Driver Radar Pro v1.5 (Freeware)

Discussion in 'other anti-malware software' started by novirusthanks, Apr 28, 2014.

  1. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    DRP v1.6.5
    DRP at Lockdown blocks C:\Windows\system32\drivers\hitmanpro37.sys. After the dings HitmanPro runs.
    DRP in Learning. HitmanPro loads driver and runs.
    DRP in Trust. HitmanPro loads driver and runs.
    DRP back to Lockdown blocks C:\Windows\system32\drivers\hitmanpro37.sys
    Um, how do I Learn (force) DRP 1.6.5 to WhiteList hitmanpro37.sys ~ HitmanPro Build 242
     
    Last edited: Jun 19, 2015
  2. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Hmmm... you might check the name of Hitman's driver between each of those tests. Hitman might be one of those security apps that renames its driver with every access.

    @ NVT -- does DRP record a driver's hash or its filename or both?
     
    Last edited: Jun 19, 2015
  3. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    I've also been trying to figure this out, and see that hitmanpro37.sys comes with a different "image base" each time it loads, and also the publisher is regarded as "unknown".
     
  4. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    NVP DRP.png
    v1.6.5 + Build 242 = bubble and dings. If I allow bubble to sit. Hitman.Pro starts scan as normal...but, hitmanpro37.sys never goes to WhiteList
    I don't remember this with Build 241
    I've tried to Learn hitmanpro37.sys into WhiteList. No joy.
     
  5. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    DRP hitmanpro37 support driver.PNG
    @Dermot7
    ~ Good to know not only me....Thanks
     
  6. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    I've been seeing this happen for some time...there appears no way to get that driver into DRP's whitelist. What happens when a HMP scan is scheduled to run? Haven't tried that, probably no different.
     
  7. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Have you been running 1.6.5 for some time. I'm only recent to 1.6.5.
    Not remembering with 1.6.0 ... I was thinking maybe something with 242...?
     
  8. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
    Yeah...maybe this just happens with 1.6.5. Worth checking.

    edit: I've had 1.6.5. since 6th April, and have deleted previous installers. Can't remember now when I first saw this. lol.
     
    Last edited: Jun 19, 2015
  9. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Yeah...my memory is forever fleeting
     
  10. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    v1.6.5 ~ these were just blocked.
    C:\Program Files (x86)\Norton Security with Backup\NortonData\22.5.0.120\Definitions\VirusDefs\20150619.002\EX64.SYS
    C:\Program Files (x86)\Norton Security with Backup\NortonData\22.5.0.120\Definitions\IPSDefs\20150619.001\IDSvia64.sys
    If there was an edit option I'd add date wildcard...
     
    Last edited: Jun 19, 2015
  11. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Well, I'm back to v1.6.0
    HitmanPro 242 easily slipped into WhiteList...
     
  12. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  13. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Oh bother... maybe I should un-check start with Windows. All system32 drivers are whitelisted afaik. :doubt:
     
  14. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @bjm_

    I could partially reproduce your issue (when you whitelist a driver it is not correctly saved in the whitelist).

    Will keep testing more in the next days and it should be fixed very soon.
     
  15. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Um, my issue ...#146 or #151, #154, #160, #161 or ?
    Thank you.. Regards
    btw ~ is it possible for event log to survive reboot...?
     
    Last edited: Jun 21, 2015
  16. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Should this be ran in learning mode for awhile when first installed?
     
  17. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    This is happening to me also and it keeps blocking core temps driver too, and it won't whitelist it when I try to add it.
     
  18. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Hi Overkill,
    I've benched DRP awaiting news re: #164 #165
     
  19. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @bjm_ @Overkill

    Please check this new version, we've fixed some issues reported by users via email:
    http://downloads.novirusthanks.org/files/setup_drp_1.6.5_BUILD02072015.exe

    To update:

    1) Close DRP
    2) Uninstall DRP
    3) Reboot PC
    4) Install new DRP

    Let me know if that works.

    @bjm_

    If you put DRP in Learning Mode, then open HitmanPro (so it can load the driver and DRP can auto-whitelist it), and then put DRP in Lockdown Mode.

    After this, if you close and re-open HitmanPro, the hitmanpro37.sys should be allowed (since it was whitelisted previously by Learning Mode).

    Let me know if this new version works fine.
     
  20. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Glad to see you back in the forum! Thanks
     
  21. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Hello novirusthanks,
    What about issue reported in #146..& ..#160
    Yeah, quote above is what happened with 1.6 ...not 1.6.5 #143
    Does the event log survive reboot...?
    What issue(s) were fixed by 1.6.5_BUILD02072015
     
    Last edited: Jul 2, 2015
  22. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I did this but it does not whitelist it
     
  23. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
  24. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    I've had DRP 1.6.5 on the bench since 07/01

    sent in DRP on 7/12 and DRP Blocked >> C:\Program Files (x86)\Norton Security with Backup\NortonData\22.5.0.120\Definitions\VirusDefs\20150712.001\EX64.SYS
    hash changes with date

    DRP back on the bench.
     
    Last edited: Jul 15, 2015
  25. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    DRP still on the bench.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.