New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. therube

    therube Registered Member

    Joined:
    Oct 5, 2012
    Posts:
    63
    Location:
    USA
    ERP is using Themida ("protections")?
     
  2. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,363
    Location:
    Italy
    @guest

    I already added it to v2.7.5 ;)

    @Trespasser

    Probably that issue is caused by the protection system, I will install EMET and test it. Thank you for reporting the issue.

    @puff-m-d

    The option to keep the protection was disabled in v2.7.4 but will be re-introduced in v2.7.5 that will be released in few days.

    @MRF71

    Sure, you can whitelist that both commandline strings, they are safe.

    @therube

    Yes, that is used to protect the main PE files.
     
  3. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Yes, I would whitelist them. Let me tell you my approach.

    First I know my system is clean. So when I take an action like change a display property, that generates one of those alerts, I automatically whitelist it. You have other protection so you are fairly safe. As these alerts occur you will notice the correlate to an action. Whitelist them. After a short period you will get most them and the alerts will stop. Then when you do get an alert take a closer look and if not sure block once, and ask.

    Pete
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Update on the Sandboxie, OA conflict when using NVT. Tzuk has come up with a fix. But there are some limitations users should be aware of so please read this thread.

    -http://www.sandboxie.com/phpbb/viewtopic.php?t=15095-

    Pete
     
  5. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Finally I encountered on the trial. Trying it on 2 PC. :D
     
  6. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    I see that the bug that PC freezes when you go between accounts is resolved.

    That's good that there's an option to start in stealth. I like it. I didn't find an option to start in Lockdown Mode. Or I missed it?
     
  7. guest

    guest Guest

    in the Settings > Policies
    when set on lockdown, now ERP keep it for every subsequent boot, until disabled.
     
  8. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    thanx
    then it must be the same when you check the Lockdown Mode in the tray icon
     
  9. simmersK00L

    simmersK00L Registered Member

    Joined:
    Mar 20, 2013
    Posts:
    323
    Location:
    USA
    Has there been any discussion about NVT ERP phoning home about every 4 hours. It seems to stay connected unless I kill the tcp connection, but then it auto establishes the connection again & again. Support says it's to validate the license, ok... But seems odd that ERP needs to repeatedly do this. Have not taken the time to check the packets, but I find it a tad "unnerving" for a security app to do this without documentation or the user's ability to disable it. (I suppose there may be some registry edit to disable it). Would appreciate your thoughts about this.
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Not all that unnerving, given the tendency of piracy in software, and the inexpensive price of this program. Piracy would kill it dead.

    In the end it's about trusting the authors, and that I do!

    Pete
     
  11. mattdocs12345

    mattdocs12345 Registered Member

    Joined:
    Mar 23, 2013
    Posts:
    1,892
    Location:
    US
    I do trust the authors. I don't like the software phoning home. On the side note, I am one of the early adopters of NVT ERP. I have to say that developers did put long hours of hard work to polish out some bugs and annoyances and make this software as mature as it is right now. So I am just going to close my eye on this one minor issue.
     
  12. guest

    guest Guest

    i dont have this "call home" issue, so i think it is an individual problem.
     
  13. mattdocs12345

    mattdocs12345 Registered Member

    Joined:
    Mar 23, 2013
    Posts:
    1,892
    Location:
    US
    im not a firewall expert. can anyone else confirm this?
     
  14. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    I installed trial version in SUA, win-7. When I enter Admin account it says it has expired though it is too early. It must be a bug.
     

    Attached Files:

  15. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Have you changed system date?
     
  16. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Of course no! Right now I entered the admin account to check that the both dates are the same.:) And they are the same. :D And ERP again informed that it has expired in the Admin account. In SUA it works OK. :eek:
     
  17. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Since trial is new feature I guess it is a bug cause it has not been tested on many systems.
     
  18. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    If NVT needs some logs, IDK what else, I can do this, only describe what buttons I should press.
     
  19. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    HI SimmersK00l

    Has your question been answered.

    Pete
     
  20. 0strodamus

    0strodamus Registered Member

    Joined:
    Aug 23, 2009
    Posts:
    1,058
    Location:
    United Surveillance States
    I noticed port 80 outbound attempts to a novirusthanks IP via the "system" process which I assumed to be coming from SwiPEInjDrv.sys. This was post-activation and seemed to happen at random times. Because of the conflicts I had, I removed ERP from my system and don't have the firewall logs anymore to reference. You're not alone in your observations or opinions related to this. I saw it too and I also didn't much care for it.
    I noticed right after installation, I would get a trial expired unless I launched EXERadar.exe as administrator. Kind of the opposite of what you observed (I'm assuming SUA means standard user account).
     
  21. mattdocs1234

    mattdocs1234 Registered Member

    Joined:
    Mar 22, 2013
    Posts:
    1
    Location:
    NY
    So i guess the question is now what will happen if i dont connect my computer to the internet for a week or so. Will nvt erp stop working?
     
  22. Seven64

    Seven64 Guest

    I e-mailed the company, and the reply was he would fix this "call-home" in the next version. I have it blocked with my firewall with no side effects.
     
  23. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Yeah, SUA stands for stand. user acc. I explored the issue, it seems like yours:
    1. It works in SUA OK.
    2. In Admin account:
    2.1 it starts automatically and says expired.
    2.2 If I start ERP not as admin then it says expired.
    2.3 If I start ERP as admin it works there OK.
     
    Last edited: Apr 26, 2013
  24. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,363
    Location:
    Italy
    @Solarlynx

    Thank you for reporting that issue with the trial version. I will try to reproduce it today and I will keep you updated.

    @mattdocs1234

    If your PC is not connected with Internet it will not check for the license and ERP will continue to run normally. When ERP (PRO version) detects an Internet connection active, after N hours, it tries to check the validity of the license. It should take no more than 1 or 3 seconds to check it.

    @Peter2150

    Thanks for the update about SBIE v4. I will take a look at it.
     
  25. pablozi

    pablozi Registered Member

    Joined:
    Oct 24, 2010
    Posts:
    215
    Location:
    nowhere
    Are there any plans to implement auto update feature in the nearest future?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.