NoVirusThanks OSArmor

D

Deleted member 65228

Opcode: "However, there's no self-protection."

- That would be better, because times are getting more and more dangerous.
Hmmmm well we need to remember that you still elevation to attack the service -> in any scenario if you allow malware to run with elevation then it can be game over just like that.

You would need elevation to hijack the configuration via the Registry, attack its driver, etc... as well.

So it isn't that it is "insecure" - I'd say its pretty good -, but yes self protection when it gets added soon as the developer said will improve it a lot
 
Last edited by a moderator:

Overkill

Level 31
Verified
Honorary Member
Feb 15, 2012
2,128
ERP gives you full control on every single application that is installed\executed in the system and is more for advanced users.

OSArmor is for beginner users (but also for experts) with pre-built rules that requires 0 configuration and adds an additional (solid) layer of defense.

What if it's blocking a legit process? will you add an exclusions option?
 

NoVirusThanks

From NoVirusThanks
Verified
Developer
Well-known
Aug 23, 2012
292
@Opcode

Yeah, the malware needs Admin rights to terminate\hijack OSArmor service or settings, but once the malware has Admin privileges it can literally do anything.

Main focus of OSArmor is to prevent the malware execution. However, we plan on adding self-defense.

@Overkill

Yes we plan to allow user to exclude some processes\events.

@HarborFront

Yes, definitely. OSArmor should work fine with other security software and adds an additional layer of defense.
 

NoVirusThanks

From NoVirusThanks
Verified
Developer
Well-known
Aug 23, 2012
292

cutting_edgetech

Level 3
Verified
Feb 14, 2013
113
Never Mind. I found OSArmor on NoVirusThanks Website. I thought I was in the ERP thread. I have been waiting for someone to develop a standalone BB again for a long time. If it's done right then this is something I will definitely be interested in using.
 
Last edited:

Aktiffiso

Level 8
Verified
Aug 24, 2013
395
Hi i dont know if NVT proyects are abandoned, maybe that software works well, for me is cool, "prometedor" . Do you think this work well whith software like avast or emsisoft or another av who have BB? Do you think it will be abandoned? I have some economic troubles but think contribute buying NVT Exe radar but maybe i use it dayly
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
No support for Secure Boot is a dealbreaker for me. I assume it won't work with virtualization-based security either.
The dev said on the other forum that support for Secure Boot is coming, hopefully within a week or so. It requires special sigs, for which he has already applied.
 
Last edited:

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
ERP gives you full control on every single application that is installed\executed in the system and is more for advanced users.

OSArmor is for beginner users (but also for experts) with pre-built rules that requires 0 configuration and adds an additional (solid) layer of defense.
That's great, thank you!
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
hello, can I have feature requests? :)
if it's possible, could you please add option to block
- java.exe and javaw.exe-> unchecked by default. Many AVs are not goot at detecting this type of malware and I'm afraid somehow java can be automatically downloaded
- teamviewer processes - unchecked by default. I have seen some malwares downloading TV package and gained access to the infected PCs although it's not very common

thank you. This program is now in my must-have list
 
D

Deleted Member 3a5v73x

@NoVirusThanks Thanks for this great tool, I hope you'll keep updates rolling. Appreciate your hard work. :)

@Evjl's Rain I assume you use it together with Avast? Any particular exclusions to be made? I don't really believe this sentence, nothing personal towards OSArmor. :)
This program is compatible with other security software
Thanks in advance. ;)
 
Last edited by a moderator:

Xtwillight

Level 6
Verified
Well-known
Jul 1, 2014
297
F/P reports in VT
yesterday = Recognition rate: 10/66
today = Recognition rate: 4 / 66 Antivirus scan for 96f521b1b5d8bcdd32225b108dd297eb7ccc718323dd74b1769cf843c1b5c550 at 2017-12-18 07:52:35 UTC - VirusTotal

I have yesterday the file to check after Emsisoft sent.

Because Emsisoft AV yesterday reported "
Emsisoft Anti-Malware v. 2017.11.0.8247
(C) 2003-2017 Emsisoft - www.emsisoft.com
ID Object
0 C:\Users\dark\Downloads\osarmor_setup.exe Gen:Trojan.Heur.LShot.1 (B)"


Arief Prabowo Malware Analyst bye Emsisoft write :
" Hello,
thank you for your submission. The file is no longer being detected by Emsisoft. Please make sure you are using our latest database by run the online update.
Best Regards,

Arief Prabowo
Malware Analyst"

(y)Thank you Arief Prabowo(y)
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
@Evjl's Rain I assume you use it together with Avast? Any particular exclusions to be made? I don't really believe this sentence, nothing personal towards OSArmor. :)
so far, I haven't made any exclusion and they are working perfectly with each other
if I have to do:
- add OSAmor folder to global exclusion in the main settings
- add the folder to Behavior Shield exclusion. For some reasons, I found BB is still blocking something although it is excluded in global exclusion
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,131
I updated OSArmor with these changes:

- Fixed FP with chrome.exe
- Block flag TESTSIGNING on Bcdedit.exe
- Allow PortableApps (.paf.exe) by Rare Ideas, LLC
- Minor improvements

Please just uninstall it from Control Panel and then download and install it again from:
Prevent Malware and Ransomware Infections with OSArmor | NoVirusThanks

@cutting_edgetech

Hi :) And yes it is a new product from us, read more here:
Prevent Malware and Ransomware Infections with OSArmor | NoVirusThanks
Very good project. It is in the early stage so needs to close some bypasses (I found 5 popular techniques of executing from scripts not covered by actual version). Please, pm me If you are interested.:)
.
Edit
There are also 2 other bypasses, but they need Administrator rights to run.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top