New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    :)

    Well advising people to Prompt would do it ;)

    That's one way of doing it :thumb:

    Regards
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    The problem with a general prompt is a huge number that have to be allowed. This would end having most folks just automatically click. That is why DiamondDC was struggling with it. They knew it was a bad way to go.

    Whitelisting valid commandlines solves that as they no longer generate alerts.
     
  3. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    agree with peter as whitelist will reduce the alerts :thumb:
     
  4. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    The problem with the above post is you can't make recommendations based on ProcessGuard experience. It simply is out of date.

    Recommendations here have to be based on current ERP capabilities.

    Pete
     
  5. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    exactly
     
  6. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Sorry about this post, Pegr, it was supposed to have been in the AppGuard section. Guess I was thinking about this subject, but in the ERP thread.
     
  7. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    No problem, Tom. I hope you found the white paper useful. :)

    Kind regards
    pegr
     
  8. AlexC

    AlexC Registered Member

    Joined:
    Apr 4, 2009
    Posts:
    1,288
    I've reproduced the tests made by Pedro in this other thread:
    https://www.wilderssecurity.com/showthread.php?t=306496&highlight=xyvos

    But instead of using Xyvos i used NVT EXE Radar Free.

    First i run procexp.exe (Process Explorer 15.3), and added it to the blacklist.

    Then i renamed it to a very long sequence of A's "aaaaaa(...)".exe and executed it.
    Result: EXE Radar blocked it (a warning shows up:"Blocked [blacklist]").

    Then i renamed it to "something.exe", moved the file to another directory, and executed it.
    Result: EXE Radar blocked it (a warning shows up:"Blocked [blacklist]").

    Nice :)
     
  9. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    this is the real deal i am telling ya:cool:
    ERP is becoming stronger and stronger
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Thanks AlexC
     
  11. AlexC

    AlexC Registered Member

    Joined:
    Apr 4, 2009
    Posts:
    1,288
    You're welcome :thumb:
     
  12. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    Not in my several years of using PG. If i had to allow numbers of Prompts every day, it would bug me. It's ONLY when i test things, including Malware, that i get them, which is what it's supposed to do, & i want to see. The recent Zip-IT etc test is the Only thing it's missed. Even then i had to allow other processes etc to run, Before i got it unzipped & ran the Actual App.

    .

    See above. But obviously if people are using W7/8 etc, then it's not designed for them. For those of us who prefer XP, it's just fine ;)
     
  13. The Red Moon

    The Red Moon Registered Member

    Joined:
    May 17, 2012
    Posts:
    4,102
    I was hoping to try the free version but i dont see the point if the free version is going to be abandoned at some point.
     
  14. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    There eventually will be a 30 day trial of the full version, but I suspect and future free version is way down the road.

    Pete
     
  15. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    With a trial people can try, I think that alone will boost the user base a bit more.

    I think the sooner they release the trial, the better.

    I'll enjoy watching NoVirusThanks grow, and I hope they get bigger and bigger.

    I have high hopes for this company, they offer great products, keep their eye out for user suggestions and offer the best support I have ever seen.

    I also think NoVirusThanks should consider a NVT army advertising program, where people like us can advertise on sites and show our support for the company....

    Anything to get the word out.

    By the way, Can't wait for the next release - I mean I can, but just excited to try it out hehe :D :thumb:
     
    Last edited: Mar 24, 2013
  16. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    good idea man:thumb:
     
  17. pablozi

    pablozi Registered Member

    Joined:
    Oct 24, 2010
    Posts:
    215
    Location:
    nowhere
    Indeed. RADEON0101: :thumb:
     
  18. KelvinW4

    KelvinW4 Registered Member

    Joined:
    Oct 11, 2011
    Posts:
    1,199
    Location:
    Los Angeles, California
    I can try to help you open up an official thread on tweakbytes.
     
  19. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Here is PM that I sent to nvt few weeks ago...

    nvt,

    I don't know how your marketing works and how many users you have, but here are some ideas that came to my mind about how to make ERP more known/popular worldwide (some of them are already in progress):

    -Update web page (Edit: DONE!)
    -Update Facebook page
    -Make a trial version
    -Make promotions (short time 25-50% discounts) at bitsdujour.com and downloadcrew.com
    -Apply free version for a review at techsupportalert.com
    -Make a detailed review on YouTube
    -Ask users to spread a word to people they know, forums and sites they visit
    -Try to make an agreement to put links to your webpage on well-known portals

    First make actions that are least expensive...
     
  20. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    It looks like NVT has updated the Facebook page as well

    These will definitely work though

    Here is another one...

    -Have users/supporters promote NoVirusThanks in their forum signatures

    I've met a few users on here that didn't know about NoVirusThanks, so that is why I am suggesting the above.
     
  21. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    @NoVirusThanks

    Once and a great while I'll double click on a trusted executable to see if it will run, while in Lockdown Mode (For ERP testing purposes).

    So far, nothing has ran while Lockdown Mode is enabled.

    Except, Today it did

    I downloaded the Steam Client from here http://store.steampowered.com/about/?snr=1_4_4__11

    Once the download finished, I double clicked to install it and sure enough it executes while Lockdown Mode is enabled.

    Is there a reason why this is executing?

    In theory...it shouldn't
     
    Last edited: Mar 25, 2013
  22. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Is download located in ProgramFiles folder?
     
  23. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    It's located here...

    C:\Users\MyUserName\Downloads
     
  24. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Hmmmmm....did you check the whitelist?
     
  25. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Yes I did, Nothing in my Whitelist either

    The only entries that are Whitelisted, are some Microsoft processes that I allowed.
     
    Last edited: Mar 25, 2013
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.