NoVirusThanks OSArmor: An Additional Layer of Defense

Discussion in 'other anti-malware software' started by novirusthanks, Dec 17, 2017.

  1. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,373
    Location:
    Italy
    OSArmor vs Eicar Test-Virus

    http://sendvid.com/0my3ponu

    :):thumb:
     
    Last edited by a moderator: Dec 25, 2017
  2. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,283
    Location:
    UK
    "
    Date/Time: 25/12/2017 10:57:00
    Process: [1824]C:\apcupsd\bin\apcupsd.exe
    Parent: [892]C:\Windows\System32\services.exe
    Rule: BlockSuspiciousProcesses
    Rule Name: Block execution of suspicious processes
    Command Line: "c:\apcupsd\bin\apcupsd.exe" /service
    Signer:
    Parent Signer:"

    v1.3 this occurs but under v1.4 it works fine so anothe FP done :)
     
  3. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Belarc Advisor gets stuck at "Updating the profile of the computer". Desktop become unresponsive. OSA is silent. Belarc Analysis afaik calls powershell. Since, I return desktop control when Belarc Advisor gets stuck with forced shutdown. I'll leave further observe to you. 1.4 rules default. Thanks
     
    Last edited: Dec 25, 2017
  4. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,954
    Suggestion: It would be good to see another icon in the task bar when protection is disabled.
     
  5. plat1098

    plat1098 Guest

    :) Thanks! Very good to know.

    Will add my request to the others to be able to scroll thru the Configurator.
     
  6. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,954
    + 1
     
  7. liba

    liba Registered Member

    Joined:
    Jan 21, 2016
    Posts:
    344
    i cant start CentBrowser
    C:\Users\USERNAMEAppData\Local\CentBrowser\Application\chrome.exe

    How do I exclude ?

    this is not working

    [%PROCESS%: C:\Users\USERNAME\AppData\Local\CentBrowser\Application\chrome.exe] [%PARENTPROCESS%: C:\Users\USERNAME\AppData\Local\CentBrowser\Application\chrome.exe] [%PROCESSCMDLINE%: /param1 /param2]
     
  8. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,954
    @liba What rule blocked CentBrowser? Could you possibly post the content of your log folder?
     
  9. liba

    liba Registered Member

    Joined:
    Jan 21, 2016
    Posts:
    344


    Process: [3048]C:\Users\test\AppData\Local\CentBrowser\Application\chrome.exe
    Parent: [1668]C:\Windows\explorer.exe
    Rule: BlockUnsignedProcessesAppDataLocal
    Rule Name: Block execution of unsigned processes on Local AppData
    Command Line: "C:\Users\test\AppData\Local\CentBrowser\Application\chrome.exe"
    Signer:
    Parent Signer:
     

    Attached Files:

  10. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,954
    This means that unsigned executables from the AppDataLocal folder are blocked. Could you disable this rule in OSArmor and try again to start CentBrowser?
     
  11. guest

    guest Guest

    Use both rules:
    Code:
    [%PROCESS%: C:\Users\*\AppData\Local\CentBrowser\Application\chrome.exe] [%PARENTPROCESS%: C:\Users\*\AppData\Local\CentBrowser\Application\chrome.exe]
    [%PROCESS%: C:\Users\*\AppData\Local\CentBrowser\Application\chrome.exe] [%PARENTPROCESS%: C:\Windows\explorer.exe]
    
    If you still get blocked processes, use these:
    [%PROCESS%: C:\Users\*\AppData\Local\CentBrowser\Application\*.exe] [%PARENTPROCESS%: C:\Users\*\AppData\Local\CentBrowser\Application\*.exe]
    [%PROCESS%: C:\Users\*\AppData\Local\CentBrowser\Application\chrome.exe] [%PARENTPROCESS%: C:\Windows\explorer.exe]
    
    Only disable the rule "Block execution of unsigned processes on Local AppData" as a last resort. Try exclusions first.
     
  12. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    In a few days will upload the new v1.4 pre-release build.

    @guest

    Yes, it uses the rules creation schema from SOB.

    We have developed a private service-only app for companies based on SOB technology.

    We have no plan yet to update SOB GUI, but who knows :)

    @bjm_

    Have downloaded Belark software and will see what happens.

    @Buddel

    Sure we'll add it, we'll change the tray icon to grey color when protection is disabled.

    @plat1098

    We'll try to do something about that too.

    @liba

    The first two exclusion rules suggested by @mood should work just fine.
     
  13. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,954
    Brilliant! Thank you!
     
  14. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,509
    My issues with this and Heimdal Pro have seemed to have disappeared. Thank you for all the updates/fixes. Cheers!
     
  15. ArchiveX

    ArchiveX Registered Member

    Joined:
    Apr 7, 2014
    Posts:
    1,501
    Location:
    .
  16. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,954
    Interesting article, @ArchiveX However, the author does not seem to be good at counting:
    It comes preloaded with more than 30 security policies that help in distinguishing between the normal and bad behavior of a process.
    It's not just 30 policies; it's twice that number.:)
     
  17. guest

    guest Guest

    yes i was aware of that ;)

    Rules aren't very complicated to implement in the actual SOB, you made a clear and precise documentation; it is just extremely laborious when you have hundreds of them to make :p
     
  18. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,253
    Location:
    Among the gum trees
    Hi @novirusthanks ,

    Checking the release notes for all releases it looks like we are still waiting for Secure Boot compatibility?

    Thanks.
     
  19. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,019
    Dec 18, 2017
    Yes, as[low]ap....
     
  20. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,954
    On a side note, does it make sense to run ERP 4 and OSArmor together? Would be an interesting combo, but there may be considerable "overlap". Maybe @novirusthanks can shed some light on this.:)
     
  21. Azure Phoenix

    Azure Phoenix Registered Member

    Joined:
    Nov 22, 2014
    Posts:
    1,560
    I asked whether VoodooShield + OSarmor would be redundant. Based on the replies, it apparently wouldn't. If that's the case, then OSarmor + EXE radar pro should be fine too.
     
  22. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,954
    VS and OSA are somewhat different, so I don't see an "overlap" here. However, ERP and OSA use the same "skeleton", so they are very similar. It is my understanding that OSA is some kind of pre-configured ERP, which is perfectly suitable for less computer-savvy users, whereas ERP is much more complex and therefore only suitable for more advanced users. Due to their similarity, there might be considerable "overlap".
     
  23. guest

    guest Guest

    OAS blocks by default via set rules unless you create a exclusion
    ERP ask by default.

    in theory OAS should block certain actions while ERP will ask about those not blocked by OAS.
     
  24. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,954
    So it's basically the same app? OSA blocks a certain action by default, whereas ERP asks the user whether this action should be blocked or not? So, if you don't want to be asked, ERP is redundant? Or, if you want to asked, OSA is redundant? Hm... maybe you're right. I really don't know. The question is whether or not it makes sense to use both apps on the same machine.
     
    Last edited: Dec 27, 2017
  25. guest

    guest Guest

    the true power of ERP is not what it ask/block/allow by default, it always was it granularity via its extraordinary rules editor.
    I always considered ERP as the king of anti-exe because you could create very complex rules (for any apps/processes) very easily then lock the system then only allowed rules are authorized.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.