XP.

    Btw, about the problem with Sandboxie, can it perhaps be solved by making ERP monitor parent-child executions? So let´s say that you could give Start.exe full execution rights (as parent), that would stop ERP from alerting about processes launched by Sandboxie, I suppose? :)
     
  14. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    What problem with Sandboxie?
     
  15. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
  16. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    See post #3220. When I´m sandboxing apps, I don´t want to see ERP alerts. :)

    Btw, doesn´t ERP work in Standard User accounts?
     
  17. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Take out the line in Sandboxie.ini pertaining to ERP and that should do the trick.
     
    Last edited: Apr 17, 2014
  18. KaneComputing

    KaneComputing Registered Member

    Joined:
    May 7, 2005
    Posts:
    33
    Location:
    Shenandoah Valley, VA
    No problems on my Win 8.1 Update 1 (x64) system so far!

    Cheers,

    David
     
  19. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    This is a new beta build for v3.1:
    http://downloads.novirusthanks.org/files/EXERadar_Pro_x86_x64_v3.1_20042014_BUILD1_20042014.exe

    These issues should be fixed:

    -Sometimes when ERP is closed or the PC is restarted the lists are emptied
    -Sometimes when the PC is booted I receive "Failed to retrieve driver handle!"

    I also added few more safe command-line strings when ERP is installed with the "Recommended settings" enabled.

    If someone has the possibility to test this new ERP with PrivaZer (in a virtual machine) just let me know if after the cleanup and/or reboot ERP runs normally.
     
  20. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    Downloaded and will test. Couple of notes on PrivaZer. I didn't have any problem on my virtual machine. but it made a huge mess of my Desktop. Be sure and have a good image first.

    Pete
     
  21. smith2006

    smith2006 Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    808
    Thank you, will update later. :)
     
  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Installed new 3.1 beta. Looks good. I would occasionally still get the driver failed message under certain boot conditions which I avoid. I pushed it with this build and the driver loaded fine.

    Pete
     
  23. Pliskin

    Pliskin Registered Member

    Joined:
    Feb 8, 2009
    Posts:
    440
    Does ERP notifies the user of loadlibrary calls, which LNK vulnerability used few years ago and most anti-exe programs failed. Here it is, method A.
     
  24. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @Pliskin

    I tested ERP against Stuxnet few days ago and ERP correctly detected both attempts of Stuxnet .LNK files to load the malicious .DLL file and the .TMP file:

    The loading of the malicious file ~WTR4141.tmp is blocked when the first .lnk file is executed:
    http://postimg.org/image/6ufb5btmr/

    The loading of the malicious file dll.dll is blocked when the second .lnk file is executed:
    http://postimg.org/image/o2xh7ci9t/

    I tried to download the "suckme(dot)rar" but it has a password:
    http://www.ivanlef0u.tuxfamily.org/?p=411
     
  25. Charyb

    Charyb Registered Member

    Joined:
    Jan 16, 2013
    Posts:
    679
    What happened to the trusted vendor and trusted folder tabs? Were these removed in an update?

    EDIT:
    I found the answer.

    The Trusted Folders tab has been merged with the Path Comparison tab and the Trusted Vendor list is found in Settings.

    The online help file needs to be updated.
     
    Last edited: Apr 22, 2014
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.