New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. francisw19

    francisw19 Registered Member

    Joined:
    Jan 29, 2007
    Posts:
    21
    Location:
    Canada
    NVT,

    I've got an issue with some .exe's running undetected by EXE Radar Pro. I run ERP in "Alert Mode". I've also got a folder of some handy system utilities that's in a folder on my D: drive (I can list these if you need them specifically). They're all just stand-alone .exe files and not installed to the OS.

    On some of these .exe files, when I run them, there is no prompt from ERP and nothing comes up under the Events tab to show why it was allowed. So from what I can see, it looks like the .exe was just missed. Or perhaps I'm just missing something. Either way, I'd appreciate it if you could dig into this a bit. I'm certainly willing to help, just let me know what you need on my end. :)
     
  2. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @sg09

    I could reproduce your issue, it'll be fixed.

    @siketa

    I had to change few things in the Win 8.1 fix, so still testing it in few boxes. I'll see how the tests goes and I'll keep you updated ;)

    @mattdocs12345

    So basically you need to configure ERP so that no unknown process is executed in the PC correct ?

    An example to do this, as Pete said, is this:

    1) Enable the options:
    -Allow Microsoft Windows system protected processes
    -Allow processes signed by Trusted Vendors
    -Allow all software from Program Files folder
    2) Try to open all the programs that you would open regularly and whitelist all processes and all possible commandline strings
    3) Restart the PC and try to re-open the programs you regularly use just to see everything is whitelisted correctly
    4) Change the protection mode to "Lockdown Mode (Extreme)" so only whitelisted processes/commandline strings are allowed to be executed

    @TomAZ

    I'll look at that in few hours.

    @francisw19

    Actual ERP version does not fully support Windows 8.1 64-bit, I am working on it :)
     
  3. sg09

    sg09 Registered Member

    Joined:
    Jul 11, 2009
    Posts:
    2,811
    Location:
    Kolkata, India
    Thanks Andreas.
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Don't know. Mine stopped at 1/1/2014. Just checked a 2nd machine. The same.

    Pete
     
  5. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Maybe ERP thinks it was a Doomsday.....:D
     
  6. francisw19

    francisw19 Registered Member

    Joined:
    Jan 29, 2007
    Posts:
    21
    Location:
    Canada
    Doh! :ouch: You're right, no worries then. I shall wait for Win 8.1 support. :)
     
  7. ruinebabine

    ruinebabine Registered Member

    Joined:
    Aug 6, 2007
    Posts:
    1,096
    Location:
    QC
    Not here, for me latest log is 11-01-2014.
     
    Last edited: Jan 13, 2014
  8. controler

    controler Guest

    Mine was Jan 12th 2014 but I did not have puter on today.

    I am still not sure what restore default lists does..:doubt:
     
  9. Antimalware18

    Antimalware18 Registered Member

    Joined:
    Dec 12, 2008
    Posts:
    417
    I have just one idea for this program that will make it even better then it already is, and that is when it is in lockdown mode (any level) you can right click a executable/program and add it to white list from there instead of having to open the interface. Just a idea.
     
  10. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Oh wow, I like this idea, a lot.

    +1 :thumb:
     
  11. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Been testing out ERP for a few days and now I think I am ready to use Lock Down Mode. Do I have to do anything special to set it up? Oh I am running it along side AppGuard if it matters. Thanks

    dja2k
     
  12. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    you are good to go:thumb:
     
  13. DX2

    DX2 Guest

    Does NVT EXE protect against MBR tampering?
     
  14. mattdocs12345

    mattdocs12345 Registered Member

    Joined:
    Mar 23, 2013
    Posts:
    1,892
    Location:
    US
    NVT ERP became a really solid product.
     
  15. guest

    guest Guest

    I'd love to know about this too. Also, does EXE Radar protect against DLL injections and system driver (.SYS) loads? Thank you.
     
  16. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Guy's

    You are asking about protecting mbr and against dll injections, etc. Ask your selves this. How can these happen if the exe's that cause them can't do them?
     
  17. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    Bingo! We have a winner. You can't inject or corrupt a MBR without something executing first.
     
  18. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Any word about 3.0 and the fix it provides for Windows 8.1?

    Is it close to being final yet?
     
  19. guest

    guest Guest

    By making the whitelisted process to load DLLs? If EXE Radar also blocks DLL and SYS then at least they wouldn't be able to execute as well.
     
  20. Correct, but ......., there is code executed in regular programs which process rich content, like your browser and its plug-ins. Also a lot of files we think only contain data, also contain (sometimes tiny bits of) code defining the structure or meta data or describe the way it is formatted (remember png and postscript exploits).
     
  21. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    You are absolutely correct which I also run SBIE, Appguard, and Emet.

    Pete
     
  22. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    True but the majority of exploits will try to dispense an exe payload. Yes I know that there are exploits that change meta data and other data streams. I'm not saying that AE are the end all but merely a piece of the big security puzzle. I should be a little clearer when blurting out my opinions. ;)
     
  23. @Pete & KJ

    I am the last one who will say you are not sufficient protected with AppGuard, SBIE, NVT, EMET or Comodo, WSA, SBIE, MBAE :D just putting things into perspective :thumb:
     
  24. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    Thanks Kees. I know you're just looking out for me. Appreciate it. :D
     
  25. just_john

    just_john Registered Member

    Joined:
    May 31, 2008
    Posts:
    14
    Running EXERadar_Pro_x86_x64_v3.0_09092013_BUILD2_V12.exe with Windows 8.1. (Is there an easy way to check if I have the latest beta?) I have AutoHotkey.exe listed as a vulnerable process. If I whitelist the commandline, the commandline is allowed to run. But if I use a wildcard in the string it triggers an alert. I have other commandlines with wildcards that work.

    This is allowed to run: "C:\Program Files\AutoHotkey\AutoHotkey.exe" "E:\info\autohotkey\zztimers.ahk"

    This triggers an alert: "C:\Program Files\AutoHotkey\AutoHotkey.exe" "E:\info\autohotkey\zztimer?.ahk"
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.