[Review] NoVirusThanks ExeRadarPro (Paid)

Discussion in 'NoVirusThanks' started by Umbra Polaris, Apr 19, 2013.

  1. Umbra Polaris

    Umbra Polaris Board Enthusiast Silver Member

    Homepage

    Hi guys,

    Today i will review NVT ExeRadarPro (aka ERP).

    ERP is an Anti-Excutable, this kind of softwares monitors every processes/executable that start or run in your system, if one of them appears to be suspicious/malicious; depending the rules, it will block it or generate an alert and ask for your decision to allow/block the process.

    Anti-executable are simpler than HIPS (which monitors a broader range of processes including DLLs)

    Let's go for a tour (on my Win8 Pro x64)

    1- Resources Usage

    ERP uses only 2 processes, it is very light on my system responsiveness, that is a big "plus".

    [​IMG]


    2- Interface & Tray Icon

    ERP interface is quite simple and easy to use, you don't have to be a computer expert to use it. The tray icon shows some basic options.

    [​IMG]

    Status

    This tab, shows you the main status and informations about your version of ERP.

    Processes

    This tab shows you all active processes running on your system with detailed infos. A right click on a process display many options related to that process.

    [​IMG]

    I like the "search hash on Virus Total " (Virus Total is a security website that scan online a uploaded process against 40+ antivirus engines to determine if it is malicious or clean), so ERP can check directly for you.

    I also appreciate the "Terminate Process" in case of infection, you can kill malicious process that may hamper your accessibility to the system.

    Blacklist

    [​IMG]

    This tab will show you all the blocked processes then you can manage them.

    Whitelist

    [​IMG]

    Here will appear all the whitelisted (trusted) processes, once there the processes will not generate any alert anymore. You have some Sub-Tab:

    - Command Line/Command Line (Wildcards): here you set the whitelisted processes via Command Line and also via Wildcards.
    - Parent Proceses: Here will be shown the parent processes allowed to launch applications.
    - Folders: if you trust a whole folder, you can add it here.
    - No Hash Check: if you want avoid the hash check for some processes, this is the place where you add them.

    Vulnerable Processes

    Here ERP will displays all processes it deems vulnerable to infections, any processes here will be monitored even if you whitelist them (so they will always generate an alert if accessed).

    [​IMG]

    Tip: if you are an advanced user and you know how to differentiate a legit access from a malicious one, you can remove them from the list, so you will not have alerts from them anymore.
    Quarantined Processes

    Here goes the malicious processes quarantined by ERP, you can manage and remove them in case of False Positive.

    [​IMG]


    Password Protect Passwords

    Here you will set a Password and will need to use it to execute any processes you add there.
    For example, you can set a password to deny anyone to launch a sensitive application/software/process.

    [​IMG]



    Temporary Allow

    Here will be displayed the processes allowed to to run until the next reboot; you will mostly use this tab for testing some processes.

    [​IMG]



    Events

    Here will be displayed all the recents events that ERP acted on. It is mostly an history of what happened on ERP.

    [​IMG]




    3- Settings

    This is the options, it is divided into sub-sections, i will describe some of them below:


    General

    [​IMG]

    an interesting options is to allow ERP to allow all process automatically from Windows or Program Files folder; to minimize the number of prompts.


    Advanced

    [​IMG]

    this settings is mostly for block processes from external medias/drives, you can also allow all "signed softwares" to reduce the numbers of alerts.

    Idle

    here you can set ERP to perform an action in a selected time in case of inactivity.

    Policies

    here you can set ERP to be on Lockdown Mode (block any unknown processes not whitelisted) or Trusted Mode (allow any unknown processes not blacklisted)

    Popups

    Here you can set ERP to show the popups alerts when a process is blocked, for how long or exlude a process to generate a popup.

    Password

    here you will set a password to deny other users to modify your settings.

    [​IMG]


    Protection

    Here you will ser ERP to restore Realtime Protection or Lockdown Mode after a defined time if they are disabled.

    Stealth Mode

    Here you will set ERP to be invisible to other users via a hotkey and also lock CD-Roms while in Stealth Mode. useful if you don't want ERP to be known by other users (ex: school computers).

    Quarantine

    here you will set the path of the quarantined processes

    Logs

    Here you can allow the events logging, set the path of the log, and authorize it deletion on shutdown.

    Sound

    Here you can select a sound (system or custom) when a popup is made or when a process is blocked

    Debug

    Here you can generate a debug file , (mostly requested by ERP developers if you have an issue)


    4- Utilities

    Here are shortcuts to some Windows utilities.

    [​IMG]


    PROS

    - Very Light on system responsiveness
    - High level of protection given by well-thought features.
    - Very simple to use
    - Very responsive support team, very open to suggestions

    CONS

    - Beginners may find the numbers of alerts dissuasive, but this is the purpose of all Anti-Executable/HIPS.


    FINAL NOTE

    ERP is a young but very well designed product, it will give you a high level of protection and control over the processes running on your system. I like its simplicity and lightness.
    I highly suggest you to try it.

    i will update this post if new infos are available or if i missed something important.


    Thanks to Andreas from NoVirusThanks for his complementary infos.
     
  2. Google Adsense

  3. KelvinW4

    KelvinW4 Board Enthusiast

    Very good. It is definitely a keeper! :)
     
  4. Umbra Polaris

    Umbra Polaris Board Enthusiast Silver Member

    after ESET HIPS , NVT ones is quiet compared to it. ^^
     
  5. Bala

    Bala Administrator Staff Member

    Haha, lol its been long since I tried ESET and its HIPS. I will give NVT a shot in the following days to come.
     
  6. MrHacker

    MrHacker Initiat3 Silver Member

    Thanks for the great review. I would be trying.
     
  7. matroska

    matroska Member Known Member

    I think this app is better than ap ** uard, CMIIW
     
  8. Umbra Polaris

    Umbra Polaris Board Enthusiast Silver Member

    never tried Appguard ^^
     
  9. Bala

    Bala Administrator Staff Member

    Yes I have used Appguard once, and figured out it guards the windows app from loading. It gave me bsods.
     
  10. artoor

    artoor Moderator Staff Member

    As I use both - AG and ERP, I can tell you guys, that they are really comparable. Each of them has its advantages and disadvantages, but I can say, I prefere ERP to AG. It is easier to configure, and don't tamper with MBR (which can be also disadvantage). Surely, advantage of AG is that it works as a driver (unlike ERP - as a service), but they both do the same good job :D
     
  11. Very helpful. Thanks :cool:
     
  12. gargi2221

    gargi2221 Initiat3

    Thanks for the great review. Thanks
     

Share This Page