New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. guest

    guest Guest

  2. hjlbx

    hjlbx Guest

    Faronics *.dll monitoring and blocking will consume system resources and visibly slow down a system - and for some to the extent that their system will be unusable.

    System-wide *.dll monitoring that doesn't interfere with system performance is a pipe-dream...
     
  3. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I hope you don't mind me also quoting this post meant for Peter. If you enable the option to block .dlls then it trashes your computer lol. It has always done this to mine anyway. My computer would usually become none responsive within 2 hours with .dll mitigation enabled. Most of the time I would have to do a hard shut down. I have not tried it in almost 2 years though.

    The last time I tried Faronics AE if I ran KillSwitch my computer would freeze immediately, and it would not recover most of the time with .dll mitigation enabled. It worked just fine as long as I did not enable .dll mitigation. I have a core i7 3.2 ghz with 8 Gigs of memory.
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Yes I have. It is no where as thorough as NVT ERP. The blocking of DLL does work, although the impact on the machine is horrible. Like running a speed boat with an anchor dragging. Then there is price.
     
  5. guest

    guest Guest

    i see, so we all have to wait Andreas release a finalized GUIed version of Smart Object Blocker ;)
     
  6. n8chavez

    n8chavez Registered Member

    Joined:
    Jul 19, 2003
    Posts:
    3,347
    Location:
    Location Unknown
    Is this project dead, or just being developed extremely slowly?
     
  7. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    It's an anti executable. There isn't a whole lot of development left. Just some bug fixes.
     
  8. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    But the product is as useful as ever
     
  9. n8chavez

    n8chavez Registered Member

    Joined:
    Jul 19, 2003
    Posts:
    3,347
    Location:
    Location Unknown
    I guess the thing I dislike about it the most, and correct me if I'm wrong, if that I don't like auto-whitelisting. Just because an app is safe doesn't mean I want it to run. I'm not getting prompted, which means I'm relying on their internal lists. I trust myself more.
     
  10. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Noticed an ever increasing uneasy buzz emanating from my daily laptop that I always use most to access everything including here. It's been noticeable to me for quite sometime so today I finally changed out the little lower storage HD (320Gb vs 500Gb) that is not exactly new but has seen little use (came with another laptop pulled off amazon that I replaced that HD with a 1TB Toshiba).

    Thanks goodness I didn't even have to turn to Macrium Reflect to restore the whole programs and shebang to it since it looks like I pretty well filled it with enough of my security and common use programs etc. and she booted up perfectly and all.

    However one crucial item wasn't installed yet, and that naturally of course was our NVT ERP. Got it done and done.

    NVT ERP for me and Windows 8(8.1) is a critical element that absolutely must be on my systems. It has and continues to work out great!
     
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    You can wipe the slate clean and make your own list. I would just be careful with the system stuff
     
  12. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Yes!
     
  13. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    But that depends on how you look at it. If you think an AE should do more then to block execution of malware delivered via exploits, then yes. But for monitoring app behavior, I rather use a HIPS that can monitor a lot more than only driver loading and DLL injection, like SOB or AppGuard.
     
  14. rpsgc

    rpsgc Registered Member

    Joined:
    Dec 29, 2005
    Posts:
    312
    Location:
    Portugal
    When I'm using ERP, my Windows keyboard layout gets automatically changed to English. Is there a way to stop that?
     
  15. guest

    guest Guest

    i am more for the first point. I expect it to just allow me to block exe/dll/drivers nothing more (hence my love for Appguard & SOB), i don't ask it to monitor every Parent-Children events of course, as you said , i have ReHIPS for that ;)
     
  16. guest

    guest Guest

    Yes, settings dependent.
    You get more alerts and are aware of changes (=good) after these settings are unticked.
    The latest update was "only" 2-3 months ago (NVT-Tool: Process Logger Service), but i think that too.
     
  17. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I use SpyShelter to monitor code injection, service+driver loading and recording of keystrokes and some other stuff. SS also monitors parent-child execution, but the problem is that you can not fine tune it. That's why I combine it with ERP.
     
  18. paulescobar

    paulescobar Registered Member

    Joined:
    Sep 22, 2008
    Posts:
    197
    Where can I find the latest version of this program?
    I maybe wrong about this, but I recall that the site does not contain the latest version...and links are actually posted in this thread.
    Any help would be appreciated.
     
  19. paulescobar

    paulescobar Registered Member

    Joined:
    Sep 22, 2008
    Posts:
    197
  20. guest

    guest Guest

    There is a newer beta-release, that was not mentioned before in this thread.
    EXERadar_Pro_x86_x64_v3.1_24062015_BUILD1.exe
    Only some weeks newer than the latest beta-release but it fixes one important thing:

    If you copy a whitelisted file to your administrator-directory (or c:\windows\temp) and execute it, you always get a "Unknown Application"-prompt, right?
    But it's whitelisted, there shouldn't be a prompt...
    Why is there a prompt? Because EXERadar.exe which has only Medium Integrity is checking the file. And it has no access to the administrator-directory = "Unknown Application"
    But with the newer release the Service ERPSvc.exe is now checking the file, which has sufficient rights (=System Integrity).
    Now there should be no prompt anymore for whitelisted files in such directories.
     
  21. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    can you post link?
     
  22. rpsgc

    rpsgc Registered Member

    Joined:
    Dec 29, 2005
    Posts:
    312
    Location:
    Portugal
    Direct link:

    http://downloads.novirusthanks.org/files/EXERadar_Pro_x86_x64_v3.1_24062015_BUILD1.exe
     
  23. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    thanks
    can you install it on top of previous version, and retain settings?
     
  24. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    first uninstall/save settings
    then install newer version
     
  25. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    Product version is the same.
    Size of new version is smaller then old one.

    Clipboard01.jpg

    Changelog:

    Clipboard01.jpg
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.