New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,805
    Location:
    .
    Someone here, a trusty member for me, told me ERP cmd line scanner was hard to read in the logs and sometimes it didn't catch all processes. I didn't test that by myself though. @novirusthanks should know if it will or it's been already improved in new beta version.
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Just did a test of a piece of malware that is a script instead of an exe. ERP, caught as all the vulnerable apps are in my settings. First alerted on Wscript. It showed the script which had a powershell embedded. I allowered it and it alerted on Powershell. I blocked that. Seems fine to me.
     
  3. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,805
    Location:
    .
    Fair enough.
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    BTW, I noticed that after updating Flash Player for Opera/Vivaldi, now cmd.exe gets blocked by ERP every time a Flash video get loaded. Did anyone notice this, and I supposed this isn't normal right?
     
  5. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,879
    Yup. If you see a legitimate running instance blocked in the event viewer, whitelist it.
     
  6. guest

    guest Guest

    It depends on the command-line and maybe you need to whitelist the command-line if you want to watch a video without an alert.
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I forgot to look at the command line. It only happens when I switch off the Vivaldi sandbox, apparently the Flash player notices that it's not being sandboxed, but I don't see why it needs to run cmd.exe, I will continue to block it.
     
  8. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Is there any way to import a vulnerable list and not add every application manually? I.e. https://excubits.com/content/files/blacklist.txt

    Or can anyone provide me with a good blacklist for vulnerable applications I can import in settings?
     
    Last edited: Jun 27, 2017
  9. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    It's not possible AFAIK, but it's a good idea.
     
  10. guest

    guest Guest

    There is no such feature because there is no reason to have it, you import ERP settings into ERP, not settings from other softs.

    The only way it could works is to import them from a .txt file. (a bit like Emsisoft web filter allows importing sites from a custom host file)
     
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    The list he wants to import is in a text file. But I don't think a lot of it is needed, and some of it could break things. Manually load a few and test.
     
  12. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,805
    Location:
    .
    Think that's not gonna work. ERP needs to hash the executable. For this to happen ERP needs you to open the browse (file explorer) function, select the exe, one by one, and it will add it to the vulnerable section along their hashes.
     
  13. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    You are right. Been a while for me.
     
  14. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Was @shadek maybe not asking if he could use someone else's exported file, someone who has already added all those vulnerable apps?

    But I guess all other white/blacklists would have to be reset, and other settings examined. Plus the hashes of the vulnerable apps may not correspond. So too tricky, I'm sure. Better to start from scratch, even if it is time consuming.

    Anyway, I would wait for ERP 2.0.
     
    Last edited: Jun 29, 2017
  15. guest

    guest Guest

    so do i. It will be the only one real anti-exe left, simple, granular, efficient and without useless features.
     
  16. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,805
    Location:
    .
    IMHO, it's time for Andreas to implement a new feature to import exes file names from a list, ERP will parse it and retrieve the filenames, browse for them in batch, add them in batch with hashes, path, date, etc., automatically.
     
  17. guest

    guest Guest

    Could be done easy , since you can scan a folder , why not read a txt file...question is " does classic users of ERP will need it so would it be worth it?" only Andreas will tell :)
     
  18. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,805
    Location:
    .
    I can tell too!: Yes, it's worth of it. :D
     
  19. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    :thumb:
     
  20. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Thanks everyone for replying!

    For me it's too troublesome to manually add all vulnerable processes. I just wondered if there was an easy way to do it, but it seems there is not. I suppose the default vulnerable processes will do.
     
  21. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,805
    Location:
    .
    It will. Not if you are kind of picky with security. I spent a year ago several hours adding and classifying vulnerable processes to have an easy to read list within ERP.
     
  22. Charyb

    Charyb Registered Member

    Joined:
    Jan 16, 2013
    Posts:
    679
    I wonder when the beta is going to be ready?
     
  23. guest

    guest Guest

    Remember only few security forum members like us knows about what are vulnerable processes and what they do, others don't have a clue of what we are talking about.
     
  24. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    This is going to sound brash, and I only mean it with expressing anticipation, but sure wish and hope it comes through soon.

    And the best part of ERP is it has performed top honors alongside every other security software that I run in tandem along with it like Ransom0ff + Comodo FW 10 etc.

    I don't do voodoo or maleebytes not because they aren't to expectations but have taken (as I always do) a different route to applying layers that work best together on this end as currently set up.

    ERP is the Watcher and Stopper anti-exe for me even if it does overlap a bit with others. Two heads are always better than one.
     
  25. Circuit

    Circuit Registered Member

    Joined:
    Oct 7, 2014
    Posts:
    939
    Location:
    Land o fruits and nuts, and more crime.
    I hope plans are moving ahead.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.