New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,804
    Location:
    .
     
  2. Tomin2009

    Tomin2009 Registered Member

    Joined:
    Sep 13, 2012
    Posts:
    94
    Spyshelter,VoodooShield,Comodo,ESET…

    In a word, they can block *.exe, but can not stop dll injection.
     
  3. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,804
    Location:
    .
    I see your point, so Exe Radar Pro could fail too, most likely.

    If you did that test could you please test AppGuard?
     
  4. Tomin2009

    Tomin2009 Registered Member

    Joined:
    Sep 13, 2012
    Posts:
    94
    I did not had the test, just share the video with you.
    The most important is that most of them could't dectect pic 1 just like ESET, then
    C:\Windows\explorer.exe could do something bad just like pic2 and 3.

    Some people think they black *.exes are enough, but the fact is that it's useless while facing with that site attacks.
     

    Attached Files:

    • 1.jpg
      1.jpg
      File size:
      131.1 KB
      Views:
      43
    • 2.jpg
      2.jpg
      File size:
      21.7 KB
      Views:
      41
    • 3.jpg
      3.jpg
      File size:
      22.2 KB
      Views:
      38
    • 4.jpg
      4.jpg
      File size:
      133.5 KB
      Views:
      34
    • 5.jpg
      5.jpg
      File size:
      145.4 KB
      Views:
      37
  5. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,804
    Location:
    .
    Trying to add to Vulnerable Processes:
    Code:
    "C:\Windows\WinSxS\wow64_microsoft-windows-registry-editor_31bf3856ad364e35_6.3.9600.17415_none_ef8e5a9de3f6db8e\regedit.exe"
    and

    Code:
    "C:\Windows\WinSxS\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.3.9600.17415_none_e539b04baf961993\regedit.exe"
    But ERP says "Warning, the file is already present in the list!
    I guess it is due to md5 which is the same among files but different path.

    Isn't important for an AE the path as well?
     
  6. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,804
    Location:
    .
    Trying to find a filename among a myriad of lines in the lists is a real nightmare :isay:

    Isn't a search feature handy or needed? :)
     
  7. guest

    guest Guest

    If you put a specific file on the blacklist/whitelist, no matter where the file is, it's blacklisted/whitelisted based on the checksum.
    Blacklist a file and try to execute it. ERP blocks it, and blocks it too if it's executed from a different path/filename.
    It's hash-based, so to speak.
    If the path is checked too, then the amount of "unknown executables"-dialog from ERP would be very high.
    Just a simple renaming of a file means you have to whitelist it again (But the file itself doesn't changed)
    If you want it path-based, you can add a path to "Whitelist - File Locations" (without checking of hashes)
    One soluton is to navigate to:
    c:\ProgramData\NoVirusThanks\EXE Radar Pro\Data\
    and search these files manually with a texteditor. Not very comfortable.
    Yes, a search feature and maybe a drag&drop-feature of files to ERP would be nice.
    Or adding of files via contextmenu - Rightclick a file + "Add to whitelist" or something like that.
    But this is unlikely to happen.
     
  8. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,804
    Location:
    .
    @mood
    Thanks for replying. I started a few hours ago to do it with a text editor. :thumb:
     
  9. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,804
    Location:
    .
    On Win8.1 x64:

    AlertWhiteList.DB is completely lost/reset on some machine restarts. This happens randomly and its related to using ERP alongside Shadow Defender. But strongly I believe is on ERP side, I mean the way it handles lists databases.

    This is serious bug. I need to check on every reboot or cold start whether some database file is reset to zero.
     
  10. guest

    guest Guest

    ERP failed against dll ; it is why NVT started SOB.

    Appguard , on the other hand, theoretically won't fail.
     
  11. paulescobar

    paulescobar Registered Member

    Joined:
    Sep 22, 2008
    Posts:
    197
    So as I understand it, there are "vulnerable" system items EXE Radar keeps...I don't know, maybe "tightly monitored" is the word.

    If I were to add all Program Files & Windows folder items to the whitelist (in a clean environment, of course)...would it affect this monitoring of vulnerable system items?
     
  12. guest

    guest Guest

    As soon as a Process is added to the list of Vulnerable Processes, ERP asks before starting it every time: "Vulnerable Application detected" (Allow/Block)
    Even if it's whitelisted.
     
  13. guest

    guest Guest

    that is the word

    no, they are still "vulnerable" and will generate an alert.
     
  14. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Eset has exploit protection. It injects eOPPMonitor.dll into web applications, and vulnerable System processes. I don't have an exact list of processes it injects into. It also uses a System Driver to assist eOPPMonitor.dll. It should be able to stop .dll injection if it is detected as malicious, or potentially malicious. I would be really surprised if it can't.
     
    Last edited: Apr 18, 2016
  15. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Has there been any word about ERP development? I thought Andrea said he was starting development on ERP again a couple months ago. Has anyone emailed him lately?
     
  16. rm22

    rm22 Registered Member

    Joined:
    Oct 26, 2014
    Posts:
    357
    Location:
    Canada
    Even if a 'vulnerable process' is called in a whitelisted cmd line? I'm trialing Webroot SA along with ERP - Webroot is launching 'rundll32.exe' on every boot which triggers an alert even with whitelisting the cmd line. How do I allow Webroot to launch rundll32.exe automatically?
     
  17. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Please post the command line so we can recommend how to allow it by using wildcards.
     
  18. hjlbx

    hjlbx Guest

    Webroot synproc XXXX command line. Whitelist command line then edit it. Use * wildcard at end of command line in place of digits. Delete any duplicate command lines.
     
  19. rm22

    rm22 Registered Member

    Joined:
    Oct 26, 2014
    Posts:
    357
    Location:
    Canada
    @Cutting_Edgetech and @hjlbx - thanks for the replies. The * wildcard did the trick. However, while i was playing around with the cmd-lines i managed to delete them all & had to reset them to default - I was surprised to see that a cmd-line with the * wildcard needed for WSA to launch rundll32.exe was already in the list. So I'm not sure why the cmd-line list I got with the ERP install didn't include it...

    I noticed as an alternative to the whitelisted cmd-line - it also works to add WRSA.exe to the 'safe parent process' list. I assume the cmd-line option is the preferred option.

    Also wouldn't it be a lot safer to link the whitelisted cmd-line strings to a specific parent process or group of parent processes that are allowed to use it?
     
  20. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    No problem.
     
  21. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,804
    Location:
    .
  22. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
  23. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I think Andrea may want to consider adding read/write protection to ERP. He could make it to where the user could choose a folder, or an entire drive for that matter.
     
  24. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,804
    Location:
    .
    To me, ERP needs improvements and some fixes but... I don't want to repeat myself, I already said in previous posts.
    As a side note, I think it's Andreas his name, iirc. :isay:
     
  25. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    The only problem I have ever had with ERP is the tray icon keeps hiding itself. It runs great. It has the least number of bugs out of all the whitelisting solutions available on my machines. I would definitely welcome any security enhancements that don't break usability. Any additional security features could always be made optional. I don't want to ask for much though because I don't want to look ungrateful, and cause undue stress for Andreas. I hope he understands there only suggestions. If other users are experiencing bugs then I think bug fixes should be a priority over additional features. I wonder if the bugs are specific to an OS. Do you know what OS they are using?
    (made quick edit to post)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.