New Antiexecutable: NoVirusThanks EXE Radar Pro

Discussion in 'other anti-malware software' started by sg09, Jun 3, 2011.

  1. Snoop3

    Snoop3 Registered Member

    Joined:
    Jan 2, 2011
    Posts:
    474
    got one - couldn't resist $20 for lifetime license :cool:

    (esp considering the great support via this thread as well as NVT's other excellent services like IPVoid and URLVoid)


    hope that NVT will consider focusing on Socket Sentinel Pro as their next move.
     
  2. 0strodamus

    0strodamus Registered Member

    Joined:
    Aug 23, 2009
    Posts:
    1,058
    Location:
    United Surveillance States
    Or better yet, just drop Themida!
     
  3. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Possible issue with EMET?
    I have EXERadar.exe added to EMET 4, with Caller and EAF unchecked/disabled as suggested.

    My question is...

    Have any of you experienced Freeze-ups while having SEHOP checked/enabled for EXERadar.exe?

    Reason why I ask is, I experienced a couple of Freeze-Ups with SEHOP enabled.

    I just recently unchecked/disabled SEHOP for EXERadar.exe, And so far no more freezing.
     
    Last edited: Jun 7, 2013
  4. Trespasser

    Trespasser Registered Member

    Joined:
    Mar 1, 2005
    Posts:
    1,204
    Location:
    Virginia - Appalachian Mtns
    No freeze-ups for me and I have SEHOP enabled. I also protect ERPx64Svc.exe.

    Regards,

    Bob
     
  5. molhopicante

    molhopicante Registered Member

    Joined:
    Aug 8, 2008
    Posts:
    135
    Any news about my problem?
     
  6. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi molhopicante

    While waiting for NVT, try this: (this for XP, you may have to modify)

    1. Re install free, and see if it works.
    2. Uninstall free, and reboot.
    3. Delete the Novirusthanks folder from Program Files.
    4. Go to Documents and settings>all users>Applicaiton Data and remove any novirus thanks folders there. Also in the application data folder scroll down, and remove any thing like exeradar.lic files.
    5. Reboot.
    6. No try installing the new version.


    Pete
     
  7. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @Snoop3

    Thanks for supporting us :)

    @TyRidian

    I tested it here with Win8 x64 and with SEHOP option checked, it works without delays (at least for now).

    @molhopicante

    I installed ERP and Online Armor, I configured Online Armor as:

    1) Open Online Armor and click on "Programs" on your left
    2) Now remove the check on "Hide trusted", select the program name "EXERadar.exe" and click the button "Allow", then click the button "Trust"
    3) Select the program name "ERPx64Svc.exe" and click the button "Allow", then click the button "Trust"
    4) Same as image: http://postimg.org/image/4gmo8fe6r/
    5) Now click on "Anti-Keylogger" on your left
    6) Remove the check on "Hide trusted", select the program "EXERadar.exe" and click the button "Allow"
    7) Same as image: http://postimg.org/image/gyiibmcev/

    For me it works fine in Windows 7 x64, is anyone using ERP and Online Armor under Windows 7 x64 ? Please let us know if you found any issue.
     
    Last edited: Jun 6, 2013
  8. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    There is no point in running ERP together with OA HIPS.
    Both of them have process execution detection and could cause problems.
    IMHO, OA is for advanced users who know how to deal with popups.
    ERP is more convenient for novice users....

    You should decide which product to keep but my advice is to drop one out of that combo...
     
  9. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Actually I use OA with ERP, but what I've done that deals with the pop ups, is I've set both Windows and Program Files as exclusions. That way OA alerts only come with something new.

    Then I get both alerts from both OA and ERP, but that's okay.

    Pete
     
  10. molhopicante

    molhopicante Registered Member

    Joined:
    Aug 8, 2008
    Posts:
    135
    Hi.

    I had already tried but unfortunately does not work.


    PS:

    I have other issue.

    Sometimes Windows action center notify me that i have the OA firewall deactivated.

    I only can solve it when i uninstall ERP
     
    Last edited: Jun 6, 2013
  11. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    If anyone could help with this problem. I have windows 8 64 bit and pokki as a start menu. I'm trying to get this stupid command string so I don't get it everytime I open a folder in pokki. "C:\Windows\sysnative\rundll32.exe" "C:\Windows\system32\WRusr.dll",SynProc 6524. Any suggestions on how because I've tried it a few ways and can't get it. Thanks!
    Edit: Ok now I just updated to the newest sandboxie beta and I get the same string when I'm opening firefox. I wasn't getting it before. Help!
     
    Last edited: Jun 6, 2013
  12. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    EDIT

    Ok, I made a mistake by posting my freeze issue here on the ERP thread.

    That's because it wasn't an ERP or SEHOP issue.

    I guess I jumped in too quick and assumed that ERP and SEHOP had something to do with it, when in fact that wasn't the issue at all.

    I found out Internet Explorer 10 with WOT extension installed ( Windows 8 ), indeed caused my freezing issues.

    I have since then returned to Comodo Dragon and no longer get system freezes.

    Sorry for thinking ERP and the SEHOP setting had something to do with it.

    Please dismiss my false report.
     
  13. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    How about this CommandLine (in Wildcard tab)?

    "C:\Windows\sysnative\rundll32.exe" "C:\Windows\system32\WRusr.dll",SynProc*
     
    Last edited: Jun 8, 2013
  14. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    Hmmm. I don't think I tried that one yet. I tried _, *", not just *. Not sure if it makes a difference. Thanks Siketa
     
  15. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    @NoVirusThanks:

    BUG REPORT​


    When "mmc.exe" is added to "Protected Processes", the Password confirmation doesn't always work when "mmc.exe" related processes are being launched.

    This is what I mean...

    For example, launch services, but don't enter in your password, just hit the "X" button to close that window.

    Doing so will either bring up the ERP notifcation saying "BLOCKED WRONG PASSWORD", or on occasion the process will launch with full permissions...as if a password isn't needed.

    Sometimes it works, Sometimes it doesn't

    Can you replicate this issue on your end?
     
  16. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @TyRidian

    No problems ;)

    @kjdemuth

    The wildcard suggested by siketa should work fine, let us know the results.

    @TyRidian

    Have you added in the "Protected Processes" both mmc.exe files:

    C:\WINDOWS\system32\mmc.exe
    C:\WINDOWS\SysWOW64\mmc.exe
     
  17. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Yes, I've always added both
     
  18. arsenaloyal

    arsenaloyal Registered Member

    Joined:
    Nov 1, 2009
    Posts:
    513
    Has any one noticed the language bar appearing on first installation if the language is not English US ? I have my language set to English UK and language bar is disabled by default but when I installed Exe Radar Pro it appeared besides the tray icon.
     
  19. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    Yep it worked. Thanks NVT and siketa.
     
  20. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Glad to hear that.;)
     
  21. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    Quick inquiry. Is anyone else using the allow process from trusted vendor option? I'm kind of wondering if it lowers the protection level. I already have a ton of vulnerable process alerting me. I also have the allow all software from program folder unchecked.
     
  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Not here. I not only select no, but I clear the trusted vendor list.

    Pete
     
  23. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Any new news for ERP?
     
  24. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Nothing new yet. NVT must be busy, it's been almost a week without a word on the beta's


    Pete
     
  25. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Yeah, they must be.

    Hopefully some news here soon
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.