Win 10 compatible HIPS programs

Discussion in 'other anti-malware software' started by Banzi, Aug 13, 2015.

  1. Banzi

    Banzi Registered Member

    Joined:
    Oct 21, 2013
    Posts:
    397
    Location:
    Scotland
    Cheers. Do you have any examples of the wildcards you can post here? I did run it in learning mode for a couple of days but kept getting the rundll32 appraiser update alerts with random codes at the end of it, the alerts were popping up several times a hour.
     
  2. Banzi

    Banzi Registered Member

    Joined:
    Oct 21, 2013
    Posts:
    397
    Location:
    Scotland
    Cheers, could you post some examples of the wildcards as well? I kept adding them to the command line whitelist but due to the random code at the end of the command line they didn't stick. I would be willing to give the app another go as it was very light on resources & didn't slow things down.
     
  3. Banzi

    Banzi Registered Member

    Joined:
    Oct 21, 2013
    Posts:
    397
    Location:
    Scotland
    From what I have read about that app it seems to be a cloud multi AV. I already have bitdefender AV+ 2015 & it doesn't like there to be other security apps. Just found a video on youtube that is a review & prevention test, will watch that & see if it will be useful. Cheers for the tip.
     
  4. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,804
    Location:
    .
    Code:
    C:\Windows\system32\rundll32.exe C:\Windows\system32\GeneralTel.dll,RunGeneralTelemetry "C:\Windows\appcompat\appraiser\Telemetry\Appraiser_GenTelOutput.xml"
     
  5. Banzi

    Banzi Registered Member

    Joined:
    Oct 21, 2013
    Posts:
    397
    Location:
    Scotland
    Cheers Mister X, those ones you posted look similar to the one I was getting alerted to all the time. Will install Exe Radar Pro again & copy the command line or grab a screenshot of it so you can see what I mean about the random code at the end.
     
  6. taleblou

    taleblou Registered Member

    Joined:
    Jan 9, 2010
    Posts:
    1,349
    its everything. You can just get the version without AV. From my experience its solid and nothing can penetrate it.

    Here is my review of secureaplus.
    https://www.wilderssecurity.com/threads/my-review-of-secureaplus-on-windows-10.379046/
     
  7. Banzi

    Banzi Registered Member

    Joined:
    Oct 21, 2013
    Posts:
    397
    Location:
    Scotland
    @Mister X Sorry for the delay, when the alert is on the screen I can't run snipping tool untill I ok the alert.

    This is the type of alert I need help with the wildcards.

    I have also noticed that despite me running O&O Shutup 10 & disabling all the telemetry I still get alerts like this.

    Really appreciate the help with this :)
     
  8. Banzi

    Banzi Registered Member

    Joined:
    Oct 21, 2013
    Posts:
    397
    Location:
    Scotland
  9. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi Banzi

    To best help with ERP wildcards, post the string that you get, with two different versions, so we can see what changes

    Pete
     
  10. Banzi

    Banzi Registered Member

    Joined:
    Oct 21, 2013
    Posts:
    397
    Location:
    Scotland
    Sure Peter2150,

    That's the last two ones I have had, it's only the random code after noappraiser that changes each time.
     
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Try this:

    C:\Windows\system32\rundll32.exe invagent,RunUpdate -noappraiser *.4

    or this

    C:\Windows\system32\rundll32.exe invagent,RunUpdate -noappraiser *

    The both should work

    Pete
     
  12. Banzi

    Banzi Registered Member

    Joined:
    Oct 21, 2013
    Posts:
    397
    Location:
    Scotland
    Cheers, I have added them to the command line whitelist & will update the thread if they work. Really appreciate the help :)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.