OXYGEN THIEF

Bardzo aktywny
Członek Załogi
Administrator
Dołączył
26 Maj 2010
Posty
35941
Reakcje/Polubienia
25032
Miasto
Trololololo

al

Marszałek Forum
Członek Załogi
Administrator
Dołączył
22 Lipiec 2012
Posty
10002
Reakcje/Polubienia
10636
Miasto
Somewhere over the rainbow.
Here is a new v4.0 (pre-release) test2:
Zaloguj lub Zarejestruj się aby zobaczyć!


*** Please do not share the download link, we will delete it when we'll release the official v4 ***

So far this is what's new compared to the previous pre-release:

+ Fixed writing of rules (matching of fields)
+ Fixed matching of wildcard characters (Like to) on rules
+ Fixed matching of parent process on rules
+ Fixed showing of main window on multi-monitors
+ Fixed showing of "Hide Main Window" on Tray Icon
+ Added option "Do not auto-close notification dialog" (when a process is blocked)

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.

There were some issues on rules, please retry with this new build (should work fine now).

To use wildcards (? and * characters) just select "Like to" instead of "Equal to".
 

al

Marszałek Forum
Członek Załogi
Administrator
Dołączył
22 Lipiec 2012
Posty
10002
Reakcje/Polubienia
10636
Miasto
Somewhere over the rainbow.
Here is a new v4.0 (pre-release) test3:
Zaloguj lub Zarejestruj się aby zobaczyć!


*** Please do not share the download link, we will delete it when we'll release the official v4 ***

So far this is what's new compared to the previous pre-release:

+ In Expression Builder "Read Data from File" on Parent doesn't parse the full file path
+ There are two undeletable categories named Learning Mode and Vulnerable Processes
+ When on Learning Mode, all automatically added rules should be added on rule category "Learning Mode"
+ Possibility to create\edit a rule from Events
+ Added button "Custom Rule" on Alert Dialog to easily create a custom rule
+ Stats are now live on the Main tabsheet (running time, # analyzed, # blocked, # allowed etc.)
+ Event log file is now created with file extension ".date.log"
+ Settings category fields are now bolded (security, notification dialog, sound effects etc.)
+ Any allowed event is now green in the Events tab
+ "View Logs" now opens the logs folder instead of selecting it only from the "EXE Radar Pro" parent folder
+ Uncluttered Settings checkbox controls so they're aligned better in the UI and uniform
+ Exclude Process dialog now has the "Delete" button disabled when an excluded process is NOT selected
+ Added 3 new checkboxes to Settings: Allow Known Safe Process Behaviors, Allow Trusted Vendors, Block Suspicious Process Behaviors
+ The option "Allow Known Safe Process Behaviors" incorporates the safe command-line strings in a safer way compared to ERPv3
+ Fixed file permission issue on .db and .log files
+ When adding a rule that is already present, close the Rule Editor window when Save button is clicked
+ On Settings tab renamed the "Manage Excluded Processes" to "Manage Exclusions for Blocked Notifications"
+ Deleting a rule understands the DELETE key and editing a rule understand the ENTER/RETURN key
+ When you double-click an event on Events tab it shows the event details
+ Added popup menu on Rules listview to edit\delete selected rule(s)
+ Added popup menu on Events listview to show process properties, open containing folder, lookup SHA1 on VirusTotal, etc
+ Show in the Events listview also integrity level, username/domain and system file (true\false)
+ Fixed vertical scrollbar from not working on events
+ Fixed exporting and importing of rules
+ Minor fixes and optimizations

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.

erp-events-png.260666
erp-settings-png.260667
erp-custom-rule-alert-dialog-png.260668
 

OXYGEN THIEF

Bardzo aktywny
Członek Załogi
Administrator
Dołączył
26 Maj 2010
Posty
35941
Reakcje/Polubienia
25032
Miasto
Trololololo

Ircus

Bardzo aktywny
Ekspert
Dołączył
26 Maj 2010
Posty
13030
Reakcje/Polubienia
43980
Here is a new v4.0 (pre-release) test4:
Zaloguj lub Zarejestruj się aby zobaczyć!


*** Please do not share the download link, we will delete it when we'll release the official v4 ***

So far this is what's new compared to the previous pre-release:

+ Added option to "Password Protect Power Options"
+ Password protect also "Allow" and "Custom Rule" button on Alert Dialog
+ Added button to set/change password
+ Fixed "Allow Known Safe Process Behaviors"
+ Added more rules on "Allow Known Safe Process Behaviors"
+ Support wildcard on "Exclude from Notification" rules
+ Added "Close" button on "Event Details" window
+ Fixed counting of stats on main window
+ The issue with "black screen" or "desktop is not loaded" should be fixed
+ Fixed "the Protection Mode is changing after options in Settings has been ticked/unticked"
+ On "Export Rules" ask to overwrite the file if it already exists
+ On "Export Rules" show a warning message if the Rules.xml is not selected
+ Order of fields on "Expression Builder" is same as on "Alert Dialog"
+ Option "Allow Microsoft Windows Apps" is checked by default
+ Option "Allow All Software from Program Files Folder" is checked by default
+ Option "Allow All Microsoft-Signed Processes" is checked by default
+ Minor fixes and optimizations

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.

Uploaded a new list of vulnerable processes (XML):
Zaloguj lub Zarejestruj się aby zobaczyć!
 

Ircus

Bardzo aktywny
Ekspert
Dołączył
26 Maj 2010
Posty
13030
Reakcje/Polubienia
43980
Here is a new v4.0 (pre-release) test5:
Zaloguj lub Zarejestruj się aby zobaczyć!


*** Please do not share the download link, we will delete it when we'll release the official v4 ***

So far this is what's new compared to the previous pre-release:

+ Fixed option "Allow All Software from Program Files folder"
+ Rules are now checked for existing conflictions by action (Allow, Deny, Ask)
+ Expression Builder Parent Process "Name" field renamed to "Full Path Name" for clarity
+ Expression Builder Parent Process "Hash" (SHA1) field is now moved above "Signer" field
+ Removed the option (checkbox) "Block Suspicious Process Behaviors" from "Settings" tab
+ Pre-filled the "Hash (SHA1)" field for Parent Process when from "Custom Rule"->"Edit Expression" is clicked on Alert Dialog
+ Improved fix for "black screen" or "desktop is not loaded" issue
+ Minor fixes and optimizations

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.
 

Ircus

Bardzo aktywny
Ekspert
Dołączył
26 Maj 2010
Posty
13030
Reakcje/Polubienia
43980
Here is a new v4.0 (pre-release) test6:
Zaloguj lub Zarejestruj się aby zobaczyć!


*** Please do not share the download link, we will delete it when we'll release the official v4 ***

So far this is what's new compared to the previous pre-release:

+ Fixed variable-length string for process name, command-line, etc
* Note: Old Rules.DB file in \ProgramData\NoVirusThanks\EXE Radar Pro\Databases MUST be deleted before running the new build
* Or you can export any current rules you have and import after the new rules.db is created
+ Fixed Edit Rule dialog for saving fields such as Disable/Enabled status, Category, Action etc.
+ Fixed "the protection mode is always reset to Alert Mode"
+ Fixed Show the actual (active) protection mode when I hover with the mouse over the tray icon
+ New Action = "Exclude" to globally exclude (allow) specific events
* It will override the other actions and will be checked as first
+ Improved order to check actions and auto-allow options
+ Minor fixes and optimizations

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.

You can use the new Action = Exclude to exclude events from Action = Ask rules.
 

Ircus

Bardzo aktywny
Ekspert
Dołączył
26 Maj 2010
Posty
13030
Reakcje/Polubienia
43980
Here is a new v4.0 (pre-release) test7:
Zaloguj lub Zarejestruj się aby zobaczyć!


*** Please do not share the download link, we will delete it when we'll release the official v4 ***

So far this is what's new compared to the previous pre-release:

+ Right-click option "Enable Selected Rule(s)" on Rules tab
+ Right-click option "Disable Selected Rule(s)" on Rules tab
+ Improved "Allow Known Safe Process Behaviors"
+ Minor fixes and optimizations

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.
 

ichito

Bardzo aktywny
Dołączył
23 Październik 2010
Posty
633
Reakcje/Polubienia
235
Miasto
Kraków
Człowieku!...ogarnij się!...po pierwsze - jest wyraźna uwaga autora by nie upubliczniać linku do pliku...po drugie - cytowanie listy zmian w softach wraz ze źródłem jest kindersztubą na forach. Zerknij sobie na pkt.6 tutejszego Regulaminu.
 

al

Marszałek Forum
Członek Załogi
Administrator
Dołączył
22 Lipiec 2012
Posty
10002
Reakcje/Polubienia
10636
Miasto
Somewhere over the rainbow.
Here is a new v4.0 (pre-release) test8:
Zaloguj lub Zarejestruj się aby zobaczyć!


*** Please do not share the download link, we will delete it when we'll release the official v4 ***

So far this is what's new compared to the previous pre-release:

+ Deny action is checked before Allow* actions on Settings tab
+ Fixed showing of Alert Dialog on dual monitors
+ Show the category of the triggered Ask rule in the Alert Dialog
+ Improved "Allow Known Safe Process Behaviors"
+ Minor fixes and optimizations

Zaloguj lub Zarejestruj się aby zobaczyć!
 

Ircus

Bardzo aktywny
Ekspert
Dołączył
26 Maj 2010
Posty
13030
Reakcje/Polubienia
43980
Here is a new v4.0 (pre-release) test9:
Zaloguj lub Zarejestruj się aby zobaczyć!


*** Please do not share the download link, we will delete it when we'll release the official v4 ***

So far this is what's new compared to the previous pre-release:

+ Added possibility to add/edit/delete/disable/enable Trusted Vendors List
+ Play Beep Sound (for Alert and Blocked Notify dialogs) are renamed to "Play a custom sound ..." and will play the loon WAV sound
+ Auto-check the field "Command-Line" in the Alert Dialog if category is "Vulnerable Processes"
+ If in the Alert Dialog the category is "Vulnerable Processes", when we click button "Allow" and the checkbox "Remember this action" is checked, the Action of the rule should be "Exclude" (not "Allow")
+ Save/load column size of Rules/Events listviews
+ Save/load window size of main window
+ Make the "Expression Builder" window re-sizable to enable more of the field values to be visible
+ Fixed the "Edit rule from event" feature does not appear to always work
+ Restored pagination (50 items per page)
+ Do not show "Category:" on Alert Dialog if the category is not applicable
+ Improved "Allow Known Safe Process Behaviors"
+ Minor fixes and optimizations

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.
 

Elvis

Bardzo aktywny
Ekspert
Dołączył
21 Czerwiec 2012
Posty
2304
Reakcje/Polubienia
850
Here is a new v4.0 (pre-release) test10:
Zaloguj lub Zarejestruj się aby zobaczyć!


*** Please do not share the download link, we will delete it when we'll release the official v4 ***

So far this is what's new compared to the previous pre-release:

+ Fixed the link to lookup file sha1 on Virustotal on Events tab popup-menu
+ Fixed When clicking "Edit Expression" on "Rule Editor" it shows a warning message "You must enter a valid expression"
+ Fixed Wrong categories/Categories which are not applicable are being shown in the Alert Dialog
+ Fixed Cosmetic issue (Logfile related): Normally a "-" is shown in the logfile if the Expression or Category is empty
+ Fixed Changing of the column size in the Rules listview seems to have no effect ("ruleColumnX:") (but Events seems to work ["eventColumnX:"])
+ Fixed Windows Apps weren't allowed by the option "Allow Microsoft Windows Apps" in Settings tab
+ Fixed Possible Rules conflict -> moved Deny action checking to be before Ask action
+ Fixed The warning message "You must enter a valid expression" is present also on the Alert Dialog -> Custom Rule
+ Fixed Command-line string is empty for very long command-line strings
+ Improved allowing of safe process behaviors
+ "Vulnerable Processes" are now pre-loaded on the Rules tab when the program is first installed
+ Smarter way to handle signed processes not found in Trusted Vendors list while on "Learning Mode" -> if a signer is not present in Trusted Vendors list (when in Learning Mode), it is auto-added and enabled/checked
+ Added more signers on Trusted Vendors list
+ Added new option "Copy Selected Rule" -> The selected rule is "copied" on the newly created rule with same parameters
+ Added new option "Copy Selected Rule to Clipboard" -> It copies the selected rule to clipboard in XML format so can be easily pasted/shared on forums
+ Added new option "Locate Process File in Explorer" on Events tab
+ Added new option "Locate Parent Process File in Explorer" on Events tab
+ Added new option on Settings tab When on Lockdown Mode auto-block "Ask"-action processes (unchecked by default)
+ Minor fixes and optimizations

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.
 
Do góry