- Jul 3, 2015
- 8,153
yes, everything looks good to me.1.Like this
View attachment 126284
2. Like this
View attachment 126285
Version is 3.1 (24062015)
View attachment 126286
yes, everything looks good to me.1.Like this
View attachment 126284
2. Like this
View attachment 126285
Version is 3.1 (24062015)
View attachment 126286
@Av Gurus: about mshta, yes, you are right, the place to add it is vulnerable processes.
Anything that you add to that list will produce a prompt, even if you have whitelisted it somewhere else.
The only way to stop prompting for something on the VPL is to whitelist a particular command-line string.
one last thought: if it was me, before going into lockdown mode, I would put it in learning mode, and do a couple reboots, and sign in and out of all my user accounts. This will whitelist the crucial command lines, and save you headaches.
it won't work. that process is on the VPL, and VPL will override the whitelist. You would have to whitelist a command-line string that defines what exactly the vulnerable process is allow to do.
yes, lockdown mode will respect your whitelist.So, everything that was detected in learning mode will be whitelisted when put in Lockdown Mode?
Tips for installing new software (know to be good)...put in Allow/Learning/Disable Mode?
View attachment 126288
yes, lockdown mode will respect your whitelist.
for installing new software, you can put it in alert mode if you are interested to see what is happening, or just disable, and whitelist the program after installation.
easiest way to whitelist after install is try to run it, let it get blocked, and then go to the log tab (or whatever they call it, I can't remember), and look for the red line, and right-click it and choose whitelist.
that's exactly right.Like this:
View attachment 126289
correct, ERP is purely an anti-executable. But remember that if the malware cannot execute, then you don't even need to block it in memory.But I read that ERP is unable to prevent the attack in memory
Me too.i cant live without Appguard
hard-core.i cant live without Appguard
Latest free beta version but stable and the best one:Wheres the link for the free version?
http://downloads.novirusthanks.org/files/EXERadar_Pro_x86_x64_v3.1_24062015_BUILD1.exe
the way to do it is to whitelist it as a command line, and then edit the command line, replacing the string of random characters with an asterisk: *
I don't have dismhost.exe in any of ERP's lists. If triggered or run somehow, then it will alert me and block it as I think dismhost.exe is not used by my system Win8.1 x64 ever.the way to do it is to whitelist it as a command line, and then edit the command line, replacing the string of random characters with an asterisk: *