New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    That seems what he is doing with Build no.'s If you like the Anti-Exec concept, you will like ERP. Be sure to feel free to ask any questions.

    Pete
     
  2. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Thanks Pete, I appreciate that. I see a lot of value in Anti-Exec concept as an important security layer these days. From what I have seen so far, the developer seems extremely hard-working, talented and devoted.
     
  3. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Yes indeed, and some of ERP's features, like whitelisting command lines and use of wildcards in the command lines make this program extremely powerful. And you are correct Andreas is top draw as a developer.
     
  4. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    I uploaded a new beta build 19012015_BUILD1:
    http://downloads.novirusthanks.org/files/EXERadar_Pro_x86_x64_v3.1_19012015_BUILD1.exe

    To update:

    1) Close ERP from Trayicon->Exit
    2) Uninstall ERP
    3) Reboot the PC (very important)
    4) Install ERP and start ERP (make sure you accept the EULA and create the whitelists)
    5) Reboot (optional)

    *** Please test with cautious this build ***

    *** You can also switch ERP in "Learning Mode (Permanent)" before point 5) ***

    Let me know if you find any issues (everything should work fine, but just in case, I wrote the warning text).

    ERP should start even faster than the previous build when the PC is booted.

    @guest

    Ahah yes I remember that suggestion, I will try to add the lock icon soon :D

    @siketa

    A reboot is not always needed (now with the beta builds yes) with stable version, but I will see about this.

    @Enternal

    About your suggestions, they are planned for ERP v3.2 as it should integrate SQLite database to handle whitelists/blacklists, so it should support pagination, sorting, searching, etc :)

    @bjm_

    Thanks for the update.

    It is stable, it protects EXEradar.exe and ERPSvc.exe from being terminated by other applications.

    @ichito

    "Allow Mode" allows all processes executions and blocks processes present in the blacklist.
    "Learning Mode" allows any process execution (except blacklisted ones) and automatically add the allowed processes to the whitelist. This is useful to populate the whitelist after ERP has been installed, you can switch to "Learning Mode" for like few hours, so all applications that run are auto-whitelisted.
    "Lockdown Mode" has now 3 options in Settings->Lockdown Mode (they are the old basic, medium, advanced mode)

    @WildByDesign

    I would recommend you to try for the first time ERP by using the previous beta build (that worked fine for all other users):
    http://downloads.novirusthanks.org/files/EXERadar_Pro_x86_x64_v3.1_17012015_BUILD1.exe

    Feel free to post here if you have any questions about ERP usage :)
     
  5. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi Andreas

    On that Learning mode text on the upgrades. I really apply at step 0. I want it in learning mode prior to uninstalling the build being replaced.

    Pete
     
  6. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Thank you Andreas, much respect. I also appreciate that you recommended that build that is known to be more stable for my starting point with ERP. So far, everything has been a fantastic experience. The amount of options/settings available is a dream come true for users like myself who like to tinker with software.

    Just a couple of quick questions, if you have a moment.

    • I noticed the setting for 'self defence against process termination' which is a great feature. Why is that not enabled by default?
    • Does ERP have an option to filter/block for .DLL and .SYS file?
    Thank you for your time, I appreciate that very much.
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I have not yet tried the newest version, but in the older version (the one from the PM) I noticed that new apps added to "vulnerable processes" are not remembered after reboot, perhaps others can check. Another thing which annoys me a bit, is that colum-size and sorting is also not remembered. And I still hope that you will add separate entries for "alert" and "lock-down mode", in the tray context menu.
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    That's the weird thing, ERP does indeed seem to be working correctly. And the reason why these programs can not list the ERP drivers, is because Windows 8 itself can't do it, so there is definitely something wrong. It's almost like the drivers are NOT loaded at all, even though I can see them in the C:\Windows\System32\drivers folder.
     
  9. Charyb

    Charyb Registered Member

    Joined:
    Jan 16, 2013
    Posts:
    679
    I will have to bow out of testing. I can't keep up with this.
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    GMER, can see the drivers, but they don't have a startup type, so I have no idea how and if they are running. What should the startup type be? Should it be: Boot, System or Auto?

    http://www.gmer.net/
     
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Very easy way to tell if the drivers are running. Does ERP work? If it does the drivers have to be running. And it does work.
     
  12. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Andreas, I know have the last build running on 2 win 7 desktops 1 win 7 Lenovo laptop and 3 vm machines (w7,w8.1 and w10) Well done.

    Pete
     
  13. Defenestration

    Defenestration Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    1,108
    Thanks for adding some of my sugested features.

    Re. the new option to save only events of blocked applications, can you change it slightly so that when enabled, it still shows Allowed events in the Events list tab, but only saves the blocked events to the file. This is because I am only interested in seeing blocked events in the log file (in case of a problem), but still want to be able to see all events (Allowed AND Blocked) in the GUI (so I can check what has ben allowed/blocked).
     
  14. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,997
    Location:
    Poland - Cracow
    Thanks NVT for clarification :thumb:
     
  15. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Andreas, you said ERP will become completely free.
    Are you considering to remove "Pro" from its name?
    I'm already used to ERP acronym but many users could get it wrong and think it is paid software.
     
  16. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Why can't a free version have the Pro name?
     
  17. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Who said it can't?
    It's just not usual....
    What does Pro stand for anyway?
     
    Last edited: Jan 20, 2015
  18. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Pro ...professional ;)
     
  19. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Hehehehe...I know that...my point is that "Pro" version is paid and we had "Free" version as well.
    Now, when we know it will become freeware, there is no reason to have that acronym any more (in case Pro was used only to distinguish between versions)....
     
  20. javagreen

    javagreen Registered Member

    Joined:
    May 2, 2005
    Posts:
    96
    When is ERP going to become free? If I install one of the builds from here, will it expire? I know it says beta, I'm assuming they will expire after a few days?
     
  21. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes, but that still does not explain why the drivers are not officially registered. I do know that some apps like GMER and Process Monitor load their drivers temporary, but that does not apply to security tools that need to run in real time, all of the time.
     
  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I can see them on my system. Instead of focusing on this stuff why not test and see if the program works.
     
  23. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @WildByDesign

    Great :)

    1) Because not all users want this option enabled, so I left it disabled by default.

    2) No, ERP only monitors process executions, it does not monitor for loading of DLL or SYS files.

    @Rasheed187

    I checked your two tools about the drivers not visible in their lists, and that should be normal as ERP does not install the kernel-mode drivers but it loads them directly from the service. Instead, the drivers will appear in our tool "Kernel Mode Drivers Manager" ( http://www.novirusthanks.org/products/kernel-mode-drivers-manager/ ) because it lists all loaded kernel mode drivers running within the system and their load order.

    @Peter2150

    Great! Thanks a lot for the testing.

    @Defenestration

    I will add the option to save only blocked applications in the log file.

    @ichito

    You're welcome ;)

    @siketa

    We need to think about it, not sure if we'll remove the Pro text, however it is yet to decide and we'll take into consideration your suggestion about Free/Pro text.

    @javagreen

    Theorically from stable v3.1 version, but again not 100% sure.

    Not these betas, they have no expirations.

    //Everyone

    Are there also other users that are running the last build ?

    I'm interested in knowing if there are any issues with that :)
     
  24. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    I'm running it on Win7 x64 SP1 and so far so good.
     
  25. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    Running fine on Win8.1x64:)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.