EXE Radar Pro v4 (Beta)

mekelek

Level 28
Verified
Well-known
Feb 24, 2017
1,661
which is better, adding a signer of a blocked app to the trusted vendor list, or having a rule that allows everything that has the signer of the app?
 
  • Like
Reactions: Andytay70

Andytay70

Level 15
Verified
Top Poster
Well-known
Jul 6, 2015
737
ERP has stopped working again!
I'm going to uninstall it until another release comes out.
All i did was reboot my Laptop!
 

Garzaman

Level 3
Verified
Well-known
Nov 14, 2017
126
How strange!
Have you tried turning off WD's realtime protection, exploit guard etc?
Is test 9 the first ERP beta you've installed or did test 8 (or any of the previous tests) work for you?
Do you use an admin account or standard user account?
Thanks again :)

Well, I've finally become paranoid. I have recovered several images from my system and still had the same problem, so I decided to do a clean installation of Windows and now everything works perfectly.

Thank you very much for your interest :)
 

NoVirusThanks

From NoVirusThanks
Thread author
Verified
Developer
Well-known
Aug 23, 2012
293
Here is a new v4.0 (pre-release) test10:
http://downloads.novirusthanks.org/files/exe_radar_pro_4_setup_test10.exe

*** Please do not share the download link, we will delete it when we'll release the official v4 ***

So far this is what's new compared to the previous pre-release:

+ Fixed the link to lookup file sha1 on Virustotal on Events tab popup-menu
+ Fixed When clicking "Edit Expression" on "Rule Editor" it shows a warning message "You must enter a valid expression"
+ Fixed Wrong categories/Categories which are not applicable are being shown in the Alert Dialog
+ Fixed Cosmetic issue (Logfile related): Normally a "-" is shown in the logfile if the Expression or Category is empty
+ Fixed Changing of the column size in the Rules listview seems to have no effect ("ruleColumnX:") (but Events seems to work ["eventColumnX:"])
+ Fixed Windows Apps weren't allowed by the option "Allow Microsoft Windows Apps" in Settings tab
+ Fixed Possible Rules conflict -> moved Deny action checking to be before Ask action
+ Fixed The warning message "You must enter a valid expression" is present also on the Alert Dialog -> Custom Rule
+ Fixed Command-line string is empty for very long command-line strings
+ Improved allowing of safe process behaviors
+ "Vulnerable Processes" are now pre-loaded on the Rules tab when the program is first installed
+ Smarter way to handle signed processes not found in Trusted Vendors list while on "Learning Mode" -> if a signer is not present in Trusted Vendors list (when in Learning Mode), it is auto-added and enabled/checked
+ Added more signers on Trusted Vendors list
+ Added new option "Copy Selected Rule" -> The selected rule is "copied" on the newly created rule with same parameters
+ Added new option "Copy Selected Rule to Clipboard" -> It copies the selected rule to clipboard in XML format so can be easily pasted/shared on forums
+ Added new option "Locate Process File in Explorer" on Events tab
+ Added new option "Locate Parent Process File in Explorer" on Events tab
+ Added new option on Settings tab When on Lockdown Mode auto-block "Ask"-action processes (unchecked by default)
+ Minor fixes and optimizations

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.

@Andytay70

If ERP runs fine but it doesn't detect new processes (Events tab remains always empty after you run processes), I suspect there is somehow a WD setting or something other (AV, HIPS, etc) that is preventing ERPv4 to communicate/load the kernel-mode driver (only guessing of course).

Can you retry with this new build? If it doesn't work, can you try to:

1) Uninstall ERPv4, then reboot
2) Disable the other security software (e.g WD, AV, HIPS, etc)
3) Now install ERPv4 and run a few programs
4) Check if processes executions are logged in Events tab

Let me know.
 

mekelek

Level 28
Verified
Well-known
Feb 24, 2017
1,661
Exclude app per basis for security or exclude the vendor for usability and convenience.

You'll probably be fine either way
you misunderstood me, i'm allowing the vendor but you can do it two ways, either add the signer to the Trusted signers list, or make an exclusion rule that only has the Signer specified.
same result, different places.

thank you for the wonderful update @NoVirusThanks
 

NoVirusThanks

From NoVirusThanks
Thread author
Verified
Developer
Well-known
Aug 23, 2012
293
Here is a new v4.0 (pre-release) test11:
http://downloads.novirusthanks.org/files/exe_radar_pro_4_setup_test11.exe

*** Please do not share the download link, we will delete it when we'll release the official v4 ***

So far this is what's new compared to the previous pre-release:

+ Rename "Copy Selected Rule" on Rules tab to "Copy/Duplicate Selected Rule"
+ Added new signers to Trusted Vendors list
+ Added "Search Signer on Google" on popup-menu of "Trusted Vendors"
+ Added "Load Signers from File" on popup-menu of "Trusted Vendors"
+ Added "Export List to File" on popup-menu of "Trusted Vendors"
+ Added "Extract Vendor from File" on popup-menu of "Trusted Vendors"
+ Added "Search Signer on Google" on popup-menu of "Trusted Vendors"
+ Added "Search Signer on Google" on popup-menu of "Trusted Vendors"
+ Fixed count of Rules when Exporting them
+ Increased the pagination on Rules tab to 100 items per page
+ Function to add/update Trusted Vendors silently rejects any vendor that matches *Microsoft*
+ Fixed List of internal Vulnerable Processes are only automatically created when ERPv4 is "FirstRun"
+ Fixed List of internal Trusted Vendors are only automatically created when ERPv4 is "FirstRun"
+ Added manual popup menu under Rules Manager (Rules Listview) so internal list of Vulnerable Processes can be manually added back
+ Improved allowing of safe process behaviors
+ Minor fixes and optimizations

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.

Here are some screenshots:

erp2.png


erp1.png
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top