NoVirusThanks OSArmor: An Additional Layer of Defense

Discussion in 'other anti-malware software' started by novirusthanks, Dec 17, 2017.

  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Test 7 is bad. Test 8 fixed the problems for me
     
  2. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    Test 8 fixed all my problems, too.
     
  3. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    It turns out that Bouncer driver was loading, but OSArmor was blocking the driver from communicating with the tray icon. Bouncer tray icon uses a cmd command to allow the driver to communicate with it's tray icon.

    Test 8 fixed the problem with Bouncer, and Malwarebytes, but now I have a problem I had with a prior build of OSArmor. It's blocking adguard, Windows Start Menu, Settings, Control Panel, Windows Notification Area, and Cortana. It's all being silently blocked. OSArmor does not report to be blocking anything. This occurred several builds ago, and Adguard happen to get blocked that time as well. I'm using Windows 10 x64 version 1709.
     
    Last edited: Jan 1, 2018
  4. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,951
    Do you have any log messages from OSA you could post here? Do you use default settings for OSA and did you "tweak" it a bit?
     
  5. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Test 8 appears to sort #344
     
  6. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    OSA is not logging anything being blocked. I took a picture of the plug & play message i'm getting when trying to reboot. This also happen the last time I had this problem. The following error is being recorded in Windows Event Viewer. ATI EEU PnP start/stop failed I did some Googling, and it says it might have something to do with my Graphics Card. I have an AMD Radeon HD 6770 Graphics Card.
     

    Attached Files:

  7. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Doing a full uninstall, and reinstall seems to have fixed the problem. That worked the last time also. I have all rules ticked except for the following below.

    Block execution of .CPL (Control Panel) applets
    Block any process executed from mmc.exe
    Block any process executed from wmiprvse.exe
    Block unknown processes executed from TeamViewer
    Block execution of any process related to TreamViewer
    Block execution of any process related to RealVNC
    Block execution of any process related to UltraVNC
    Block execution of any process related to NirSoft
    Block execution of any process related to Radmin
    Block exection of schtasks.exe
     
  8. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
  9. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    Here is a new v1.4 (pre-release) (test9 ):
    http://downloads.novirusthanks.org/files/osarmor_setup_1.4_test9.exe

    *** Please do not share the download link, we will delete it when we'll release the official v1.4 ***

    So far this is what's new compared to the previous pre-release:

    + Fixed blocking of processes executed from mmc.exe
    + Minor fixes and optimizations

    This pre-release version can be installed over the top of the previous one.

    @Sampei Nihira

    I checked your security setup, very minimal and OSArmor should work just fine.

    Will try to reproduce the issue.

    @Cutting_Edgetech

    Yeah, looks like related to the graphic card:

    Win 10 booting delay caused by AMD graphic driver in my laptop
    ATI EEU PnP start/stop failed
    Event Viewer Logs Error [Solved]
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Haven't done any testing, but it' running fine.

    Reminder: The dual monitor issue
     
  11. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,367
    Location:
    Italy
    TH.:thumb::)
     
  12. JoWazzoo

    JoWazzoo Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    241
    Location:
    Ether
    Losing (already lost? :) my mind. Of course at my age, memory is a terrible thing to lose. heh Anyway, how do I ascertain which beta I am testing? I thought it showed me, but now I only see 1.4.0.0. Am I mis-remembering? TIA
     
  13. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    @novirusthanks

    Thanks for this new release. Great new program and i'm anxiously looking forward to all your team does to make it a fabulous useful addition to users security layer.
     
  14. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    The exe is named with the test number. Once installed, it's a guess
     
  15. Charyb

    Charyb Registered Member

    Joined:
    Jan 16, 2013
    Posts:
    679
    When I reset the rules to default the scroll function quits working until I close and reopen the configurator or click on a rule.

    To turn OSArmor off permanently am I to disable it in Services or is there going to be a way to turn it off permanently in the GUI?
     
    Last edited: Jan 2, 2018
  16. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    Here is a new v1.4 (pre-release) (test10):
    http://downloads.novirusthanks.org/files/osarmor_setup_1.4_test10.exe

    *** Please do not share the download link, we will delete it when we'll release the official v1.4 ***

    So far this is what's new compared to the previous pre-release:

    + Block any process executed from javaw.exe (except java.exe)
    + Block any process executed from java.exe
    + Fixed display of GUI and Configurator on multi-monitors
    + Minor fixes and optimizations

    This pre-release version can be installed over the top of the previous one.

    We're now working on the driver to support Secure Boot.

    @Charyb

    This test 10 should fix it.

    You disable OSArmor via tray icon -> Disable Protection, but if you want to disable it permanently you need to disable the service (OSArmorDevSvc).

    @Peter2150

    Should be fixed now, let me know if it works fine.
     
  17. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,951
    Thanks for the update. BTW, I have always enabled all options (with only two exceptions: block execution of any process related to NirSoft and SecurityXploded). So far, so good. Works really great, but I also have a couple of exclusion rules.:)
     
  18. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Dual monitor issue along with configurator is fixed. Thanks Andreas
     
  19. plat1098

    plat1098 Guest

    Nice to scroll thru the rules now. :) Some rules like blocking known Bitcoin miner command-lines suggest a need for periodic updating, right? Would the interface be getting some sort of updater? For version/test #--same, I only see the date it was modified in Properties, no test #.
     
  20. rdsu

    rdsu Registered Member

    Joined:
    Jun 28, 2003
    Posts:
    4,537
    @novirusthanks ,

    I'm using the v1.4 test 10 without issues...

    Inside Configuration window, can you group the protections by their type, for better understanding...?

    Keeps the great work!
     
  21. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I just don't want to reformat! Not my thing to do! :)
     
  22. Rainwalker

    Rainwalker Registered Member

    Joined:
    May 18, 2003
    Posts:
    2,720
    Location:
    USA
    Why is Panda Security\Panda Devices Agent and PSExpCampaign.exe considered unsafe and being blocked? Does OSArmor not have a whitelist? I think PSExpCampaign.exe is an advertising component and \Panda Devices Agent is required for the anti-virus cloud component to work.
     
  23. guest

    guest Guest

    What is mentioned in the log file?
     
  24. Rainwalker

    Rainwalker Registered Member

    Joined:
    May 18, 2003
    Posts:
    2,720
    Location:
    USA
    Rule: BlockSuspiciousProcesses along what appears to be an I.D. of my computer, some other info for them and what I mentioned in post #372.
     
    Last edited: Jan 3, 2018
  25. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    This version is working great, but could you fix the scrollbar to move up or down as I'm moving it? because, I have to use the arrows currently...check out this short video to see what I mean...
    https://sendvid.com/7j9krykz
     
    Last edited by a moderator: Jan 3, 2018
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.