New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Huh, very interesting, thank you

    What are your settings set to?
     
  2. First I did not understand what you were saying with "I trust most of what's on my system" and at the same time you lock applications in a LUA-jail (AppGuard) and put them on hand-cuffs (Exe Radar Anti-Executable). When this is how trust looks like, how would . . .

    Then the meaning of "so I let those things do what I want" dripped through my brain and everything became clear with a big grin. :D
     
  3. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    On the General Tab . the first and last box
    on the advanced tab nothing ticked
    Settings Tab Disable idle prompt 5 minutes and block once
    Policies Nothing checked
    Pop ups Both boxes checked, 10 seconds
    Passwords Nothing
    Protection Restore Realtime after 5 minutes
    Nothing on Stealth and Paths
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I can see where this might seem confusing. Let me take a shot at it.

    WHen you install something like Outpost Firewall, it goes thru and makes different rules for the software it finds. Also there can be different setting for the firewall It's Antileak section puts different rules on different process interactions.

    So since I trust software I've put on the system, I go thru those outpost settings, and make the network access all everything, and I go thru all the Antileak settings and allow all actions.

    Now that other piece of software common sense kicks on. There is software that can be exploited. Adobe Reader comes to mind. While in some respects I trust it, it can be exploited. So common sense says protect the system. I run Abode as a guarded app in Appguard. That way it can do what it needs, but is blocked from the system area's which it should never need to go.

    Java is a better example. It unfortunately not trusted, so run it guarded in Appguard, so it can't tamper with the system, and I've removed it from ExeRadarPro's whitelist. This way I know whenever it wants to run, and have the option to let it run or not.

    Does this make sense.

    Pete
     
  5. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    Pete you don't get a lot of pop ups from a setting like this?
    Also are you in lock down or just under protection?
     
  6. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Thanks Peter :thumb:
     
  7. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    Not really. I'll get a pop up when Rundll32 does something. If legit I whitelist the command line, and that's it. Also there are a couple of things like RealPlayer which I do use, so I've taken it's updater out of the whitelist, and when it first pops up, I block it, and then tick the box to not show that pop up again.

    I am just under protection. I don't use Lock Down, because of my approach of wanting the option to run some things.

    Pete
     
  8. smith2006

    smith2006 Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    808
    Thanks for the reply.

    It seems like NoVirusThanks EXE Radar Pro is not protecting.

    I have tried adding a process to BlackList & I could still run it. There is no prompt or event in the Events Log.

    I do not have this problem prior to this or 1 version earlier.
     
  9. smith2006

    smith2006 Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    808
    The whitelist is not empty.
     
  10. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    I think he was talking about Events, not Whitelist...
     
  11. Yep got a simular line of defense using Windows Pro features (got an Ultimate, but also find AppGuard to much hassle)

    1. Use Protected mode of IE and Low/Untrusted Intergrity of Chromium, to seperate everything in proces from the rest of the system

    2. Deny execute on shared, download and media folders for Everyone (ACL) and block autorun/deny execute access to USB's (GPO)

    3. Deny execute on everything outside Windows & Program files on all files for all users except Admins (SRP), so still can install with right click "run as admin".

    4. Deny elevation of unsigned programs (Chromium, Classic Media Player, Evince-PDF, 7-ZIP) through UAC. Gave Outlook a mandatory Medium Level Integrity with icacls.

    I just found the "trust most versus I let them do what I want" humereous way of describing a tight deny execute (NVT)/deny elevate (AG) policy, considering you have SBIE at hand to use as Sandbox. So IMO your setup is build around the same principles, only your implementation is the fort knox version of mine.
     
    Last edited by a moderator: Mar 4, 2013
  12. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Unofficial Todo/suggestions list for future ERP versions:

    1. Update of Help File
    2. Automatic uninstall (without waiting for service shutdown)
    3. Alert popup optimization (https://www.wilderssecurity.com/showpost.php?p=2180495&postcount=1376)
    4. Internal updater
    5. Auto refresh of Processes tab (without changing tab view)
    6. Auto alphabetical order of processes in Processes tab
    7. Make "CPU" column in Processes tab (show usage like in Task Manager)
     
  13. therube

    therube Registered Member

    Joined:
    Oct 5, 2012
    Posts:
    63
    Location:
    USA
    > then I whitelisted ... Documents and settings

    Wouldn't that generally be a poor decision?

    D&S is a place open to you.
    Therefore a place where malware could drop something.
    And if something is then dropped into D&S & as you have allowed anything therein, you have then given given malware a foothold on your system.

    I would expect no, & would want no executables within D&S, unless perhaps you save downloaded programs on your desktop or something like that.
     
  14. DBone

    DBone Registered Member

    Joined:
    Nov 24, 2010
    Posts:
    1,041
    Location:
    SoCal USA
    For max security without a real time AV I went a different route. This is how I run on a known clean machine (base system re-image with only OS, updates, drivers and ERP is first program installed) This procedure can also be used on a seasoned machine, as long as it is known clean.

    1 After install, select NO to add system protected processes.
    2 Right click tray icon and select add running processes to White list.
    3 uncheck automatically allow system protected processes and auto allow program files in settings tab. Uncheck hide the popup, so you have to manually close it. Check play sound (your choice).
    4 Reboot.
    5 I let the machine idle for a period of time and I white list any pop ups that I get. Usually 5-6
    6 Start to "use" the machine and white list any popups. Right click desk top, windows update, task manager, WMP, IE, control panel, reboot, sleep, ect, ect... Usually 20-30 popups.
    7 Reboot, let idle again for a short time, use the machine again by doing anything that I can think of (except CMD, I don't white list that) and white list anything that I forgot to do earlier.
    8 Install all my software, and white list once installed. (I install with ERP OFF, as I know all of my programs/installers are clean. Things like CCleaner Portable, Chrome, MBAM, HMP, ect..)
    9 Leave in default mode NOT lockdown.


    Yes, this setup isn't for everyone, and it does take about 90 minutes, but at the end of the day, nothing else will ever run that I am not alerted to, and since this is my one and only line of defense, it's how it has to be. Do expect 2-3 rogue popups for the next 72hrs. Leaving your machine running over night will reveal these.

    This in my opinion is the most secure setup. Also, my machine is only used by me and never anyone else.
     
    Last edited: Mar 4, 2013
  15. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Problem I have is there are a couple of good programs I have, that install in the Docs and Settings area. I don't run that all that often. I don't worry about the vulnerability aspect, as Appguard protects that area.

    But thinking about this, I may just change that and take that whole area off the white list.

    That's the beauty of interacting here on Wilders.

    Thanks therube.

    Pete
     
  16. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,014
    I was under the impression that whitelisting Docs and Settings would only whitelist the executables in that area at the time of the whitelisting, and not just blanket whitelist the entire folder. So wouldn't anything dropped in there and executed later, still get you a popup and blocked? Or am I understanding how it works incorrectly?
     
  17. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Well I went back and took a look at this. A lot of harmless stuff like installers did get whitelisted, but to clear it out would be time consuming, and in the end not accomplish much. Let me explain

    First the only way a new program could land there is if it came either by Browser or Outlook Email. Sandboxie wouldn't stop that, but it would stop execution and it would stop entering autostart entries.

    But if it should find its way Sandboxie, Appguard wouldn't let it run without deliberately lowering protection....

    But even if it should be by Appguard, since it is new and not whitelisted it will thru an ERP pop up, where it can be blocked.

    Bottom line.... I am not worried.

    Pete
     
  18. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    See my response post. You are indeed correct.

    Pete
     
  19. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,014
    Ok, very good. Thanks Peter. :)
     
  20. arsenaloyal

    arsenaloyal Registered Member

    Joined:
    Nov 1, 2009
    Posts:
    513
  21. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    @NoVirusThanks:

    I've been working on a concept for the EXE Radar Pro popup window, tell me what you think.

    Maybe this will give you some ideas


    Here they are:

    With the Process Execution indicator (Orange Bar):
    ERPPOPUP.jpg

    Without the Process Execution indicator (No Orange Bar):
    ERPPOP.jpg

    Plus, I was thinking...would it be better to place the popup window in the lower right-hand corner of the screen, instead of the center of the screen?

    Anyways, I hope you like it :D :thumb:
     
  22. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Great work! :thumb:
    I prefer first option cause orange color means: take it seriously!

    Since you obviously have a talent for art, try next:
    Make it smaller so it would consist only important informations.
    Other infos should be in additional or expanded window.
    Make an arrow or a link to open it.
     
    Last edited: Mar 4, 2013
  23. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Thanks, I appreciate that :D
     
  24. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    On my machines it is in the lower right hand corner of the screen. But there are a few issues with multi monitors, and with my big high resolution screen there is also an issue. NVT is aware and is working on them.

    Pete
     
  25. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Such kind words, thank you for that


    What would you consider important?

    Process, Path, Description, Signed for main?

    Then the rest of the info when a user clicks More details....

    Bitness, Cmdline, MD5 Hash, Parent, Publisher?

    So, kind of like a link text that say's More details..., then it expands more info when a user clicks it?

    EXAMPLES:​


    Basically, something like this?

    Main popup (Less info):
    ERPPOPUPsmall.jpg

    Expanded popup (When clicking More details...)
    ERPPOPUPLarge.jpg

    These are just concepts, it's up to the developer on how he wants to implement dimensions, info, placement, etc....
     
    Last edited: Mar 4, 2013
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.