- Jan 29, 2017
- 1,201
Boringly quiet here. No detection logs since April 9. Nice. I keep checking the tray to see if I've disabled OSA All non-orange/red options selected.
No, the powershell commands were blocked, see: NoVirusThanks OSArmorIt wasn't?
I want to block writing to "G" partition by all except Signer: Microsoft.Now with latest option to allow only signed processes in user space, one only needs to add addtional partitions/drives to your custom block rules, it is as easy as this, where X is the drive letter: [%PROCESSFILEPATH%: X:\*]
So when you split your harddisk into C for programs and D for files it would look like: [%PROCESSFILEPATH%: D:\*]
1. Is starting other programs covered by the anti-exploit option of Word?
2. Do you have made allow exceptions for print spool and touch keyboard?
I am asking because for wscript.exe you have:
So when you split your harddisk into C for programs and D for files it would look like: [%PROCESSFILEPATH%: D:\*]
You may find these new options useful:
+ Block unsigned processes outside system partition (e.g. C:\)
+ Block ALL processes outside system partition (e.g. C:\)
You can just make exclusions then, it is what i do.Andreas,
Does the rule BLOCK ALL PROCESSES OUTSIDE also includes USB and RAM disk (other options)?
I would prefer it to apply the rule "block all" on harddisks only, so user has granular control on others (USB, CD Rom, Ram etc) with other options.
@NoVirusThanks
Note: Any comment regarding my question about BadUSB? Is it feasible or not?
False positive by GData and MAX:The 1.4 release is marked as Malware : Win32.Malware.Bucaspys.VSRSE4