New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Right click the system tray icon to change them
     
  2. controler

    controler Guest

    Cool thanks

    Is that ins the help file? It sure isn't mentioned in the main GUI.

    Also what does the import/export restore default lists do?


    Also how do I Enable Process Behavioral Analysis Technology.
    Thanks
     
    Last edited by a moderator: Jan 5, 2014
  3. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
  4. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    Why did they remove that feaure? Seemed like it worked well.
     
  5. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Andreas thinks it is not needed.
     
  6. guest

    guest Guest

    not needed and will makes the soft heavier
     
  7. Nebulus

    Nebulus Registered Member

    Joined:
    Jan 20, 2007
    Posts:
    1,635
    Location:
    European Union
    I installed today NVT Exe Radar Pro 2.7.7 build 25 and I came across the following situation: few minutes after installation and after validating the license, when I tried to start a certain application, my firewall warned me that EXERadar.exe is trying to connect to internet. I had updates notifications disabled, an empty trusted vendors list and I selected not to allow signed processes. The bigger problem is that I wasn't able to start any other applications until EXERadar Pro decided that it cannot connect to the internet and gave me back control! My questions:

    1. Is this a bug?
    2. Is this internet connection the normal behaviour?
    3. Is it something in the configuration/settings that I missed and that can disable this connection completely?

    Thanks!

    Later edit: It seems that EXERadar requests a list of certificates, despite the settings. That would be fine, but applications cannot start (the computer is effectively blocked) until the communication is complete. That is not an ideal situation, especially when the internet connection is poor.
     
    Last edited: Jan 10, 2014
  8. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @Nebulus

    When a process is executed in the system, ERP checks the certificate (if the exe is signed), an example of HTTP query is like this:

    Code:
    GET /pca3-g5.crl HTTP/1.1
    Accept: */*
    User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
    Host: crl.verisign.com
    Connection: Keep-Alive
    Cache-Control: no-cache
    Pragma: no-cache
    
    How many seconds does it needs in your PC to execute the GET query ?
     
  9. Nebulus

    Nebulus Registered Member

    Joined:
    Jan 20, 2007
    Posts:
    1,635
    Location:
    European Union
    Yes, I used Wireshark to determine that your application is requesting a certificate.

    Under normal circumstances, it doesn't take too long, but if I block it from firewall or if I have no/poor internet connection at the time, it takes around 40 seconds until it gives up connecting and it presents me to a prompt to choose if I want to block or allow running the application. Is there no way to disable this behaviour and to show me the prompt directly, without checking for a certificate first?
     
  10. NVT documentation mentions it applies a whitelist of command strings.

    Does NVT interpret the command line string of vulnerable processes with location or origin info of the executable?

    E.g. it would be much easier to allow command strings referring to safe locations (e.g. Windows and Program Files) and to block command strings referring to executables which come from the internet (using default Windows mechanism).

    Regards Kees
     
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    The command string that is whitelisted is the one presented to run at the time. If a command string is presented from something just downloaded and being installed one would wisely use allow once.
     
  12. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    Just a quick question concerning the version 3 betas and release to come. The last version that I see is build 13 from November 28th. Since then I have seen posts referring to a Windows 8.1 bug or two followed by a reply that it had been fixed in the next version to be released in a few days. I am wanting to install ERP on a Windows 8.1 machine but want to wait for the version 3 that has these bugs fixed. Is there a later version than build 13 that I have missed and if not, is a new version coming soon? I do not mean to seem impatient but with replies stating a new version was coming in a few days (and now it has been a while) and the fact this next version seems to be taking longer than in the past (yes, I realize the holidays), I was wondering if I had missed something or could get a staus report. Thanks as I look forward to trying this version on a new 8.1 machine...
     
  13. ruinebabine

    ruinebabine Registered Member

    Joined:
    Aug 6, 2007
    Posts:
    1,096
    Location:
    QC
    Build 13 is the last publicly known build. Very stable here on 7x64.
    Can't be of help for systems running 8.1, so good luck with it.
     
  14. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    Thanks for verifying. I was fairly sure build 13 was the latest and just did not want to install a version with any known 8.1 bugs on the new machine. I can wait for the next release with the fixes.
     
  15. sg09

    sg09 Registered Member

    Joined:
    Jul 11, 2009
    Posts:
    2,811
    Location:
    Kolkata, India
    Bug Report
    ERP Pro does not understand my Calender Settings and greets me with an alert on startup. Windows 8 Pro 64 bit. Thing started after I changed the date settings. See below

    3.png

    1.png

    2.png
     
  16. Fair, just wondered whether NVT would help by assessing location and origin
     
  17. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Any news about release date?
     
  18. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    +1 on this
     
  19. mattdocs12345

    mattdocs12345 Registered Member

    Joined:
    Mar 23, 2013
    Posts:
    1,892
    Location:
    US
    How to force NVT ERP to recognize all programs in the Programs Folder?
    I have installed ERP and I checked the following options:
    • Allow Microsoft Windows system protected processes
    • Allow processes signed by Trusted Vendors
    • Allow all software from Program Files folder
    But after I started Vsee, NVT ERP asked me if I wanted to allow the process... This is bad, I need NVT ERP to recognize ALL software in Program Files and never ask me again. How do I do it?
     
    Last edited: Jan 12, 2014
  20. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Go to the menue and select scan. There first tick the do subdirectories box. Then select the program files directory and scan. Do this for program files, Program files(x86) and windows. This will whitelist everything.

    But be aware the vulnerable processes like run32dll and cmd will still alert you until you whitelist the command line.

    Pete
     
  21. mattdocs12345

    mattdocs12345 Registered Member

    Joined:
    Mar 23, 2013
    Posts:
    1,892
    Location:
    US
    Thank you. But is there a way to whitelist all vulnerable processses?
    Im setting this up for a family member and I can't have anything popping out. I just don't want him/her to install any new software or run any malware.
     
  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Take him/her thru everything they can do. That way you will catch all the things some of the vulnerable processes and whitelist the command string. These will no longer bother you. Then set up a strong password, and password protect all the actions. That will lock them down.
     
  23. mattdocs12345

    mattdocs12345 Registered Member

    Joined:
    Mar 23, 2013
    Posts:
    1,892
    Location:
    US
    Can you clarify this?
     
  24. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    yes cmd.exe is one of the vulnerable apps and if you use Sandboxie, when the sandboxes is closed and set to delete, it uses a string with cmd.exe. Normally you would get a pop up every time. To make it worse each string is unique because it has a random 16 digit number.

    if this is whitelisted

    C:\Windows\system32\cmd.exe /c rmdir /s /q "?:\*\__Delete_*"

    then any time Sandboxie deletes the sandbox some form of this string isused, and since is whitelisted with *'s you never get an alert.

    Also this string is whitelisted by default when you install.

    Pete
     
  25. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    I just noticed that for some strange reason, ERP hasn't created/saved any Log folders since 12/31/13 - and I haven't changed anything. Any thoughts on this?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.