Boringly quiet here. No detection logs since April 9. Nice. I keep checking the tray to see if I've disabled OSA
All non-orange/red options selected.
Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
No, the powershell commands were blocked, see: NoVirusThanks OSArmorIt wasn't?
I want to block writing to "G" partition by all except Signer: Microsoft.Now with latest option to allow only signed processes in user space, one only needs to add addtional partitions/drives to your custom block rules, it is as easy as this, where X is the drive letter: [%PROCESSFILEPATH%: X:\*]
So when you split your harddisk into C for programs and D for files it would look like: [%PROCESSFILEPATH%: D:\*]
1. Is starting other programs covered by the anti-exploit option of Word?
2. Do you have made allow exceptions for print spool and touch keyboard?
I am asking because for wscript.exe you have:
So when you split your harddisk into C for programs and D for files it would look like: [%PROCESSFILEPATH%: D:\*]
You may find these new options useful:
+ Block unsigned processes outside system partition (e.g. C:\)
+ Block ALL processes outside system partition (e.g. C:\)
![]()
You can just make exclusions then, it is what i do.Andreas,
Does the rule BLOCK ALL PROCESSES OUTSIDE also includes USB and RAM disk (other options)?
I would prefer it to apply the rule "block all" on harddisks only, so user has granular control on others (USB, CD Rom, Ram etc) with other options.
@NoVirusThanks
Note: Any comment regarding my question about BadUSB? Is it feasible or not?
False positive by GData and MAX:The 1.4 release is marked as Malware : Win32.Malware.Bucaspys.VSRSE4
Members who viewed this thread in the last 5 minutes