New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    It is better that nvt checks this possible "issue".
     
  2. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,363
    Location:
    Italy
    @chris1341

    I could't test it yesterday, I quickly tested it few minutes ago and ERP was able to detect the execution of the setup file located in the RAM disk mounted at "M:", see this image: http://postimage.org/image/ojnrqkn0j/

    In the next version we may add an option "Automatically block processes executed from RAM Disks".

    When ERP doesn't detect new processes, in most cases, it means the AV or HIPS installed in the system is blocking ERP to do some things, for example, with ESET AV 6 you need to allow ERP to do file, registry and other modifications in the ESET HIPS module plus you need to add it in the AV exclusions list, example:

    http://postimage.org/image/9x2fjmgkz/
    http://postimage.org/image/9xlliockd/

    After these changes and a reboot, ERP will work without problems.
     
  3. chris1341

    chris1341 Guest

    Thanks NVT, I think it was maybe SBIE hangover as the Ram disc was (now is again) the location of the SBIE container.

    Really liking the Alert List and command line whitelist/wildcard changes. Very positive updates for those paranoid types like me that like to know what accesses these vulnerable/often exploited processes.

    I've added an SRP deny policy to the sandbox for now until you add that element in a future release.

    You should take a bow for the support you're providing and the improvements you're delivering at present. :thumb:
     
  4. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Possible issue:
    I have SSD.
    When Lockdown mode is enabled, it takes long time for notebook to shut down.
    With LM disabled, notebook shuts down in few seconds.
    I can make a test with measured times when I get home.

    Has anyone experienced this?
     
  5. molhopicante

    molhopicante Registered Member

    Joined:
    Aug 8, 2008
    Posts:
    135
    The problem never happened again.

    I do not know what was but maybe had been a coincidence.

    I'm still using free version and love it.

    In some days i will buy one license.
     
  6. chris1341

    chris1341 Guest

    Yes, significant difference on start-up too for me. I don't have SSD but Win 8 starts very quickly when not on Lockdown, 20 or so secs longer with. My issue with the app taking a long time to initialise after start-up only happens on Lockdown too I've found.

    Cheers
     
  7. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Chris, I'm talking about shut down time.
    ;)

    This looks random. Right now both shut down time are around 7 secs.
    But this afternoon, after I enabled LM, it was way over 20 secs.
    o_O
     
    Last edited: Mar 9, 2013
  8. AlexC

    AlexC Registered Member

    Joined:
    Apr 4, 2009
    Posts:
    1,288
    Quick question:

    I´m in Europe, can i use paypal to buy the software?

    Thanks
     
  9. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Seems like it should work. I believe NVT is in Italy.
     
  10. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,363
    Location:
    Italy
    @molhopicante

    Glad the problem is gone now :)

    @siketa

    May not be this, but when you shutdown the PC I think the process logonUI.exe should be whitelisted: http://postimage.org/image/ixo5za0lp/

    If it is blocked with Lockdown Mode then the shutdown can be delayed of few seconds.

    @chris1341

    I noted that in Windows 8 all apps are a little delayed compared to Windows XP or Windows 7. What is the last icon that is displayed in the system tray ? EXE Radar Pro or also icons of other applications ?

    @AlexC

    Sure, we support also PayPal, you can PM me for more information ;)
     
    Last edited: Mar 9, 2013
  11. chris1341

    chris1341 Guest

    ERP is always last but then I don't use real time AV, really only Sandboxie which has always been lightening in terms of start-up times and I'm careful about what I allow to start at boot. Win 8 boots very quickly in comparison to XP and Win 7 for me so I sometimes have to wait a little for the icons to appear but as noted ERP is the last by a considerable way. With the others protection seems to be in place even if the icon/GUI is not. Not the case with ERP although taskmanager shows the service running.

    Seems to be less when not in Lockdown but will take a number of times over the next few days to see if that stands up empirically.

    Thanks
     
  12. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    I always wondered if the creator of EXE Radar Pro uses EXE Radar Pro, or better yet...what he uses as his security setup.

    Just curious
     
  13. pablozi

    pablozi Registered Member

    Joined:
    Oct 24, 2010
    Posts:
    215
    Location:
    nowhere
    Hi,
    When can we expect fully functional trial version?
     
  14. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I think the best answer to this is a great line from the film "Masters and Commanders" when the captain asked the cook when something will be done, and got the answer "She will be ready when she is ready"

    NVT has already said it is fairly high on his priority, but didn't promise an exact date.

    Pete
     
  15. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    He is also working on a new web site, which is now totally redesigned.
     
  16. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,363
    Location:
    Italy
    @RADEON0101

    Of course we all use ERP in our PCs along with other security software ;)

    @pablozi

    Due to some important additions in v2.7.4, we plan to release ERP trial version after v2.7.4. As for the date, if all goes well, it may be released and ready in 1 week
     
  17. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Heck yeah, Nice :thumb:
     
  18. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    It would be strange if it were otherwise.

    anticipating...
     
  19. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    I wonder what that "other security software" are...
     
  20. arsenaloyal

    arsenaloyal Registered Member

    Joined:
    Nov 1, 2009
    Posts:
    513
    I have noticed the following things with the latest version in Windows 8 x64.
    1.Clear logs folder option under settings does not clear the logs folder,checked in admin as well as standard accounts.
    2.Restore lockdown mode if disabled for more than 5 mins does not work,lockdown mode is not restored back.

    And here is a suggestion that I would like to be included is to have option to clear logs on shutdown.

    thanks
     
  21. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Just finished testing on Win 7 HP x64.
    1. Clear logs folder works fine
    2. CONFIRMED! LM is not restored after 5 mins.

    +1 for clear on shutdown idea
     
  22. Trespasser

    Trespasser Registered Member

    Joined:
    Mar 1, 2005
    Posts:
    1,204
    Location:
    Virginia - Appalachian Mtns
    Hi,
    If you place rundll32.dll in the AlertList I've noticed that you'll get a lot of notifications about its activity. Has anyone came up with a solution (wildcard) to reduce these notifications? I get these rundll32.dll popups frequently. It's a bit annoying really.

    Thanks.

    Later...

    BTW, plus one for process termination protection for ERP. Also, can someone explain the function of Password Protected Processes. What would be some its uses?
     
  23. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    HI Trespasser

    First your right initially you will get a lot of Run32dll pop ups. But when you do select whitelist command string. Eventually you will get them all and they will stop. But it keeps RUn32dll from being abused.

    2nd the reason the password protection tab is there is if you look at the password protections they are all general. But say for some reason you don't want a specific process to be run, you can list it there and it will be password protected.

    an example. Suppose my computer is being used by someone I am okay with, but I don't want them to look at my Quickbook's data. I password protect that process and them nothing else is bothered, but they can't run Quickbooks without the password.

    Pete
     
  24. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    @Pete

    Can you explain this a little further and just exactly what needs to be done to accomplish it.
     
  25. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    CONFIRMED, same here (#2)

    +1 for your suggestion (Clear logs on shutdown)...Great idea!
     
    Last edited: Mar 13, 2013
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice