New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. iammike

    iammike Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    342
    Location:
    SE Asia
    Thanks, and you can also use the Import/Export function in the program itself
     
  2. just_john

    just_john Registered Member

    Joined:
    May 31, 2008
    Posts:
    14
    That would only work though if the import function would recognize that the two categories had been merged and then would properly sort things out. It might not be a bad idea (if this is a concern) to backup the data and check just to make sure, especially when dealing with a beta version.
     
  3. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    I must say, I am quite impressed :thumb:

    Good job, can't wait for a new or official build :D
     
  4. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,348
    Location:
    USA
    Have you made changes to trust mode yet? like the lockdown modes where you have time options?
     
  5. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    where is the new download link?
     
  6. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,363
    Location:
    Italy
    @Overkill

    Sure, all protection modes (except the Alert Mode) can be enabled for 10 minutes, 30 minutes, 1 hour, until reboot (until the application is exited), permanently.

    @everyone, @jmonge

    New build 2 V10:
    http://downloads.novirusthanks.org/files/EXERadar_Pro_x86_x64_v3.0_09092013_BUILD2_V10.exe

    Please note that I updated only the x64 version.

    Changelog:

    The configuration wizard->custom configuration looks like this:
    http://postimg.org/image/k7z81dr3r/

    I removed all the other checkboxes because they can be easily changed from settings (I see they are redundant), in the custom configuration I wanted to only allow user to select what to whitelist to create the initial whitelist rules.

    This build does not merge automatically the commandline strings present in CommandLineWhiteList.DB file with the ones present in CommandLineWhiteListWildcard.DB file, so you should do this manually for now. The DB file that is used now is CommandLineWhiteListWildcard.DB

    I removed the tab "Advanced Options" in "Settings" window, and I added a new tab "External Devices". I removed the possibility to restore the protection, I think it is not needed anymore because now the user is able to select for how much time enable a protection mode, so has more control on this and can also enable permanently a protection mode.

    Don't forget to test the restore/import/export settings/lists.

    Let me know what you all think about the new changes and if you have other suggestions/bugs to report :)
     
  7. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,348
    Location:
    USA
    When will the x86 version be ready? Thanks
     
  8. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi NVT

    So far so good on the new version.

    Pete
     
  9. Jryder54

    Jryder54 Registered Member

    Joined:
    Sep 3, 2013
    Posts:
    212
    The avast installer is still able to execute :(
     
  10. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    thank you:thumb: :thumb:
     
  11. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    + Added option "View commandline string" in the popupmenu of Events tab
    + Added option "View commandline string" in the popupmenu of CommandLine tab

    Very useful! :)
     
  12. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Where are you executing it from?
     
  13. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    BUG

    Go to Menu-Settings-Master Password.
    Check "Password protect enabling of Disabled Mode".

    Go to Import/Export and select Restore Default Settings.

    Now, check Menu-Settings-Master Password settings.
    "Password protect enabling of Disabled Mode" is still checked.
    It should be unchecked. ;)

    Restoring default settings of other Master Password options works ok.
     
  14. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,363
    Location:
    Italy
    @Overkill

    I should release the x86 version later in the afternoon.

    @Jryder54

    I have not yet fixed it, I will do that in the next build ;)

    @siketa

    I could reproduce the issue, will fix that in few hours.
     
  15. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Andreas, what is the problem regarding avast?
     
  16. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,363
    Location:
    Italy
    It seems that in Windows 8+, sometimes, the setup file of Avast is executed without alerting ERP, I have not yet analyzed this behaviour, but I could reproduce it. After I have the x86 version ready, I will check it.
     
  17. Jryder54

    Jryder54 Registered Member

    Joined:
    Sep 3, 2013
    Posts:
    212
    Thank you :thumb:
     
  18. just_john

    just_john Registered Member

    Joined:
    May 31, 2008
    Posts:
    14
    Currently external devices can be blocked. What about adding blocking of internal folders and subfolders? I have a data only e drive. It would be nice to block file execution for that whole drive. It would even be better to do that and to allow exceptions for a time or permanently.

    It may be the same thing. Allow wildcards in the blacklists so I could enter e:\*.
     
    Last edited: Nov 18, 2013
  19. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi Again NVT

    On my Win 7 desktop the install was straight forward, but in my win7x64 VMworkstation machine, it was no go.

    1st I did a routine uninstall, but I was never asked if I wanted to keep my settings. It came up with all the old settings and was a mess. So uninstalled again, and again no settings.

    This time, I removed the NVT folder in Allusers. THen did a reinstall. I never got the option query, it just installed and came up. Absolutely no settings are lists to be seen.

    Next?

    Pete
     
  20. smith2006

    smith2006 Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    808
    Is the description for the first item changed to

    "Allow rundll32.exe to load system protected modules" ?



    Thanks
     

    Attached Files:

  21. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    I prefer the description that is already in the Settings.
     
  22. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,363
    Location:
    Italy
    This is the new build 11 (x86 version is updated):
    http://downloads.novirusthanks.org/files/EXERadar_Pro_x86_x64_v3.0_09092013_BUILD2_V11.exe

    Please remember:

    @smith2006

    Yes, I updated the text in the Settings window and I updated now also the changelog text.

    @just_john

    Sure, that can be done, an option would be to have the same Whitelist rules for the Blacklist (CommandLine, Parent Processes, Untrusted Folders, Path Comparison). Although I think that these features may not be needed, since with the Lockdown Mode Extreme you just need to set rules for allowed processes and all the rest is blocked, I would be interested to know how many users may benefit from these options added in the Blacklist ?
     
  23. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Master Password bug is fixed! :thumb:
     
  24. just_john

    just_john Registered Member

    Joined:
    May 31, 2008
    Posts:
    14
    I only see use for being able to deny file execution on the data drive. I never thought of doing it before using ERP. It would also add a layer of defence against Cryptolocker. I guess I could also accomplish the same thing by changing the e drive security permissions to deny file execution.
     
  25. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,348
    Location:
    USA

    Thanks :thumb:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.