NoVirusThanks Smart Object Blocker - wersje rozwojowe

OXYGEN THIEF

Bardzo aktywny
Członek Załogi
Administrator
Dołączył
26 Maj 2010
Posty
35949
Reakcje/Polubienia
25043
Miasto
Trololololo
smart-object-blocker-gui2.png

NoVirusThanks Smart Object Blocker to bezpłatny program który zabezpiecza komputer przed infekcjami malware czy rootkitami bez potrzeby pobierania ich sygnatur czyli tak jakby odcisków po których można było by je identyfikować .Program monitoruje ładowanie sterowników, pliki DLL, uruchamiane pliki w systemie i wrazie potrzeby je zablokuje.Posiada tryb Lockdown Mode, pozwala tworzyć reguły, filtrować i wiele więcej.
Zaloguj lub Zarejestruj się aby zobaczyć!

Zaloguj lub Zarejestruj się aby zobaczyć!
 
A

Anonymous

ssl111 napisał:
Dzięki Oxy.Testował to już ktoś ?
To sofcik typu : zainstaluj (i po stworzeniu reguł) zapomnij.Nie masz żadnych wyskakujących komunikatów .A przeprowadzone akcje możesz se sprawdzić w oknie głównym programu.
Co do skuteczności...to dopiero pierwsza beta czyli testy dopiero przed nami.
 

OXYGEN THIEF

Bardzo aktywny
Członek Załogi
Administrator
Dołączył
26 Maj 2010
Posty
35949
Reakcje/Polubienia
25043
Miasto
Trololololo
NoVirusThanks Smart Object Blocker v1.1

NoVirusThanks Smart Object Blocker v1.1
Zaloguj lub Zarejestruj się aby zobaczyć!

[02-08-2015] v1.1.0.0
+ Added tray icon with right-click menu
+ Change the tray icon when objects are blocked if the GUI is not showing
+ Improved support for Windows 10 and Google Chrome
 

OXYGEN THIEF

Bardzo aktywny
Członek Załogi
Administrator
Dołączył
26 Maj 2010
Posty
35949
Reakcje/Polubienia
25043
Miasto
Trololololo
Released a new version v1.1 (small updates):
Zaloguj lub Zarejestruj się aby zobaczyć!


+ Added more path variables
+ Improved the \Block\ rules for Behavioral Mode
+ Improved the text on Variables.txt file
+ Show protection mode on the trayicon hint
+ Write "-= Passive Logging =-" text also in the log file
 
A

Anonymous

Tachion z SG testował ten sofcik...i na razie coś słabo wypada...ale widać,że Andrea opuścił już NVT i koncentruje się na SOB więc na pewno z czasem git odpicuje ten produkt.
 

jasonX

Bardzo aktywny
Dołączył
23 Październik 2015
Posty
149
Reakcje/Polubienia
987
Would be nice if the program will block any files like video, MS Office files and not just process/dll/drivers. But as I see it the program is very promising and can be a partner to NVT Exe Radar. Anyone have tried out this thoroughly..?


---

Byłoby miło, gdyby program będzie blokować żadnych plików, takich jak wideo, plików MS Office i nie tylko procesu / DLL / kierowców. Ale jak ja to widzę program jest bardzo obiecujące i może być partnerem do NVT Exe Radar. Każdy, próbowali się tego dokładnie ..?
 

jasonX

Bardzo aktywny
Dołączył
23 Październik 2015
Posty
149
Reakcje/Polubienia
987
Any news on the supposed update? I'd like to check how to make a rule to block a specific file from being accessed. Well if that is feasible with SOB.

-----

Wszelkie wiadomości na temat rzekomej aktualizacji? Chciałbym sprawdzić, jak zrobić regułę blokowania określonego pliku przed dostępem. Cóż, jeśli jest to wykonalne z SOB.
 

jasonX

Bardzo aktywny
Dołączył
23 Październik 2015
Posty
149
Reakcje/Polubienia
987
Have given thought on fiddling with this Smart Object Blocker to see how it behaves and checkout if this may be of use to my computing.
Rules creation was from scratch and if you do not like creating rules like that chances are you aren't gonna like it but the gem in this program is it's possibilities or so I was told or understood as I was reading the thread at Wilders
Zaloguj lub Zarejestruj się aby zobaczyć!
. At the time I tried it out there came a new version which is version 1.3. You can download it here,
Zaloguj lub Zarejestruj się aby zobaczyć!
.

So as I tried to make rules from scratch via the Read Me / Variables I have had success and some failures with observations in tow. I tried it focusing on the .exe files but may later try .dll and driver blocking. Here are they:

Restricting launch of default browser due to trigger-mechanism by programs

--Before I would try this out with Bitdefender 2013/2014 and there was no luck. Browser would launch when a game or an application is closed or when you click something in the gui. In SOB you can restrict that. But in my experiment there are programs (like Auslogics Disk Defrag) that tend to use "explorer.exe" to trigger the browser launch. So blocking the browser via the rule (as guided by the Read Me/Variables) will not work. Auslogics Disk Defrag is using explorer.exe to trigger the launch of firefox.exe(former default browser). Default browser will still launch EVEN if you block the default browser. So if you block the default browser (firefox.exe or iexplorer.exe) from being triggered by DiskDefrag.exe (Auslogics Disk Defrag) the default browser will still launch.

Rules below will not work for Auslogics Disk Defrag
[%PROCESS%: *\iexplore.exe][%PARENTPROCESS%: *\DiskDefrag.exe]
[%PROCESS%: *\firefox.exe][%PARENTPROCESS%: *\DiskDefrag.exe]
[%FILENAME%: iexplore.exe][%PARENTPROCESS%: *\DiskDefrag.exe]
[%FILENAME%: firefox.exe] [%PARENTPROCESS%: *\DiskDefrag.exe]


It should be that you must block explorer.exe from being triggered by DiskDefrag.exe (Auslogics Disk Defrag).

[%FILENAME%: explorer.exe] [%PARENTPROCESS%: *\DiskDefrag.exe]
[%PROCESS%: *\explorer.exe][%PARENTPROCESS%: *\DiskDefrag.exe]

See proof of SOB blocks below:

SOB Block Logs:
[11/29/2015 7:51:29 PM] Blocked Process: C:\Windows\SysWOW64\explorer.exe
Rule: [%FILENAME%: explorer.exe] [%PARENTPROCESS%: *\DiskDefrag.exe]
Command Line: C:\Windows\SysWOW64\explorer.exe
Process Id: 3216
Parent Process Id: 4412
Parent Process: C:\Program Files (x86)\Auslogics\DiskDefrag\DiskDefrag.exe


[11/29/2015 7:51:30 PM] Blocked Process: C:\Windows\SysWOW64\explorer.exe
Rule: [%FILENAME%: explorer.exe] [%PARENTPROCESS%: *\DiskDefrag.exe]
Command Line: C:\Windows\SysWOW64\explorer.exe
Process Id: 2732
Parent Process Id: 4412
Parent Process: C:\Program Files (x86)\Auslogics\DiskDefrag\DiskDefrag.exe

[11/29/2015 9:55:27 PM] Blocked Process: C:\Windows\SysWOW64\explorer.exe
Rule: [%PROCESS%: *\explorer.exe][%PARENTPROCESS%: *\DiskDefrag.exe]
Command Line: C:\Windows\SysWOW64\explorer.exe
Process Id: 5156
Parent Process Id: 5820
Parent Process: C:\Program Files (x86)\Auslogics\DiskDefrag\DiskDefrag.exe


[11/29/2015 9:55:29 PM] Blocked Process: C:\Windows\SysWOW64\explorer.exe
Rule: [%PROCESS%: *\explorer.exe][%PARENTPROCESS%: *\DiskDefrag.exe]
Command Line: C:\Windows\SysWOW64\explorer.exe
Process Id: 5056
Parent Process Id: 5820
Parent Process: C:\Program Files (x86)\Auslogics\DiskDefrag\DiskDefrag.exe

For GOM Media Player GOM.exe it triggers the default browser to launch so the rules that did not work for Auslogics will work for it.

//Prevent GOM Player from running default browser
[%PROCESS%: *\iexplore.exe][%PARENTPROCESS%: *\GOM.exe]
[%FILENAME%: iexplore.exe][%PARENTPROCESS%: *\GOM.exe]

//Prevent GrLauncher.exe from launching
[%PROCESS%: *\GrLauncher.exe][%PARENTPROCESS%: *\GOM.exe]

//Prevent GrLauncher.exe from running default browser
[%PROCESS%: *\iexplore.exe][%PARENTPROCESS%: *\GrLauncher.exe]

See proof of SOB blocks below:


SOB Block Logs:
[11/29/2015 7:53:06 PM] Blocked Process: C:\Program Files\Internet Explorer\iexplore.exe
Rule: [%PROCESS%: *\iexplore.exe][%PARENTPROCESS%: *\GOM.exe]
Command Line: "C:\Program Files\Internet Explorer\iexplore.exe"
Zaloguj lub Zarejestruj się aby zobaczyć!

Process Id: 5172
Parent Process Id: 3916
Parent Process: C:\Program Files (x86)\GRETECH\GomPlayer\GOM.EXE


[11/29/2015 7:53:07 PM] Blocked Process: C:\Program Files\Internet Explorer\iexplore.exe
Rule: [%PROCESS%: *\iexplore.exe][%PARENTPROCESS%: *\GOM.exe]
Command Line: "C:\Program Files\Internet Explorer\iexplore.exe"
Zaloguj lub Zarejestruj się aby zobaczyć!

Process Id: 5756
Parent Process Id: 3916
Parent Process: C:\Program Files (x86)\GRETECH\GomPlayer\GOM.EXE


[11/29/2015 7:53:08 PM] Blocked Process: C:\Program Files (x86)\GRETECH\GomPlayer\GrLauncher.exe
Rule: [%PROCESS%: *\GrLauncher.exe][%PARENTPROCESS%: *\GOM.exe]
Command Line: C:\Program Files (x86)\GRETECH\GomPlayer\GrLauncher.exe
Process Id: 5104
Parent Process Id: 3916
Parent Process: C:\Program Files (x86)\GRETECH\GomPlayer\GOM.EXE

As in GOM.exe, media player Daum PotPlayer - PotPlayerMini.exe the rules to block browser launch is the same BUT PotPlayer prefers to launch firefox.exe instead of Internet Explorer.

//Prevent PotPlayerMini.exe from running default browser
[%PROCESS%: *\firefox.exe][%PARENTPROCESS%: *\PotPlayerMini.exe]
[%FILENAME%: iexplore.exe][%PARENTPROCESS%: *\PotPlayerMini.exe]

See proof of SOB blocks below:

SOB Block Logs:
[11/29/2015 9:46:10 PM] Blocked Process: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Rule: [%PROCESS%: *\firefox.exe][%PARENTPROCESS%: *\PotPlayerMini.exe]
Command Line: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Process Id: 6700
Parent Process Id: 3652
Parent Process: C:\Program Files (x86)\DAUM\PotPlayer\PotPlayerMini.exe


[11/29/2015 9:46:10 PM] Blocked Process: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Rule: [%PROCESS%: *\firefox.exe][%PARENTPROCESS%: *\PotPlayerMini.exe]
Command Line: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Process Id: 1508
Parent Process Id: 3652
Parent Process: C:\Program Files (x86)\DAUM\PotPlayer\PotPlayerMini.exe

Internet Explorer issues

Encountered launching of IE as SOB blocked it from running because of the default rule. It was impossible to run IE normally if you will not disable SOB or Exclude it in the SOB exclude rules. So as I am not using IE I prefered to make it the default browser from firefox.exe.

Also if IE is the default browser you can just block the whole IE execution altogether via rule, [%PROCESS%: *\iexplore.exe] -- since SOB is restricting IE and will not let it execute normally due to exploit process issues.

//Prevent commonly exploited processes from executing processes
[%PARENTPROCESS%: *\iexplore.exe]

See proof of SOB blocks below:

SOB Block Logs:
[11/29/2015 10:35:24 PM] Blocked Process: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Rule: [%PARENTPROCESS%: *\iexplore.exe]
Command Line: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Process Id: 4456
Parent Process Id: 5284
Parent Process: C:\Program Files\Internet Explorer\iexplore.exe


[11/29/2015 10:35:45 PM] Blocked Process: C:\Windows\system32\rundll32.exe
Rule: [%PARENTPROCESS%: *\iexplore.exe]
Command Line: C:\Windows\system32\rundll32.exe C:\Windows\system32\inetcpl.cpl,ClearMyTracksByProcess Flags:264 WinX:0 WinY:0 IEFrame:0000000000000000
Process Id: 7152
Parent Process Id: 5284
Parent Process: C:\Program Files\Internet Explorer\iexplore.exe


[11/29/2015 10:35:45 PM] Blocked Process: C:\Windows\system32\rundll32.exe
Rule: [%PARENTPROCESS%: *\iexplore.exe]
Command Line: C:\Windows\system32\rundll32.exe C:\Windows\system32\inetcpl.cpl,ClearMyTracksByProcess Flags:65800 WinX:0 WinY:0 IEFrame:0000000000000000
Process Id: 5212
Parent Process Id: 5284
Parent Process: C:\Program Files\Internet Explorer\iexplore.exe


[11/29/2015 10:35:45 PM] Blocked Process: C:\Windows\system32\rundll32.exe
Rule: [%PARENTPROCESS%: *\iexplore.exe]
Command Line: C:\Windows\system32\rundll32.exe C:\Windows\system32\inetcpl.cpl,ClearMyTracksByProcess Flags:65800 WinX:0 WinY:0 IEFrame:0000000000000000
Process Id: 5520
Parent Process Id: 5284
Parent Process: C:\Program Files\Internet Explorer\iexplore.exe


Restrict executables from running in a specific file path or drive

As for restricting access to drives and locations, experienced that only "executables" are blocked and not common filetypes like .doc / .html. Rules created:

//Block any programs from executing in J:\
Process.DB:
[%PROCESS%: J:\*]
[%FILEPATH%: J:\*]

Drivers.DB:
[%FILE%: J:\*]

DLL.DB:
[%FILE%: J:\*]

Executables that were blocked are below:

J:\BandiZip Portable\Bandizip32.exe
J:\MPC-HCPortable\MPC-HCPortable.exe
J:\Portable WordWeb\wweb32.exe

See proof of SOB blocks below:

SOB Block Logs:
[11/29/2015 10:28:57 PM] Blocked Process: J:\BandiZip Portable\Bandizip32.exe
Rule: [%PROCESS%: J:\*]
Command Line: J:\BandiZip Portable\Bandizip32.exe
Process Id: 3916
Parent Process Id: 4844
Parent Process: C:\Windows\explorer.exe


[11/29/2015 10:29:03 PM] Blocked Process: J:\MPC-HCPortable\MPC-HCPortable.exe
Rule: [%PROCESS%: J:\*]
Command Line: J:\MPC-HCPortable\MPC-HCPortable.exe
Process Id: 6316
Parent Process Id: 4844
Parent Process: C:\Windows\explorer.exe


[11/29/2015 10:29:10 PM] Blocked Process: J:\Portable WordWeb\wweb32.exe
Rule: [%PROCESS%: J:\*]
Command Line: J:\Portable WordWeb\wweb32.exe
Process Id: 1816
Parent Process Id: 4844
Parent Process: C:\Windows\explorer.exe


Restrict Kingsoft applications from launching default browser.

Rules created below for Kingsoft Writer to not be able to launch the defaukt browser from it's gui worked.

[%PROCESS%: *\iexplore.exe][%PARENTPROCESS%: *\wps.exe]

See SOB proof of block below:

SOB Block Logs:

[11/29/2015 11:24:46 PM] Blocked Process: C:\Program Files\Internet Explorer\iexplore.exe
Rule: [%PROCESS%: *\iexplore.exe][%PARENTPROCESS%: *\wps.exe]
Command Line: "C:\Program Files\Internet Explorer\iexplore.exe"
Zaloguj lub Zarejestruj się aby zobaczyć!

Process Id: 6084
Parent Process Id: 7008
Parent Process: C:\Program Files (x86)\Kingsoft\Kingsoft Office\office6\wps.exe


[11/29/2015 11:24:51 PM] Blocked Process: C:\Program Files\Internet Explorer\iexplore.exe
Rule: [%PROCESS%: *\iexplore.exe][%PARENTPROCESS%: *\wps.exe]
Command Line: "C:\Program Files\Internet Explorer\iexplore.exe"
Zaloguj lub Zarejestruj się aby zobaczyć!

Process Id: 5212
Parent Process Id: 7008
Parent Process: C:\Program Files (x86)\Kingsoft\Kingsoft Office\office6\wps.exe

I will try to test some on programs like Glary Utilities the next time I can. Smart Object Blocker is pretty much in it's infancy but the potential for this program is great. The trigger mechanism alone I formerly block with Comodo HIPS or Outpost Firewall Pro Anti-Leak (and the defunct Online Armor Premium HIPS) is a piece of cake with SOB. Not may security application can do this.

If there are any of you who are trying Smart Object Blocker please do chip in your experience :)
 

jasonX

Bardzo aktywny
Dołączył
23 Październik 2015
Posty
149
Reakcje/Polubienia
987
Well pretty much slow roll for Smart Object Blocker. I think it's a keeper if they can get it to full swing AND a good gui will definitely help.

Zaloguj lub Zarejestruj się aby zobaczyć!
 
Do góry