New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. dja2k

    dja2k Registered Member

    I started getting this pop-up a few minutes ago and never seen it before. I am running on Lockdown Mode (Extreme). I know its a Microsoft executable, but odd that the executable says that its not signed. Anyone seen this before?

    dja2k
     

    Attached Files:

  2. novirusthanks

    novirusthanks Developer

    @iammike @guest

    I could reproduce that issue, I'll check it tomorrow morning.

    @dja2k

    Some MS processes are, unfortunately, not digitally signed.

    The process, located in the folder displayed by ERP alert, is a safe MS process, you can whitelist it without problems.
     
  3. Defenestration

    Defenestration Registered Member

    - To allow the information to be copied to clipboard, can you use a read-only editbox for the Path, CmdLine and Parent fileds on the alert dialog.

    - I noticed there was a delay when starting processes, and narrowed it down to ERP checking the digital signature. What is causing the delay, as the UAC prompt seems able to determine if a process is signed much quicker than ERP ?

    As I don't trust processes just on the basis they're signed, I enabled the option "Disable the checking for digitally signed processes", which gets rid of the delay, but means the "Signed" field on the alert dialog just says "(Disabled)".

    I understand you may not be able to check if the certificate is valid, or has been revoked without a delay, but is there any way to do a quick check to determine if a process is signed, so the alert dialog can show this information (along with signing identity) ?
     
  4. guest

    guest Guest

    using the function "Search hash on VT" maybe. ERP has no cloud unfortunately (or not ^^)
     
  5. Defenestration

    Defenestration Registered Member

    I mean how ERP checks the signature internally, so it knows whether a process is signed or not.

    BTW, the delay appears to be more noticeable the larger the exe file.
     
  6. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    I experienced the same delay before being prompted for an action.
     
  7. novirusthanks

    novirusthanks Developer

    @Defenestration

    Sure, that can be added, we can also allow right-click over the item in the alert dialog, but maybe it is better with read-only editbox.

    @Defenestration @Cutting_Edgetech

    ERP checks if the file is signed but it also checks if the certificate is valid, for big files it may need some seconds to create the certificate checksum and check it online. It would be useless if it only check if the file is signed (without checking the validity of the certificate online). With this option disabled, there should be no delays (except if a file is, for example of 50MB, it can take some time to generate the MD5 hash, but only that).
     
  8. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    I would prefer to just disable it then since I don't trust software based on whether it is signed, or not though it can rule out a lot of viruses since they are rarely signed.
     
  9. novirusthanks

    novirusthanks Developer

  10. Peter2150

    Peter2150 Global Moderator

  11. novirusthanks

    novirusthanks Developer

    Thanks Pete :D
     
  12. Peter2150

    Peter2150 Global Moderator


    No problem. ERP truly is a 5 star piece of software.
     
  13. jmonge

    jmonge Registered Member

    this program is like Gold:thumb: :thumb: PURE GOLD
     
  14. Q Section

    Q Section Registered Member

    ---> novirusthanks

    Quite a few pages ago you said you would check your programme against stuxnet and report back. The 'report back' was not found. What happened when you tried it?

    Best regards
     
  15. Overkill

    Overkill Registered Member

  16. siketa

    siketa Registered Member

    Voted 5 stars. :D
     
  17. guest

    guest Guest

    same here ^^
     
  18. iammike

    iammike Registered Member

    Could be a co-incidence, but after I disabled the Windows Search and Windows Media Player Network Sharing Services I haven't seen any of these messages
     
  19. Houley456

    Houley456 Registered Member

    Very interested in the response.......
     
  20. Peter2150

    Peter2150 Global Moderator

    The answer should be obvious... If it comes onto your computer as an executable and tries to run, ERP should alert you. If you block it then it won't run. If you allow it, then get ready to do a restore.

    ERP won't identify it as good or bad, that is not the purpose of an Anti Executable.

    Pete
     
  21. Overkill

    Overkill Registered Member

    I just voted 5 stars as well!
     
  22. Defenestration

    Defenestration Registered Member

    I would still like the option to have ERP check for a signature but disable the validity check. I understand the signature could be invalid/revoked, but whether it's signed or not is a bit more information for me to decide on what action to take, without having the delay. Maybe this could be displayed on the alert -

    Signed: True (XYZ Corp) - Not Checked

    Signed: True (XYZ Corp) - Valid/Trusted

    Signed: True (XYZ Corp) - Expired

    Signed: True (XYZ Corp) - Revoked

    If it's possible to determine whether the certificate has expired or been revoiked, the distinction should be made (which is why I've split them into two)

    I noticed that if I block Internet access with my firewall and launch an app (that hasn't already bee launched, and so checked), the delay before the ERP alert is displayed is even longer (approx 45 seconds - an in-built timeout?).
     
  23. dja2k

    dja2k Registered Member

    Thanks!

    dja2k
     
  24. Charyb

    Charyb Registered Member

    With all of the positive reviews/comments, I think it's time to make a donation.
     
  25. DBone

    DBone Registered Member

    I only own 4 pieces of software. ERP, MBAM, WinPatrol and AppGuard because they all offered a lifetime license. Far and away, my favorite piece is ERP. Andreas is active on this thread, and listens to his users. It really is worth 3 times what I paid, and would easily pay that now knowing what I know.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice