New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. Defenestration

    Defenestration Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    1,108
    Could it be that with most installers, the parent process stays around until the installation is complete (ie. it's the last process to finish), in which case you just need to detect when that parent process terminates (ie. without polling).
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I think you need an advanced HIPS for this which can monitor "direct disk access" and can protect the MBR. But once you install a malicious driver it's quite hard to stop advanced root-kits. That's why M$ came up with PatchGuard.
     
  3. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Tested install mode. Worked great.

    Rasheed, I have to confess when you kept asking about it I thought it a waste. But seeing how Andreas implemented it, I like it.

    pete
     
  4. netbook0tr

    netbook0tr Registered Member

    Joined:
    Nov 7, 2010
    Posts:
    24
    Location:
    england
    Worked great on my Windows 8.1.3 64-bit, Windows 7 Pro 64-bit and Windows 8 32-bit!!!
    Stealthy mode worked ok on this build, I like install mode.
     
  5. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    I'm having a problem with the latest build. It doesn't remember my Internet connection and my printer at start. Keeps popping a windows even if I click on "Allow" I tried learning mode, allow mode but same result.
    What else can I do?
     
  6. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Are those whitelisted?
     
    Last edited: Feb 25, 2015
  7. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    Yes they are
     
  8. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    I mean....commandlines are whitelisted?
     
  9. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    Yes they are. Funny things is that sometimes I shut down the PC and it will remember the first time I restart it. But then if I close it again and restart it, I get
    the popup windows asking me to allow.:confused:
     
  10. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @Antarctica I sent you a PM, can you write here or by PM the command-line strings (inside the CODE tag) ?
     
  11. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    Done.Thanks Andreas:)
     
  12. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    I can't see them in your post or in my PM/email, can you resend :)
     
  13. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    Thank you Andrea for your help. Really appreciate how fast you respond when a problem arise.:)
     
  14. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    3.1.0.0Build1-24022015
    Font is noticeably smaller.
    Why is a virustotal scan and signature / certificate check not doable before populating initial (default) WhiteList.
    I mean, after ERP is initially setup... I may run Sysinternals.
    Why not have ERP run Sysinternals as a prelude to WhiteList
     
  15. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    Not sure I understand what you are suggesting or why.
     
  16. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Not sure I can explain my thinking sufficient to satisfy.
    Intellectually, I resist auto allow auto whitelist. I'll run Autoruns and Process Explorer scans before clean install of ERP. I'll run Herd and Hitman scan before ERP install.
    I'm imagining a built in native virustotal scan prior to whitelisting.
    ERP has rt click virustotal scan (after an event). Why not scan before an event is whitelisted ?
    If that would be too cumbersome then....maybe, limit scan to before initial whitelist setup.
    As ERP is now. I have to manually scan each event after the event has been whitelisted. Seems, counter intuitive.
    I probably do not appreciate understand what would be involved. Intellectually, I "feel" malware may pop anywhere at any time under any name. Even a legit name in a seemingly legit path. So, a scan before the event seems prudent. Perhaps in the way real time protection works.
    Is real time whitelist scan a crazy idea ?
     
  17. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Okay

    What you should do if you aren't sure is thoroughly scan your system prior to install. Then you can safely whitelist windows and both program files.

    Remember also ERP is strictly and anti executable. Nothing more. I personally would hate to see it try and be more. I one wants to scan first, then do that with an AV.

    My $.02

    Pete
     
  18. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,812
    Location:
    .
    Better yet, why don't make use of a previously saved system image? I mean it take much less time to restore and update just a few programs and update ERP.

    My two cents too, ;)
     
  19. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Interesting, perhaps Andreas can observe other apps to come up with more ideas how to make this work. Currently I'm not using HIPS, but on Win XP I used SSM which also implemented this, though not perfect, I sometimes still got to see some alerts related to the install process.

    Haven't tested it yet, but as you have seen it's about convenience.
     
  20. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @ bjm

    I agree, if you want to make sure that your system is clean use an AV, it's that simple. I personally like ERP's simplicity, if you want an all in one tool you can take a look at SecureAPlus. I personally didn't like that tool because I didn't need the cloud scanning stuff and white-listing looked a bit more complex.
     
  21. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Okay ~~ Just feels backwards that ERP offer rt click Search hash google Search process google Search hash virustotal "after" Allowed Whitelist.
    I can always Block Once then Search. Anyone think smaller text is too small ?
     
  22. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
  23. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Same as VS....
     
  24. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    same as VS ~ meaning ?
     
  25. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    ...meaning "check my answer in VS topic"....
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.