New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @ marzametal and TyRizian

    The reason why I asked this, is because I'm getting tired of having to navigate to the sub menus. Why not also offer the "alert" and "lockdown permanent" mode on the main menu? Of course without removing them from "Protection Modes".

    About my "double click" idea, it's the way it worked with SSM, so a "quadruple click" would bring up the GUI. But it's only good for people who don't look at the main GUI that often, so it should be optional.
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @novirusthanks

    I have tested the "install mode" and it seems to work fine, but I still need to test it on my real system, so far I've tried installing a couple of apps inside the sandbox (with Sandboxie). I do wonder if it's perhaps a good idea, to make ERP give a notification when "install mode" is turned off, after you have installed some app.

    BTW, I had a problem with Privazer inside the sandbox, ERP kept asking me about cmd.exe (see screenshot), and I couldn't get rid of it, no matter if I clicked on "allow until reboot" or "install mode". Is there a workaround for this? I also got an error message from SBIE that it could not communicate with its service, but I can not imagine that ERP had anything to do with that.

    http://privazer.com/
     

    Attached Files:

  3. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    CMD is one of the vulnerable processes so it will be popping up unless you whitelist the string. If it's the same string with minor changes you might need to use wildcards.
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Correct, but you should be able to get rid of it without having to white-list the string(s). Perhaps the new "Install Mode" can play a role.
     
  5. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    I've just installed the Beta version and I have a few basic questions :

    1. What's the 'Allow Mode if you compare with the 'Alert Mode' ?
    2. Need explanations between 'Applications' (from Whitelist) and 'Parent Process' ?
    3. Could ERP protect also again illegitimate dll files ?

    Thanks in advance.
     
  6. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,812
    Location:
    .
    This is the online help file:
    http://novirusthanks.org/help-files/exe-radar-pro/
    Remember ERP is just an anti-executable software.
     
  7. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    This is an old help file, and it can't help me more. Protections mode are different.

    If someone can to give me yours answers, I would really appreciate it.

     
  8. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,812
    Location:
    .
    Yep, I agree. Perhaps novirusthanks can review and update that online help file.
     
  9. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    1. Allow mode just lets everything run. Alert mode pops up when an un whitelisted exe runs.
    2. If a is the parent and b is the child, under white list if a is listed and b isn't you will get an alert on b. Under parent process is a is there then b would be allowed to run
    3 No. a dll is not an exe file.

    Pete
     
  10. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    OK, thank you Peter.
    When you said 'Allow mode just lets everything run', except those who are on the blacklist, I suppose. Only whitelist is on 'Allow Mode', is that correct ?

     
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I haven't tested as I don't use Allow mode, but I think allow mode allows everything. Maybe someone else can confirm.
     
  12. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    Bug report:

    Under Vista 32 bits, ERP latest beta version, doesn't start automatically from my user account. In fact, it doesn't appear on the system tray. Nevertheless, the process EXERadar.exe is loaded. I have to stop the process , then I manually start in order to appear on the system tray.
     
  13. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @Rasheed187

    Even if the process is in vulnerable processes, if it is related to the setup file (installation) it should be allowed.

    It seems that Privazer is scanning your system (the installation should be already finished), that should not be related to the installation I guess ?

    This is the command-line wildcard you can use for that particular command-line string:

    @Ashanta

    The "Allow Mode" is used to allow every process execution, except processes listed in the "BlackList".

    That's strange, I do not have Vista here to test but it should work fine.

    Anyone has Vista 32-bit with ERP installed ?

    More questions:

    What other security apps do you have ?
    Is there the possibility a security app is blocking ERP from starting ?
    Is ERPSvc.exe (ERP Service) process running ?

    @puff-m-d

    That is correct, I removed the two recently added processes.

    @Rasheed187

    #1 can be added, #2 may be added an option to control the double-click event on the trayicon, #3 hard to do this without sub-menus.
     
  14. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    I'd like to notice that I'ven't such problem with my admin account, this only occurs on the user account.

    What other security apps do you have ? HMP Alert, Spyshelter and AppGuard
    Is ERPSvc.exe (ERP Service) process running ? Yes, is running and ExeRadar.exe also.

     
    Last edited: Mar 15, 2015
  15. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    I think I found the culprit, it was SpyShelter Premium, it encryption module interfered with ERP. I will confirm in the next days.
     
  16. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,997
    Location:
    Poland - Cracow
    Try this things:
    1 - add ERP process to exlusion list
    2 - set "better comptiability mode"

    Panorama.jpg
     
  17. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    The second point was exactely what I made.
    I will add your first point. Thanks Ichito ! :)

     
  18. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    During update of the latest Adobe Flash Player used with PaleMoon browser I got 3-4 alerts although I pressed "Install mode" each time.

    NVT ERP 3.1.0.0 BUILD1-09032015

    Andreas, can you check it?
     
  19. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    Were the alerts related to vulnerable processes ?

    To reproduce the alerts, should I install PaleMoon browser with an old version of Adobe Flash and then check for updates from Adobe Flash ?
     
  20. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes correct, it was already installed, but I don't always want to white-list stuff, especially when I'm only testing stuff. So why wasn't "allow until reboot" working? Also, I installed ManicTime and I kept getting alerts about "rundll32.exe" when in install mode, so it seems like it currently does not suppress vulnerable processes, seems like a bug. Another thing that I noted about ERP Build 03032015, is that it doesn't always recognize "start.exe" (Sandboxie) as "safe parent process". So seems like the old bug is back again, perhaps you can check it out.

    http://www.manictime.com/
     
  21. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Sounds cool, but I'm actually a bit surprised about #3, shouldn't it be easy to also offer these options on the main menu? If you could add this, then I wouldn't even need #2. To me it's all about speed, even if it's only a matter of seconds, I think it takes too long when having to navigate to the "Protection Modes" sub-menus.
     
  22. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Here is the part of Event log at that time....
     

    Attached Files:

    Last edited: Mar 18, 2015
  23. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,172
    Location:
    Canada
    Giving this a try, couple of issues. When I click on the desktop icon the program won't open, have to click on taskbar icon to open it.

    Downloaded from post 4436 which says it is build 2, when I click on " About" in taskbar bar icon it says I'm running build 1.
     
  24. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    I think desktop icon just starts the application and does not open GUI.
    Andreas sometimes forgets to update About window.
     
  25. digmor crusher

    digmor crusher Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    1,172
    Location:
    Canada
    Yah, I'm getting a box that says an update is available, version 3.0.0.0, ok, I won't worry about either. Thanks.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.