NoVirusThanks OSArmor: An Additional Layer of Defense

Discussion in 'other anti-malware software' started by novirusthanks, Dec 17, 2017.

  1. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    Oh okay that must be the case then because I searched thoroughly but couldn't find anything.

    Well maybe let's see if @novirusthanks has a response to this, and if it's actually still a security hole.
     
  2. pernu

    pernu Registered Member

    Joined:
    May 10, 2021
    Posts:
    82
    Location:
    Norway
    I am running OSArmor v1.8.1 with Extreme Protection on, but it blocks EmsisoftEmergencyKit. What can I do to open the block :thumbd:
     
  3. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    Hi pernu,

    if you right-click the OSA tray icon and select Open Logs Folder, the blocked event shoud be in there. Just copy the contents and paste in this thread, removing any personal information such as your name, and include @novirusthanks at the top of the post, and report it as a False positive.
     
  4. pernu

    pernu Registered Member

    Joined:
    May 10, 2021
    Posts:
    82
    Location:
    Norway
    Thank you so much :)
     
  5. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    You're welcome!

    If you get numerous FP's, you might want to consider reducing the Protection Profile to Advanced.
     
  6. pernu

    pernu Registered Member

    Joined:
    May 10, 2021
    Posts:
    82
    Location:
    Norway
  7. pernu

    pernu Registered Member

    Joined:
    May 10, 2021
    Posts:
    82
    Location:
    Norway
    :thumb:
     
  8. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    Hi Guys! I would like to ask for those that employ OSA what protection level is being used? Response either here or via message would be appreciated!
     
  9. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    @pernu,

    to resolve the BlockSignerNotPresent roadblock, you could open the Configurator-> Trusted Vendors tab-> Edit Trusted Vendors List, and add these two for Trusted Vendors:

    Code:
    Emsisoft Limited
    Emsisoft Ltd
    make sure to save the list. This will address both the Portable installer and normal installer.

    @cruelsister

    I have Advanced Level plus a few more Protections enabled, so I'm essentially somewhere between Advanced and Extreme Level.
     
  10. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Hi, I use the Default profile (basic, I think) with a number of rules over and above, particularly in the Scripts section. I'm on my Windows 11 drive at the moment so can't be more specific.

    Any more aggressive than what I have now gets me too much noise from block alerts.
     
  11. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    As plat here above, I'm also using the default profile. I find it a good balance and not much noise.:)
     
  12. pernu

    pernu Registered Member

    Joined:
    May 10, 2021
    Posts:
    82
    Location:
    Norway
    That did the trick. Thank you very much :thumb:
     
  13. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    Advanced Protection plus an assortment of blocked extras, like all of the PUPs.
     
  14. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    :thumb:
     
  15. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,239
    Location:
    Among the gum trees
    Hi cruelsister,

    Advanced Protection +.
     
  16. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Protections profile: Medium (no other selections).
     
  17. Roberteyewhy

    Roberteyewhy Registered Member

    Joined:
    Mar 4, 2007
    Posts:
    611
    Location:
    US
    Protection profile: Extreme Protection with everything checked except 2 Protections (Alerts = Low). Never had a problem.
     
  18. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,784
    Extreme Protection.
    Zero issues here, very few alerts.
     
  19. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    Thank you all for your responses! The reason why I asked is that as OSA has a number of protection levels, one would need to know the most probable OSA security configuration employed by the user in order to do some sort of review.

    Once again, thanks for being kind!
     
  20. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Review it at the default install level which is basic protection only.
     
  21. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    @cruelsister -- I use Win7 with ALL rules of OSA checked. FPs are very VERY rare -- I guess I'm a clean liver. (My kidneys are also tres bien.)
     
  22. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    Have you already heard anything from OSA's developer, regarding the bug that you found? Or are you still testing stuff?
     
  23. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    Here is a pre-release test 2 version of OSArmor PERSONAL v1.8.2:

    Code:
    https://downloads.osarmor.com/osa-personal-1-8-2-setup-test2.exe
    
    @Rasheed187

    The case related to XYplorer is that OSA considers third-party file managers and other programs that meet a specific internal trust score as "not critical" so they are not fully monitored if you have the option "Enable internal rules for allowing safe behaviors" checked, this is done to reduce FPs. With this new test 2 build also XYplorer is monitored but you may expect more FPs. In the next build we plan on adding an option like "Do not monitor specific programs that meet a high trust score" or similar so if checked, XYplorer and other "not critical" programs will not be fully monitored, and allows advanced users to disable this option if needed.

    @pernu

    Thanks for reporting it, have added Emsisoft Limited to Trusted Vendors list.
     
  24. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    NOT me. I do not choose to neuter my Rottweiler.
     
  25. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,239
    Location:
    Among the gum trees
    Possible FP:

    Date/Time: 4/10/2022 10:07:42 AM
    Process: [2928]C:\Windows\System32\schtasks.exe
    Process Size: 229.5 KB (235,008 bytes)
    Process MD5 Hash: 76CD6626DD8834BD4A42E6A565104DC2
    Parent: [11428]C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
    Parent Process Size: 23.94 MB (25,105,696 bytes)
    Rule: BlockSchtasksExe
    Rule Name: Block execution of schtasks.exe
    Command Line: schtasks /run /TN "AMDRyzenMasterSDKTask"
    Signer: <NULL>
    Parent Signer: Advanced Micro Devices, Inc.
    User/Domain: David/DAVID-HP
    System File: True
    Parent System File: False
    Integrity Level: Medium
    Parent Integrity Level: Medium

    Thanks!
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.