NoVirusThanks OSArmor: An Additional Layer of Defense

Discussion in 'other anti-malware software' started by novirusthanks, Dec 17, 2017.

  1. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    Awesome. Will install test build 38 tonight. Thank you!
     
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    That suggests a course of action to me :)
     
  3. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,942
    I simply use OSA's uninstall exe. That's all I need to uninstall it. No need to use an uninstaller if just want to update. Just my humble opinion.
     
  4. Azure Phoenix

    Azure Phoenix Registered Member

    Joined:
    Nov 22, 2014
    Posts:
    1,560
    Does Revo use the built-in uninstaller of OSarmor first?
     
  5. kdcdq

    kdcdq Registered Member

    Joined:
    Apr 19, 2002
    Posts:
    815
    Location:
    A Non-Sh*thole State
    Build 38 running great on 4 W10 1709 x64 systems.
     
  6. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Yes, then Revo searches for left over traces.
     
  7. Azure Phoenix

    Azure Phoenix Registered Member

    Joined:
    Nov 22, 2014
    Posts:
    1,560
    Ok. I think that explains it. The current Iobit Uninstaller doesn't seem to use the built-in uninstaller of products.

    And I'm guessing that's why it has issues uninstalling OSarmor.
     
  8. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Yes. It uses the softwares uninstaller first, and then scans for leftovers.
     
  9. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Cerber used netsh to add Win firewall rules to block Windows Defender cloud scanning capability. One way among many to modify Win firewall rules and settings. I will never use the Win firewall since its settings are stored in clear text in the registry.
    https://myonlinesecurity.co.uk/cerber-using-firewall-rules-to-disable-windows-defender/
     
  10. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    But that means you still let Cerber on to your machine somehow anyway, doesn't it?
     
  11. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    Here is a new v1.4 (pre-release) test39:
    http://downloads.novirusthanks.org/files/osarmor_setup_1.4_test39.exe

    *** Please do not share the download link, we will delete it when we'll release the official v1.4 ***

    So far this is what's new compared to the previous pre-release:

    + Prevent Base Filtering Engine (BSE) from being disabled via cmdline
    + Improved detection of suspicious command-lines
    + Improved OSArmor self defense (basic)
    + Fixed some false positives

    To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.

    @itman

    OSA would have blocked it at beginning with the rules:

    Block execution of .js scripts
    Block any process executed from wscript.exe

    @Sampei Nihira

    1) Iobit Uninstaller FP should be fixed now.

    2) Should be fixed now (/VERYSILENT and /SILENT "without space" fix).

    No, it would only filter for command-lines related to turning off or disabling Windows Firewall.

    Yes, it also covers sc.exe stop MpsSvc, etc
     
  12. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Andreas it can be hard to keep up with you. Will install 39 a bit later. Thanks a bunch for an excellent piece of software
     
  13. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,629
    It always runs the software's own installer first. It uninstalls software which uses Windows Installer, without showing the usual prompt asking if you want to proceed with uninstalling.
     
  14. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Yes, I am aware of that. Much better way is to run netstat via .Net using a C# program:
    https://social.msdn.microsoft.com/F...ion-for-windows-7-machine?forum=csharpgeneral
     
  15. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    (Dizzy!)

    Rock On Andreas :argh:
     
  16. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    I second this. Just installed test 39 build. Will report back tomorrow if any problems arise. Thank you!
     
  17. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi Andreas

    Build 39 installed and running fine.

    Request?? would it be worth blocking system.management.automation.dll It's part of the powershell mess.


    Pete
     
  18. JoWazzoo

    JoWazzoo Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    241
    Location:
    Ether
    Agree that Beta testing of this is a challenge. :) Especially when also trying ERP and SysHardener.

    TY Andreas
     
  19. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    These products are amazing already, but I am also weary of testing them all at once on the same machine, until they are more stable (I guess ERP 4 has a way to go).

    I do hope Andreas develops and maintains them separately for those that want that granularity, but I would also kinda like to see some sort of converged product option eventually (with different defaults for the novice / intermediate / expert).

    But either way, Andreas' stuff will increasingly become core to all my systems.
     
  20. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Thanks Andreas! Build 39 running smoothly here.
     
  21. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    Trying an experiment I installed the lastet Avast Free AV on my current setup. After a restart OSA UI tray icon failed to start. Double clicking on the desktop shortcut started OSA UI but protection is disabled. Clicking Enable does nothing.

    Probably going back to Windows Defender shortly.

    Edit: Another restart and OSA started without problem so may have been a temporary glitch, although BlackFog Privacy service hasn't started properly with Avast installed yet.
     
    Last edited: Mar 6, 2018
  22. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    Planning to join "Prevent Base Filtering Engine (BSE) from being disabled via cmdline" and "Prevent Windows Firewall from being disabled via command-line" in "Prevent important Windows Services from being disabled", and include Windows Defender, Security Essentials, Windows Update, Security Center (suggested by an user via email).

    Will release the new build later or tomorrow.

    A client has just sent me a log file of OSArmor that blocked a recent "MuddyWater" APT threat in a few workstations:

    Code:
    Date/Time: 06/03/2018 11:18:59
    Process: [5104]C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
    Parent: [4132]C:\Windows\System32\wmiprvse.exe
    Rule: BlockPowerShellEncodedCommands
    Rule Name: Block execution of PowerShell encoded commands
    Command Line: powershell.exe  -exec Bypass -c iex([System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String((get-content C:\\ProgramData\\WindowsDefender.ini))))
    Signer:
    Parent Signer:
    
    Here are more information about recent "MuddyWater" attack:
    https://sec0wn.blogspot.it/2018/03/a-quick-dip-into-muddywaters-recent.html

    @Krusty

    Also other users reported similar issues "OSArmor is disabled after a restart" with Avast installed.

    Personally I tested Avast + OSA on a W10 VM and found no issues, but I excluded all OSA .exe files on Avast:
    https://www.youtube.com/watch?v=nQCMcu1_G2s

    //Everyone

    I plan to enable a few option inA dvancted tab by default prior to releave OSA 1.4:

    Block specific locations

    Block scripts execution

    Other useful block-rules

    Attacks mitigation rules

    These rules should not create FPs and should be fine with beginner users too.

    What do you think guys?
     
  23. guest

    guest Guest

    @novirusthanks

    Some apps like Slack or Discord have their executables on user's folder (appdata), this should be handled carefully.
     
  24. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I agree, I use the Napster(Rhapsody) Music service and it install's totally in Appdata. I'll test for you.
     
  25. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hi Krusty

    AV's are gettting tricky as they ad new features. Back a few versions the installation of OSA broke for me. Turns out I now need to disable EAM and it installs.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.