NoVirusThanks OSArmor: An Additional Layer of Defense

Discussion in 'other anti-malware software' started by novirusthanks, Dec 17, 2017.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    15,193
    Location:
    The Netherlands
    I was just about to write this, you need a specialized anti-ransomware tool, to block ransomware that's launched manually. But anyway, seems like a very exciting tool, something that should also be in EXE Radar, but then with some more control. :thumb:
     
  2. Circuit

    Circuit Registered Member

    Joined:
    Oct 7, 2014
    Posts:
    939
    Location:
    Land o fruits and nuts, and more crime.
    Really doesn't need more control than what is offered.
    So far so good!
     
  3. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Very cool! so it seems like it's a stand-alone behavior blocker? This is a great little tool Andreas. Thanks :) The systray icon reminds me of MBAE ;)

    ~ Removed VirusTotal Results per Policy ~
     
    Last edited by a moderator: Dec 17, 2017
  4. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,629
    That's what I thought when I first saw this icon.:D
     
  5. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Why does it install to C:\?
     
  6. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,292
    Location:
    USA, MICHIGAN
    " It is lightweight, zero-configuration and runs in the background "

    How light is light what is everyone seeing?
     
  7. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Less than 5mb here

    Why does it say blocked chrome.exe?

    2017-12-17_171809.png
    Can it run with sandboxie installed?

    EDIT: I rebooted and the ram increased a tad...

    2017-12-17_172619.png

    it's blocking parts of chrome

    Code:
    Date/Time: 12/17/2017 5:03:47 PM
    Process: [6576]C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Parent: [6604]C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Rule: BlockPowerShellEncodedCommands
    Rule Name: Block execution of PowerShell encoded commands
    Command Line: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Mike\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Mike\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=63.0.3239.108 --initial-client-data=0x98,0x9c,0xa0,0x8c,0xa4,0x7fef10c5720,0x7fef10c5760,0x7fef10c5738
    Signer: Google Inc
    Parent Signer: Google Inc
     
    Date/Time: 12/17/2017 5:27:54 PM
    Process: [5048]C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Parent: [4948]C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Rule: BlockPowerShellEncodedCommands
    Rule Name: Block execution of PowerShell encoded commands
    Command Line: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Mike\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Mike\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=63.0.3239.108 --initial-client-data=0xa8,0xac,0xb0,0xa4,0xb4,0x7fef4125720,0x7fef4125760,0x7fef4125738
    Signer: Google Inc
    Parent Signer: Google Inc
     
    
     
    Last edited: Dec 17, 2017
  8. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Where would you expect it to install??
     
  9. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    C:\Program Files\NoVirusThanks

    rather than
    C:\OSArmorDevSvc
     
  10. Beyonder

    Beyonder Registered Member

    Joined:
    Aug 26, 2011
    Posts:
    545
    Any ETA on when that will change?
     
  11. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,170
    Location:
    Italy
    @Overkill

    Yes it is, and it uses pre-built rules (so no configuration needed).

    For now we install it on C:\OSArmorDevSvc\, we may change it in next builds.

    Thanks for reporting the FP about chrome.exe, we'll fix it asap.

    Memory usage vary from 5 MB to 10 MB (approximately).

    @Buddel

    This is the icon in use by OSArmor:
    https://www.iconfinder.com/icons/1034363/advantage_protect_protection_security_shield_icon#size=128

    :)

    @Rasheed187

    The primary objective of OSArmor is to be simple and zero configuration, for full control on processes\applications then there is ERP.

    @Beyonder

    Hope within one week or so, it doesn't depend on us but on how much it takes to receive the EV codesign.
     
  12. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,629
  13. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,292
    Location:
    USA, MICHIGAN
    Is there any manual scan features or does it totally run quiet in the background? how does it do product updates/version/fixes?
     
  14. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    I don't suppose you could add enable/disable buttons? Like in my case maybe i'd like to disable it until you fix the chrome FP, sure I know I could just exit the program, but would it completely exit or would it still be partially running?
     
  15. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,170
    Location:
    Italy
    @Overkill

    Who said you have to wait for the fix? :)

    I updated OSArmor with these changes:

    - Fixed FP with chrome.exe
    - Block flag TESTSIGNING on Bcdedit.exe
    - Allow PortableApps (.paf.exe) by Rare Ideas, LLC
    - Minor improvements

    Please just uninstall it from Control Panel and then download and install it again from:
    http://www.novirusthanks.org/products/osarmor/

    Let me know if the chrome.exe FP is gone for you.

    We'll add a enable\disable option soon.

    @daman1

    OSArmor uses internal rules to analyze processes behaviors and block suspicious processes.

    There is no option to scan an executable or a file on disk.

    We will think about adding a sort of auto-update feature.
     
    Last edited: Dec 17, 2017
  16. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,292
    Location:
    USA, MICHIGAN
    So to update you need to uninstall then re-download? o_O
     
  17. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,170
    Location:
    Italy
    For now yes, we'll add auto-update soon :)
     
  18. daman1

    daman1 Registered Member

    Joined:
    Mar 27, 2009
    Posts:
    1,292
    Location:
    USA, MICHIGAN
    :thumb:
     
  19. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Thanks for the quick fix :)

    Yes FP with chrome is fixed!
     
    Last edited: Dec 17, 2017
  20. guest

    guest Guest

  21. Infected

    Infected Registered Member

    Joined:
    Feb 9, 2015
    Posts:
    1,084
    You guys need to be patient. It's a brand new app, not everything is going to be perfect or be fixed immediately...
     
  22. guest

    guest Guest

    sure but some of us are used to do it with NVT.

    btw @novirusthanks seems quite a while since we don't get a new ERP 4 build to beta test. seems you are putting lot of changes for the next one ;)
     
  23. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    Now I have an Anti-Executable and Behavior Blocker from NVT! along with my other security, I feel very safe.
     
  24. clubhouse1

    clubhouse1 Registered Member

    Joined:
    Sep 26, 2013
    Posts:
    1,124
    Location:
    UK


    +1
     
  25. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,170
    Location:
    Italy
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.