New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    IDK...to gain more users?
     
  2. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I can look into this later for you. The installer is 220 mbs. It's going to take a moment to download. Good grief Comodo! You have to do something about your installer! This has been brought up so many times by users.
     
  3. J_Whacka

    J_Whacka Registered Member

    Joined:
    May 30, 2014
    Posts:
    13
    Still dont see the Webroot file under processes or anywhere else WRSA.exe. I have NVT and Webroot on default settings also.

    The "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\WRusr.dll",* command was listed under whitelist command lines but not sure if the exe is supposed to show in processes in nvt.

    Also even tho its not listed under processes Webroot seems to be running fine and scans are fine also, so probs just me being paranoid just seems weird that every thing else on system is listed but not the webroot exe
     
    Last edited: Jun 1, 2014
  4. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I'm still getting the driver handle error every so often (randomly) not sure why.
     
  5. WalterWolf

    WalterWolf Guest

    Hi
    How i can fix problem with NVT + Sandboxie because when sandboxie is cleaning my sandbox NVT always jumps to allow/block process(cmd.exe) ??
     
  6. iammike

    iammike Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    342
    Location:
    SE Asia
    Add this:

    C:\Windows\system32\cmd.exe /c rmdir /s /q "?:\*\__Delete_*"

    to Whitelist / CommandLine in NVT
     
  7. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @Peter2150

    That was strange, when you uninstall and then install new ERP builds, ERP should recognise the whitelists/blacklists/etc from the previous version.

    I'll run some more tests today to try to reproduce it.

    @TyRidian

    Adding a generic memory protection is a complex feature to add, and users will need to configure memory allow/deny for specific processes, plus it may create some issues with other programs if the user does not correctly configure the permissions to write/read the memory of another process. However I will dicuss it internally these days.

    About the ERP as a service startup, that too has some pros and cons, ERP may run too early and block some needed-processes (AVs-related or similar) or maybe have problems loading the lists, etc. But of course I will run some tests in the next days to see if it is doable in a safe way.

    @puff-m-d

    I tried it now and it works here, but please note that if you add an already-present command-line, it will not show an error message or similar, it simply closes the "add new" window. So you may not see the command-line at the end of the list but if it is already present, it may be in another position. Try to add "ABC" as command-line string and see if it is added at the end of the list correctly.

    @J_Whacka

    I will add an option in the RMB of processes tab named "Export processes list to file", so I can check what are the running processes and other details.

    @Overkill

    I'll improve it in the next build.

    @WalterWolf

    Try to add the command-line string suggested by @iammike and let us know if that worked.
     
  8. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello Andreas,

    Thanks for your reply. Your scenario worked for me this time. What I had done before was I had been prompted to a vulnerable process (command line) and meant to click Whitelist commandline, but by mistake clicked allow instead. I was almost certain it was not in the commandline whitelist, so I went and tried to add it manually. I did check and again almost certain it was not there. I wonder if by clicking allow first and then trying to add it caused the issue. I will try to recreate those same circumstances again in the near future so I can verify. As you said, it could have very well already been in the list but somehow I just overlooked it when checking for it. Thanks again...
     
  9. Jryder54

    Jryder54 Registered Member

    Joined:
    Sep 3, 2013
    Posts:
    212
    I am getting this error as well randomly.
     
  10. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Thanks!
     
  11. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    After I uninstalled ERP the tray icon was still running in the desktop toolbar, and I could navigate throughout the GUI. Windows said ERP was done uninstalling. Windows did not say I needed to perform a reboot to finish uninstalling ERP. It said the uninstall was complete. This seemed really strange to me that the tray icon, and GUI was still running. I decided to go ahead, and reboot anyways. After rebooting the tray icon was no longer running, but there were many orphaned files. ERP left orphaned files in the Program Files directory, and also in the appdata folder, or programdata folder. I'm not sure which one it was since I uninstalled ERP yesterday. Is this normal?

    Edit: I was using Windows 7X64.
     
    Last edited: Jun 3, 2014
  12. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @Peter2150

    I could reproduce your issue, it should be fixed now.

    Will upload the new build tomorrow.

    @Cutting_Edgetech

    Did you closed EXERadar.exe before uninstalling it ?

    If EXERadar.exe is not running, the uninstaller should delete all files (if they are not is use by other processes).
     
  13. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    No, I did not close ERP before uninstalling it. Thank you for fixing this issue!
     
  14. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    Thanks Andreas
     
  15. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    I uploaded the new build, download it from this link:
    http://downloads.novirusthanks.org/files/EXERadar_Pro_x86_x64_v3.1_20042014_BUILD1_20042014_v4.exe

    To update, follow these steps:

    1) Close EXERadar (if it is running)
    2) Uninstall EXERadar (you can keep your current settings)
    3) Reboot the PC (needed)
    4) Install the new build

    What's new ?

    + Added option to minimize the application when started manually
    + Added option on the RMB of Whitelists and Vulnerable Processes to reset the lists to default
    + Added option on the RMB of Processes to export processes list to a file
    + Automatically remove the spaces when inserting activation code
    + Fixed issue of blank whitelists when the application is installed
    + Improved x64 and x86 services
    + Improved loading of kernel-mode driver
    + Improved uninstaller

    Let me know how this new version works :)
     
  16. SIR****TMG

    SIR****TMG Registered Member

    Joined:
    May 31, 2004
    Posts:
    833
    Downloaded and running fine on vista 32 bit and windows 7 64 bit
     
  17. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I like the colored icons, great job Andreas
     
  18. WalterWolf

    WalterWolf Guest


    I will try it later because i removed sandboxie.
    Thank you.
     
  19. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Andreas, I hope that popup alerts in the final version will have no visible boxes in each row.
     
  20. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi Andreas

    The problem I reported is indeed fixed. Well done and thanks,

    Pete
     
  21. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello Andreas,

    I can also verify the issue that I reported is also fixed.
    Thanks :thumb: !!!
     
  22. guest

    guest Guest

    installed, run fine, it is sad to say :

    i don't have any issues since quite a long time, so i don't have much to say :D
     
  23. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    ERP just keeps getting more & more pefectly perfecter. :)
     
  24. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    When I launched ERP installer in Alert mode, I got 2 popups about .tmp files.
    Is that expected since NVT is a trusted vendor?
     
  25. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.