NoVirusThanks OSArmor: An Additional Layer of Defense

Discussion in 'other anti-malware software' started by novirusthanks, Dec 17, 2017.

  1. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    Very Gooooood !! :thumb:

    Sei un asso !! :D

    10.JPG
     
  2. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @guest @Peter2150

    This option "Block execution of processes on All Users Folder" blocks processes on:

    C:\Users\All Users\*

    On my system I only have 3 .exe files inside C:\Users\All Users\*:

    exes.png

    Blocking of programs on User's AppData (C:\Users\<CurrentUser>\AppData\) is handled with:

    Block execution of unsigned processes on Local AppData
    Block execution of unsigned processes on Roaming AppData
    Block execution of unsigned processes on Common AppData

    And yes, these 3 options can generate some FPs.

    @Sampei Nihira

    Great :thumb:
     
  3. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    @novirusthanks- Ok, looks good and big hearty thanks diving headlong into all areas of concern with this project.

    One word-Super.
     
  4. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    I think it's better to add too:

    11.jpg

    Andreas, what do you think of adding a rule for CHML?
    The Mark Minasi Tool.
    Works also on W.10:

    12.jpg

     
    Last edited: Mar 6, 2018
  5. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Andreas Your da man on this one.
     
  6. co22

    co22 Registered Member

    Joined:
    Nov 22, 2011
    Posts:
    411
    Location:
    router
    not sure good for adding or not but worth adding it(it can be blocked by spyshelter,Bouncer) block execution url with command line
    usually after some installer finish installing open browser it can block this staf

    C:\some.exe>"C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "https://www.some.com/"
    C:\some.exe>"C:\Program Files\Mozilla Firefox\firefox.exe" http://www.some.com

    also check this maybe good for adding in SysHardener
    https://hshrzd.wordpress.com/2017/0...ons-handlers-as-a-malware-persistence-method/

    thanks
     
  7. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I haven't had issues with EAM. But my OSA has been on defaults and set to passive logging, so maybe that's why.
     
  8. guest

    guest Guest

    oh ok, i mistaken then, i thought All Users was for all users profiles folders (C:\Users\*) :p
     
  9. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    :thumb::thumb::thumb::thumb:

    12.jpg 13.jpg
    14.jpg 15.jpg
     
    Last edited: Mar 6, 2018
  10. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Running latest beta of OSA along with Windows Defender. Nothing gets by that combination when I throw malware at it in a virtual environment. No issues whatsoever in everyday usage.

    I have enabled every checkbox there is (including everything under advanced options). I have been running like this for over a month without any false positives.

    Good job!
     
  11. JoWazzoo

    JoWazzoo Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    241
    Location:
    Ether
    @shadek --- everything? Wow :eek: No flse positives, but any problems?
     
  12. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    Thanks Pete. I've restored an image from before Avast so am back using Windows Defender which seems much more compatible with other programs.
     
  13. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hooray for imaging software.
     
  14. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    Here is a new v1.4 (pre-release) test40:
    http://downloads.novirusthanks.org/files/osarmor_setup_1.4_test40.exe

    *** Please do not share the download link, we will delete it when we'll release the official v1.4 ***

    So far this is what's new compared to the previous pre-release:

    + Joined "Prevent Base Filtering Engine (BSE) from being disabled via cmdline" and "Prevent Windows Firewall from being disabled via command-line" in "Prevent important Windows Services from being disabled"
    + Added Windows Defender, Security Essentials, Windows Update, Security Center to "Prevent important Windows Services from being disabled"
    + Block cmstp.exe from loading .inf files (AppLocker bypass)
    + Improved detection of PowerShell malformed commands
    + Advanced -> Block execution of processes on Public Folder (C:\Users\Public) -> Enabled by default
    + Advanced -> Block execution of processes on All Users folder -> Enabled by default
    + Advanced -> Block execution of .msc scripts outside System folder -> Enabled by default
    + Advanced -> Block reg.exe from hijacking Registry startup entries -> Enabled by default
    + Advanced -> Prevent attrib.exe from setting +h or +s attributes -> Enabled by default
    + Advanced -> Prevent wevtutil.exe from cleaning Windows Eventlog -> Enabled by default
    + Advanced -> Prevent important Windows Services from being disabled -> Enabled by default
    + Advanced -> Block reg.exe from disabling UAC (User Access Control) -> Enabled by default
    + Improved "Prevent important Windows Services from being disabled"
    + Block execution of regini.exe

    To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.

    Let me know if you find any FP with the 8 options enabled by default in Advanced tab.

    @Sampei Nihira

    Will check and discuss about CHML (Mark Minasi Tool).

    @co22

    Many legit programs use Firefox or IE or a web browser to open URLs, so that would generate many FPs.

    To protect that registry entries you can use Registry Guard or Registry Guard Service.

    @guest

    No problem :D

    @shadek

    Great! Thanks for sharing it.
     
  15. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Um, what if I run with Windows Defender Security Center and Windows Update: Services disabled.
    Which Windows Services are deemed "important"?
     
    Last edited: Mar 7, 2018
  16. novirusthanks

    novirusthanks Developer

    Joined:
    Nov 5, 2010
    Posts:
    1,359
    Location:
    Italy
    @bjm_

    That's not a problem, that option prevents sc.exe, net.exe, wmic.exe, etc from disabling\stopping important Windows Services via command-line.

    If you have already disabled them, no alert will be triggered by OSArmor.

    Windows Firewall, Windows Defender, Windows Updates, Security Center, Microsoft Security Essentials.

    These important (security-related) Windows Services are commonly hijacked\stopped\disabled by malware via sc.exe, net.exe, etc.

    OSArmor makes sure they can't be hijacked\stopped\disabled via command-line.
     
    Last edited: Mar 6, 2018
  17. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Aha. Okay. Thanks.
     
  18. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,241
    Location:
    Among the gum trees
    I know it has been discussed in this lengthy thread before but will OSA have an updater built-in when released?
     
  19. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Build 40 installed with all settings default. So far no problems.
     
  20. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,507
    Same here.
     
  21. kdcdq

    kdcdq Registered Member

    Joined:
    Apr 19, 2002
    Posts:
    815
    Location:
    A Non-Sh*thole State
    Ditto on 3 systems. Win10 1709 x64.
     
  22. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Hmm, on build 40 I click on result to default and all the advanced setting cleared Should that have happened?
     
  23. JoWazzoo

    JoWazzoo Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    241
    Location:
    Ether
    I'm a couple betas late....LMAO. Had a side trip with a lunched machine installing something else. That's fixed so now I can play again with all the new stuff from NVT. :rolleyes:
     
  24. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Totally tightened up on the settings. Have some command line desktop stuff I use, and it threw up alerts. set the exclusions and then no further bother. Beautifully done.
     
  25. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Installing now to a refreshed 10 system with ERP and various other goodies.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.