NoVirusThanks OSArmor

uninfected1

Level 11
Verified
Top Poster
Well-known
Jan 28, 2016
525
I've read quite a lot of this thread and also the OSArmor thread in the 'other place' but I still haven't been able to find out whether it is worth using in addition to Voodooshield or if there is too much duplication, or indeed if there are any compatibility issues. I've been using both of them for a little while and there don't appear to be any conflicts. Any feedback appreciated.
 

NoVirusThanks

From NoVirusThanks
Verified
Developer
Well-known
Aug 23, 2012
292
Here is a new v1.4 (pre-release) test69:
http://downloads.novirusthanks.org/files/osarmor_setup_1.4_test69.exe

*** Please do not share the download link, we will delete it when we'll release the official v1.4 ***

So far this is what's new compared to the previous pre-release:

+ Fixed some false positives
+ Removed "Block execution of IQY Excel Web Query files" (executed directly via excel /dde, can't be filtered)
+ Added numbering of questions (Q) and answers (A) on Help\FAQs file, e.g. Q1 A1, Q16 A16, Q21 A21
+ New option: Prevent explorer.exe from executing exes with /c
+ Improved Block suspicious command-lines

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.

If you find any false positive or issue please let me know.

All reported FPs should be fixed.

//Everyone

Summary of important features not yet added (scheduled for next version):

- Automatic update
- Button to manually check for updates
- Maybe encrypt the CustomBlock.db/Exclusions.db files so they are not in plain-text and create a GUI-helper to edit them
- Move all protection options in a ListView so they can be easily sorted/categorized/searchable/enabled/disabled
- Create pre-defined protection modes: Basic/Medium/Advanced/Custom
- Add possibility to add custom apps in Anti-Exploit tab
- Possibility to exclude a specific blocked event from being shown via the notification dialog
 

NulFunction

Level 2
Verified
Jun 2, 2018
96
NVT is one of the few vendors that you can use a beta as if it was a stable.
I follow this vendor since day one, i almost never had severe issues while using their apps.
However, NVT specifically recommended the use of it's 3.1.0.0 beta for ERP. So this is only true for OSA, if at all.

BTW I have problem with the OSA blocking popup, using test 68: When I get a popup and another one from a different program opens, OSAs gets closed. It will also close when pressing keys.

Feature requests:
- Show log as you do in ERP.
- Make it also password protectable
- You have these exclamation marks in configurator, warning for possible problematic settings. Could you add a mouse-over text for all settings that gives a little context as to what they do? Like, why should I "prevent odbcconf.exe from loading .rsp scripts"?

Long term feature requests:
Combine all your great software into one.
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Long term feature requests:
Combine all your great software into one.
Not always the best idea, look at Malwarebytes, it hasn't faired so well over the years. More features = bloated = more bugs and fixes = compatibility issues etc..
Another excellent example are people who use paid Bitdefender Total Security, then ignore the 80% of the features.
Those highlighted in bold are likely to be ignored and alt. software used instead.

Start.
  • Complete Data Protection
  • Advanced Threat Defense
  • Multi-Layer Ransomware Protection
  • Anti-Phishing
  • Anti-Fraud
  • Safe Files
  • Secure Browsing
  • Rescue Mode
  • Anti-Theft
  • Bitdefender AutopilotTM
  • Bitdefender PhotonTM
  • Battery Mode
  • Global Protective Network
  • Game, Movie & Work Modes
  • Bitdefender VPN
  • Webcam Protection
  • Safe Online Banking
  • Parental Advisor
  • File Shredder
  • Privacy Firewall
  • Social Network Protection
  • Password Manager
  • Vulnerability Assessment
End.
 

NoVirusThanks

From NoVirusThanks
Verified
Developer
Well-known
Aug 23, 2012
292
Just a quick update:

Here is a new v1.4 (pre-release) test70:
http://downloads.novirusthanks.org/files/osarmor_setup_1.4_test70.exe

*** Please do not share the download link, we will delete it when we'll release the official v1.4 ***

So far this is what's new compared to the previous pre-release:

+ Fixed some false positives
+ Improved Block suspicious command-lines
+ Improved Block processes located in suspicious folders

To install it, first uninstall the previous build, then reboot (not really needed but may help), and install the new build.

If you find any false positive or issue please let me know.

NulFunction

The features you suggested are scheduled for v1.5
 

Hi Brothers

Level 2
Verified
Apr 19, 2018
71
Can I exclude a process from being blocked? OSArmor blocks my automatic scheduled acronis backup which runs even if pc is off, it turns it on, makes a backup, then turns it back off. Using version 1.3, here's the details:

Date/Time: 6/16/2018 2:00:02 PM
Process: [21228]C:\Program Files (x86)\Common Files\Acronis\TrueImageHome\TrueImageHomeNotify.exe
Parent: [3648]C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
Rule: BlockDirectJsVbsExecution
Rule Name: Block direct execution of javascript and vbscript code
Command Line: /dummy /dummy /script:"B39B3715-B5B5-40AC-B7B9-40E0E0A3A1F9" /uuid:"B39B3715-B5B5-40AC-B7B9-40E0E0A3A1F9" /run_mode:8
Signer: Acronis International GmbH
Parent Signer: Acronis International GmbH
 
  • Like
Reactions: JB007 and vtqhtr413

NoVirusThanks

From NoVirusThanks
Verified
Developer
Well-known
Aug 23, 2012
292
We've released the official OSArmor v1.4 (final) version:

* Make sure to first uninstall v1.3 and then install the new version

[20-Jun-2018] v1.4.0.0​
+ More than 250 built-in protection options to choose from​
+ Thousands of internal rules to block suspicious process activities​
+ Very effective in blocking MalDocs (DOC/XLS/RTF/etc) payloads​
+ Block execution of scripts, unwanted programs, powershell.exe or cmd.exe​
+ Options to mitigate UAC bypasses, whitelisting/device guard/applocker bypasses​
+ Block unsigned processes elevated with high or system privileges​
+ Really many smart protection options that you can enable with a click​
+ Added "Anti-Exploit" module to protect commonly exploited programs​
+ The Configurator has now 3 tabs: Main Protections, Anti-Exploit, Advanced​
+ Integrated a smart caching mechanism to improve performances​
+ Improved support for Fast User Switching and Logouts​
+ Added "Passive Logging" to just log the blocked event without blocking it​
+ Option to Enable internal rules for allowing safe behaviors​
+ Option to disable protection temporarily, for 10 minutes, 30 minutes, 1 hour​
+ Option to use only your own custom block rules (ignoring built-in protection options)​
+ Option to play a WAV sound when something is blocked​
+ Option to User must be in the Administrators Group to change protection​
+ Extended process and parent process cmdline to 8192 chars (max for Windows)​
+ Disabled /silent and /verysilent uninstallation​
+ Added basic and process-termination self-defense​
+ The program is now installed on Program Files​
+ You can now exclude a process from being blocked​
+ Added support for exclusions via Exclusions.db file​
+ Added support for custom block-rules via CustomBlock.db file​
+ Supports vairables (like %PROCESS%) on Exclusions and Custom Block rules​
+ Added a basic GUI application to create exclusions​
+ Added option "Disable Protection" on tray icon menu​
+ Added option "Manage Exclusions" on main GUI and on tray icon menu​
+ Added option "Custom Block-Rules" on main GUI and on tray icon menu​
+ Support Secure Boot (drivers are co-signed by Microsoft)​
+ Added a simple Help/FAQs file​
+ Fixed all reported issues on Windows XP​
+ Fixed all reported false positives​
+ Many bug fixes and optimizations​


You can download it from our website:
Prevent Malware and Ransomware with OSArmor | NoVirusThanks

We'll start to work on v1.5 from middle of July * See below for important features in the todo list *

Summary of important features not yet added (scheduled for next version v1.5):

- Automatic update
- Button to manually check for updates
- Maybe encrypt the CustomBlock.db/Exclusions.db files so they are not in plain-text and create a GUI-helper to edit them
- Move all protection options in a ListView so they can be easily sorted/categorized/searchable/enabled/disabled
- Create pre-defined protection modes: Basic/Medium/Advanced/Custom
- Add possibility to add custom apps in Anti-Exploit tab
- Possibility to exclude a specific blocked event from being shown via the notification dialog


Thanks everyone for the help, suggestions and testing!

If you find any FP or issue please share them here.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top