New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Mouse clicking freeze

    The problem: When an ERP alert window is activated, at the same time of messing around within' an open GUI window (The program itself), it can sometimes freeze further mouse clicks in windows, therefore requiring power button reset.

    I thought this was related to specific processes, but it appears to only happen when the main GUI is open and when an alert is given at the same time.
     
  2. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @TyRidian

    Yes, you can do that without problems, TiWorker.exe is a safe process used by the system ;)

    Sure, I can add that process in the whitelist using the recommended settings.

    @Trespasser

    Finally I could reproduce the issue you reported with the Avast setup file. So far, I was able to reproduce that issue only in Windows 8.1 64-bit Preview, so I will look into that these days to solve that issue.

    @jmonge

    I tested your situation but I could not reproduce the issue:

    - I added taskmgr.exe in the password protected processes
    - I tried to execute taskmge.exe and the password-prompt popped up
    - I clicked in the "X" button to close the popup: the process was blocked
    - I used a wrong password: the process was blocked
    - I clicked the "Cancel" button: the process was blocked

    I tested it on 32-bit and 64-bit OS, if anyone is experiencing a similar issue please let me know.

    @Jryder54

    Thank you for the log files you sent, they've helped me to reproduce the issue.

    @controler

    What kind of error did you got on restart ? "Failed to retrieve driver handle!" ?

    @everyone

    Has anyone experienced again the error message "Failed to retrieve driver handle!" with the Build V7 ?
     
  3. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    This will be great, thanks :)

    Have you been able to simulate any click suppression/freezes, while alert and GUI are open at the same time?
     
  4. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    @novirusthanks the problem is when you enter the password,let say to disable and then re-enable then try to do what you try and then it will happen but if I reboot then all it is ok try that:)
     
  5. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi Andreas

    Yes I have a couple of times on 2 different machines.

    Pete

    PS it was the latest build you've sent me.
     
  6. Cch123

    Cch123 Registered Member

    Joined:
    Oct 27, 2013
    Posts:
    15
    Hi, I think this product is definitely worth considering. However, how does it stand against advanced threats? For example, Flame malware disguises itself with forged microsoft certificate. Will it be allowed to run because it came from "microsoft"?
     
    Last edited: Oct 30, 2013
  7. controler

    controler Guest

    NoVirusThanks

    Nope, please see my screen shots in post # 2735.

    I get a service failed error.

    This happens after every reboot.

    I can reinstall it and get a crash dump if you like.
     
  8. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Not if you do what I do which is empty the list of trusted vendors, and set the allow signed processes to No.

    I think this is one of the best AE products available.

    Pete
     
  9. Trespasser

    Trespasser Registered Member

    Joined:
    Mar 1, 2005
    Posts:
    1,204
    Location:
    Virginia - Appalachian Mtns
    Hey Andreas,
    Windows 8.1 64-bit Preview only? That's wild. I'm definitely running the latest Win 8.1 Pro 64 bit downloaded directly from MicroSoft (via a little trick provided by TOMxEU to get the iso :)). At least you've been able to reproduce it.

    Thanks for your investigations into this issue.

    Later...

    Bob
     
  10. just_john

    just_john Registered Member

    Joined:
    May 31, 2008
    Posts:
    14
    Please help me here. If I update windows and an executable necessary for booting is changed by the update, won't ERP see that the hash has changed and stop the boot? Don't I set the signed processes to Yes to allow the system to boot?
     
    Last edited: Oct 30, 2013
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    When I am updating something that may be a problem with booting, I take the approach of disabling ERP, doing the update, rebooting, and then just rescan the appropriate directories to white list them.

    I do it this way because I know I'd allow everything involved anyway.

    Pete
     
  12. Cch123

    Cch123 Registered Member

    Joined:
    Oct 27, 2013
    Posts:
    15
    Hmm...can anyone tell me the difference between anti executables and application control software like Bit9 or lumension?
     
  13. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi Cch123

    Let me take a shot. Those two programs are basically like a combo of ERP and Appguard and maybe an AV thrown in.

    An Anti executable is more like Faronics AE and ERP. Both these products are strictly anti executable.

    A major difference is cost. When you have to "arrange" for a demo which means talking to a salesman, the product is really aimed at corporations and tends to make them more expensive.

    Also when products are active here and the developers are active you can see and influence change.

    For example. When ERP first was introduced it didn't work with Sandboxie. But that was important to a lot of users here so.... Novirusthanks went to work and now ERP works beautifully with SBIE. Probably none of the customers of the two companies you mentioned have even heard of SBIE so if there is a conflict, good luck.

    Hope this helps some.

    Pete
     
  14. jks52

    jks52 Registered Member

    Joined:
    Apr 8, 2010
    Posts:
    12
    I have a question that may have been covered. Suppose you have a drive-by download that doesn't try to execute until you have restarted your computer. Would NVE be able to prevent it from executing (installing?) on startup? Or is that kind of malware even possible? As I understand it, the new Cryptolocker virus only installs if you click it (hopefully unknowingly) and NVE should come up with a message to block it, which gives you the opportunity to not install it, in case it was a hidden executable. But has anyone experienced an attack that occurred after a restart/reboot (sort of like a boot time rootkit)?

    jks52
     
  15. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    Powerful anti-executable software designed to alert an user everytime an unknown process tries to run in the system.it will alert you for any malware infiltration attemp
     
  16. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Any updates on version 3?
     
  17. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    every thing was ok after i uninstall the other anti-executable i was trying:) maybe it was a conflict:)
     
  18. controler

    controler Guest

    Hello everyone

    I posted a link to <snip> a while back and never got any comments.

    It is an odd site. I went there by accident while forgetting to type <snip>. Instead I typed just<snip>. It is odd because I check it from time to time and it doesn't always ask you to install the latest version on flash player. Today it did again. It asks , I say no thasnk and I want to go to another page and pops up another popup that crashes not onlty my browser which is IE 8.0 but also crashed Antiexecutable.

    Bruce

    Removed links to a malware site. Please don't ask people to go there.. Peter2150
     
    Last edited by a moderator: Nov 3, 2013
  19. SIR****TMG

    SIR****TMG Registered Member

    Joined:
    May 31, 2004
    Posts:
    833
    <snip> is blocked by my ad muncher, so I won't get there.


    Removed link to malicious site
     
    Last edited by a moderator: Nov 3, 2013
  20. controler

    controler Guest

    Sir

    That realy doesn't help much other then advertise another software.

    My point was Antiexploit, Antiexecutable, maleware bytes don't stop it at present and it shuts down my Antiexecutable by crashing it.

    Sir, try going there without your admuncher once please?

    Bruce
     
  21. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    No DON't It is a malicious site. Post to links of dodgy sites should not be posted.

    I did check it out and it's definitely bad, although I had no problem with Eexeradarpro
     
    Last edited: Nov 3, 2013
  22. controler

    controler Guest

    Ok I am sorry, I guess I remember now the old policy has not changed. I should have sent the links to the SOftware producers.

    I sure hope they do not ignore it.

    I did some more research and increasing the pop up setting in IE helps but ruins the browsing experience.

    I reinstalled NVT and didn't have the service faild to start pop up but ofr some reason I had to uninstall it again for now.

    Bruce
     
  23. ruinebabine

    ruinebabine Registered Member

    Joined:
    Aug 6, 2007
    Posts:
    1,096
    Location:
    QC
    Need help.
    I have a problem when I use my printer (Canon).
    (edit : I have to put ERP in trust mode each time I need to use the printer)

    I tried allowing some processes and folder but it did not work. I would prefer not be using the publisher feature list, if possible. When you see EditPadLite in the log, it's because I used it to make a quick printing test. I also tried allowing this folder : "c:\programdata\canonbj\ijprinter\cnmwindows\canon mp250 series printer\languagemodules", doesn't work either... And tried whitelisting some other with no better result. Here's the log :

    (nitpicking, why the logs ("Events.html") have to always open in Maxthon-IE when Opera is my default browser ?)
    edit Maxthon had made itself the default browser
     
    Last edited: Nov 5, 2013
  24. controler

    controler Guest

    Sorry my posts are being ignored as usual. All you smart people here now, I don't stand a chance do I?
    Where were you during the original 1000 members here? Sure could have used your comments back then.
    Been here lomger then most and never asked to me a mod , Why? because I am too radicle. Talked about rootkits and was a fear mongerer by mods, you go figure.

    Bruce
     
  25. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I saw your last post, but didn't see anything where you were asking for a response.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.